How safe is India’s critical national infrastructure?
In this note
Practice
7 questions on this article
Check the answer for each question, or reveal all at once.
1. At a Glance
- India's critical infrastructure (power, water, banking, telecom, transport, defence, healthcare) is increasingly digitised via IoT, automation and AI, which improves efficiency but widens the attack surface for remote cyber disruption [5].
- The nodal legal-institutional response is the National Critical Information Infrastructure Protection Centre (NCIIPC), created under Sec. 70A, IT Act 2000 [1].
- UPSC relevance: tests GS-III (internal security, cybersecurity, disaster management) and GS-II (governance/regulatory bodies).
- Static topic — no recent trigger; the Hindu article (27 May 2026) is an explainer piece, not a report of an actual breach [5].
2. Why in the News
- Static topic — no recent trigger. The referenced article is an analytical/explainer piece on vulnerabilities from IoT-linked critical infrastructure rather than coverage of a specific attack [5].
- Government data shows a sharp rise in cybersecurity incidents: from 10.29 lakh (2022) to 22.68 lakh (2024), keeping the issue in policy discourse [2].
3. Background & Evolution
- 2000: Information Technology Act enacted; later amended (2008) to insert Section 70A, providing statutory basis for critical information infrastructure (CII) protection [1].
- 16 January 2014: NCIIPC formally notified via gazette notification, functioning as a unit of the National Technical Research Organisation (NTRO), under the Prime Minister's Office (PMO) [1].
- 2004: Indian Computer Emergency Response Team (CERT-In) established as the national nodal agency for cybersecurity incident response (background body distinct from NCIIPC) [2].
- April 2023: Sector-specific CSIRT-Power (Computer Security Incident Response Team – Power) inaugurated for the power sector [2].
- 2025: Draft Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2025 under finalisation — a dedicated regulatory framework for power-sector cyber resilience [2].
4. Core Static Facts
| Item | Detail |
|---|---|
| Definition of CII | "Computer resource, the incapacitation or destruction of which shall have debilitating impact on national security, economy, public health or safety" — IT Act, 2000 [1] |
| Nodal agency | NCIIPC (National Critical Information Infrastructure Protection Centre) [1] |
| Enabling provision | Section 70A, IT Act 2000 (amended 2008) [1] |
| Parent body | NTRO, reporting to PMO [1] |
| Established | 16 January 2014 [1] |
| Helpline | Toll-free 1800-11-4430 (24x7 Help Desk) [1] |
| Sister agency | CERT-In — coordinates national-level cyber incident response [1] |
| Sectors covered | Energy, finance, telecom, transport, government, defence, health, etc. [1] |
| Power-sector CERT | CSIRT-Power, launched April 2023 [2] |
| Cybersecurity audits | Over 9,700 CERT-In audits conducted in 2024–25; 200 empanelled auditing organisations [2] |
| Budget allocation | ₹782 crore for cybersecurity in Union Budget 2025–26 [2] |
| Grid audit status | 30 of 35 State Load Despatch Centres completed VAPT (Vulnerability Assessment & Penetration Testing) audits in past 5 years (as of March 2024) [2] |
| Incident trend | Cybersecurity incidents rose from 10.29 lakh (2022) to 22.68 lakh (2024) [2] |
5. Multi-Dimensional Analysis
Economic
- Disruption of power, banking, or fuel-distribution networks can cascade into supply-chain and market instability, given the interlinkage of services like electricity, banking and transport [5].
- Budgetary allocation (₹782 crore, 2025–26) reflects rising fiscal commitment to cyber-resilience [2].
Geopolitical/Strategic
- Critical infrastructure is a prime target for state-sponsored actors and hybrid warfare; sectors like defence, energy and telecom carry direct national-security stakes [1].
Legal/Constitutional
- Statutory backbone is Section 70A of the IT Act, 2000, which empowers the government to declare any computer resource "protected system" and designate CII [1].
Scientific/Technological
- IoT, automation and AI have improved monitoring and control of infrastructure but also created new attack vectors via previously isolated Operational Technology (OT) systems now linked to IT networks [5].
Administrative/Governance
- Multiple overlapping agencies (NCIIPC, CERT-In, sector-CERTs like CSIRT-Power) — coordination and last-mile audit compliance (e.g., 5 of 35 State Load Despatch Centres pending VAPT) remain implementation gaps [2].
6. Recent Developments (last 12-18 months)
- 2024–25: CERT-In conducted over 9,700 cybersecurity audits across critical sectors [2].
- 2025: Draft CEA (Cyber Security in Power Sector) Regulations, 2025 finalisation underway [2].
- Union Budget 2025–26: ₹782 crore allocated for cybersecurity [2].
- March 2024: Status update — 30/35 State Load Despatch Centres VAPT-compliant [2].
- 27 May 2026: The Hindu published an explainer on IoT-driven vulnerabilities in critical infrastructure, reiterating the need for a stronger policy framework [5].
7. Prelims Hooks
- NCIIPC was created under Section 70A of the IT Act, 2000 (amended 2008) [1].
- NCIIPC was notified on 16 January 2014 [1].
- NCIIPC functions as a unit of NTRO, under the PMO — not MeitY or MHA [1].
- NCIIPC's 24x7 helpline number is 1800-11-4430 [1].
- CERT-In (not NCIIPC) is India's nodal agency for cyber incident response generally [1].
- CSIRT-Power, a sector-specific CERT for the power sector, was inaugurated in April 2023 [2].
- No cyberattack has been officially reported to have disrupted actual power grid operations in India, per government statements [2].
- Union Budget 2025–26 allocated ₹782 crore for cybersecurity [2].
- Cybersecurity incidents rose from 10.29 lakh (2022) to 22.68 lakh (2024) [2].
- As of March 2024, 30 of 35 State Load Despatch Centres had completed VAPT audits in the preceding 5 years [2].
- CERT-In has empanelled 200 organisations for cybersecurity audits [2].
- The Draft CEA (Cyber Security in Power Sector) Regulations, 2025 are meant to create a dedicated cybersecurity framework for the power sector [2].
8. Mains Relevance
- GS-III: Internal Security — "Role of external state and non-state actors in creating challenges to internal security"; "Basics of cyber security"; Disaster Management linkages.
- GS-II: Governance — institutional mechanisms/regulatory bodies for infrastructure protection.
- Possible question stems: 1. "Discuss the vulnerabilities introduced by digitisation (IoT, AI, automation) in India's critical infrastructure. Suggest a comprehensive policy framework to mitigate these risks." (GS-III) 2. "Examine the institutional architecture for protecting India's Critical Information Infrastructure. How adequate is the coordination between NCIIPC, CERT-In and sector-specific CERTs?" (GS-II/III) 3. "Critical infrastructure protection is as much a governance challenge as a technological one. Comment with reference to India's power sector." (GS-III)
9. Related Topics to Study Next
- CERT-In and Information Technology Act, 2000/2008 — the overarching statutory-institutional cybersecurity framework.
- National Cyber Security Policy/Strategy — broader policy context beyond CII.
- Internet of Things (IoT) and Industrial Control Systems (SCADA) security — technical vulnerability discussed in the article.
- Disaster Management Act, 2005 — parallel framework for infrastructure-related disruptions.
- Data Protection (DPDP Act, 2023) — related digital governance/security legislation.
- National Technical Research Organisation (NTRO) — parent body of NCIIPC.
- Power sector reforms and grid resilience — CSIRT-Power, CEA regulations.
- Cyber warfare and hybrid threats in international relations — geopolitical dimension.
10. Common Errors / Trap Areas
- Confusing NCIIPC (CII protection, under NTRO/PMO) with CERT-In (general incident response, under MeitY) — they are distinct bodies with distinct mandates [1].
- Misattributing NCIIPC's parent ministry as MeitY or MHA instead of PMO (via NTRO) [1].
- Assuming a power-grid cyberattack has actually occurred in India — government statements explicitly deny any reported operational disruption [2].
- Confusing CSIRT-Power (sector-specific, power sector, 2023) with CERT-In (national-level, 2004) [2].
- Treating the IT Act's CII protection provision as a standalone Act — it is Section 70A of the IT Act, 2000, not a separate statute.
Sources
- 1National Critical Information Infrastructure Protection Centre, Government of Indianciipc.gov.in · tier 1
- 2Government Strengthens Cybersecurity Across Critical Sectors; Over 9,700 CERT-In Audits Conducted in 2024–25pib.gov.in · tier 1
- 3Cybersecurity of Power Gridspib.gov.in · tier 1
- 4Strengthening Cybersecurity in Power Sectorpib.gov.in · tier 1
- 5How safe is India's critical national infrastructure? — The Hindu (27 May 2026)thehindu.com · tier 4
At the end · practice MCQs
7 questions on this article
Check the answer for each question, or reveal all at once.