·The Hindu

How safe is India’s critical national infrastructure?

In this note
  1. At a Glance
  2. Why in the News
  3. Background & Evolution
  4. Core Static Facts
  5. Multi-Dimensional Analysis
  6. Recent Developments (last 12-18 months)
  7. Prelims Hooks
  8. Mains Relevance
  9. Related Topics to Study Next
  10. Common Errors / Trap Areas
Practice
7 questions on this article
Check the answer for each question, or reveal all at once.
Practice MCQs →

1. At a Glance

  • India's critical infrastructure (power, water, banking, telecom, transport, defence, healthcare) is increasingly digitised via IoT, automation and AI, which improves efficiency but widens the attack surface for remote cyber disruption [5].
  • The nodal legal-institutional response is the National Critical Information Infrastructure Protection Centre (NCIIPC), created under Sec. 70A, IT Act 2000 [1].
  • UPSC relevance: tests GS-III (internal security, cybersecurity, disaster management) and GS-II (governance/regulatory bodies).
  • Static topic — no recent trigger; the Hindu article (27 May 2026) is an explainer piece, not a report of an actual breach [5].

2. Why in the News

  • Static topic — no recent trigger. The referenced article is an analytical/explainer piece on vulnerabilities from IoT-linked critical infrastructure rather than coverage of a specific attack [5].
  • Government data shows a sharp rise in cybersecurity incidents: from 10.29 lakh (2022) to 22.68 lakh (2024), keeping the issue in policy discourse [2].

3. Background & Evolution

  • 2000: Information Technology Act enacted; later amended (2008) to insert Section 70A, providing statutory basis for critical information infrastructure (CII) protection [1].
  • 16 January 2014: NCIIPC formally notified via gazette notification, functioning as a unit of the National Technical Research Organisation (NTRO), under the Prime Minister's Office (PMO) [1].
  • 2004: Indian Computer Emergency Response Team (CERT-In) established as the national nodal agency for cybersecurity incident response (background body distinct from NCIIPC) [2].
  • April 2023: Sector-specific CSIRT-Power (Computer Security Incident Response Team – Power) inaugurated for the power sector [2].
  • 2025: Draft Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2025 under finalisation — a dedicated regulatory framework for power-sector cyber resilience [2].

4. Core Static Facts

Item Detail
Definition of CII "Computer resource, the incapacitation or destruction of which shall have debilitating impact on national security, economy, public health or safety" — IT Act, 2000 [1]
Nodal agency NCIIPC (National Critical Information Infrastructure Protection Centre) [1]
Enabling provision Section 70A, IT Act 2000 (amended 2008) [1]
Parent body NTRO, reporting to PMO [1]
Established 16 January 2014 [1]
Helpline Toll-free 1800-11-4430 (24x7 Help Desk) [1]
Sister agency CERT-In — coordinates national-level cyber incident response [1]
Sectors covered Energy, finance, telecom, transport, government, defence, health, etc. [1]
Power-sector CERT CSIRT-Power, launched April 2023 [2]
Cybersecurity audits Over 9,700 CERT-In audits conducted in 2024–25; 200 empanelled auditing organisations [2]
Budget allocation ₹782 crore for cybersecurity in Union Budget 2025–26 [2]
Grid audit status 30 of 35 State Load Despatch Centres completed VAPT (Vulnerability Assessment & Penetration Testing) audits in past 5 years (as of March 2024) [2]
Incident trend Cybersecurity incidents rose from 10.29 lakh (2022) to 22.68 lakh (2024) [2]

5. Multi-Dimensional Analysis

Economic

  • Disruption of power, banking, or fuel-distribution networks can cascade into supply-chain and market instability, given the interlinkage of services like electricity, banking and transport [5].
  • Budgetary allocation (₹782 crore, 2025–26) reflects rising fiscal commitment to cyber-resilience [2].

Geopolitical/Strategic

  • Critical infrastructure is a prime target for state-sponsored actors and hybrid warfare; sectors like defence, energy and telecom carry direct national-security stakes [1].

Legal/Constitutional

  • Statutory backbone is Section 70A of the IT Act, 2000, which empowers the government to declare any computer resource "protected system" and designate CII [1].

Scientific/Technological

  • IoT, automation and AI have improved monitoring and control of infrastructure but also created new attack vectors via previously isolated Operational Technology (OT) systems now linked to IT networks [5].

Administrative/Governance

  • Multiple overlapping agencies (NCIIPC, CERT-In, sector-CERTs like CSIRT-Power) — coordination and last-mile audit compliance (e.g., 5 of 35 State Load Despatch Centres pending VAPT) remain implementation gaps [2].

6. Recent Developments (last 12-18 months)

  • 2024–25: CERT-In conducted over 9,700 cybersecurity audits across critical sectors [2].
  • 2025: Draft CEA (Cyber Security in Power Sector) Regulations, 2025 finalisation underway [2].
  • Union Budget 2025–26: ₹782 crore allocated for cybersecurity [2].
  • March 2024: Status update — 30/35 State Load Despatch Centres VAPT-compliant [2].
  • 27 May 2026: The Hindu published an explainer on IoT-driven vulnerabilities in critical infrastructure, reiterating the need for a stronger policy framework [5].

7. Prelims Hooks

  • NCIIPC was created under Section 70A of the IT Act, 2000 (amended 2008) [1].
  • NCIIPC was notified on 16 January 2014 [1].
  • NCIIPC functions as a unit of NTRO, under the PMO — not MeitY or MHA [1].
  • NCIIPC's 24x7 helpline number is 1800-11-4430 [1].
  • CERT-In (not NCIIPC) is India's nodal agency for cyber incident response generally [1].
  • CSIRT-Power, a sector-specific CERT for the power sector, was inaugurated in April 2023 [2].
  • No cyberattack has been officially reported to have disrupted actual power grid operations in India, per government statements [2].
  • Union Budget 2025–26 allocated ₹782 crore for cybersecurity [2].
  • Cybersecurity incidents rose from 10.29 lakh (2022) to 22.68 lakh (2024) [2].
  • As of March 2024, 30 of 35 State Load Despatch Centres had completed VAPT audits in the preceding 5 years [2].
  • CERT-In has empanelled 200 organisations for cybersecurity audits [2].
  • The Draft CEA (Cyber Security in Power Sector) Regulations, 2025 are meant to create a dedicated cybersecurity framework for the power sector [2].

8. Mains Relevance

  • GS-III: Internal Security — "Role of external state and non-state actors in creating challenges to internal security"; "Basics of cyber security"; Disaster Management linkages.
  • GS-II: Governance — institutional mechanisms/regulatory bodies for infrastructure protection.
  • Possible question stems: 1. "Discuss the vulnerabilities introduced by digitisation (IoT, AI, automation) in India's critical infrastructure. Suggest a comprehensive policy framework to mitigate these risks." (GS-III) 2. "Examine the institutional architecture for protecting India's Critical Information Infrastructure. How adequate is the coordination between NCIIPC, CERT-In and sector-specific CERTs?" (GS-II/III) 3. "Critical infrastructure protection is as much a governance challenge as a technological one. Comment with reference to India's power sector." (GS-III)

9. Related Topics to Study Next

  • CERT-In and Information Technology Act, 2000/2008 — the overarching statutory-institutional cybersecurity framework.
  • National Cyber Security Policy/Strategy — broader policy context beyond CII.
  • Internet of Things (IoT) and Industrial Control Systems (SCADA) security — technical vulnerability discussed in the article.
  • Disaster Management Act, 2005 — parallel framework for infrastructure-related disruptions.
  • Data Protection (DPDP Act, 2023) — related digital governance/security legislation.
  • National Technical Research Organisation (NTRO) — parent body of NCIIPC.
  • Power sector reforms and grid resilience — CSIRT-Power, CEA regulations.
  • Cyber warfare and hybrid threats in international relations — geopolitical dimension.

10. Common Errors / Trap Areas

  • Confusing NCIIPC (CII protection, under NTRO/PMO) with CERT-In (general incident response, under MeitY) — they are distinct bodies with distinct mandates [1].
  • Misattributing NCIIPC's parent ministry as MeitY or MHA instead of PMO (via NTRO) [1].
  • Assuming a power-grid cyberattack has actually occurred in India — government statements explicitly deny any reported operational disruption [2].
  • Confusing CSIRT-Power (sector-specific, power sector, 2023) with CERT-In (national-level, 2004) [2].
  • Treating the IT Act's CII protection provision as a standalone Act — it is Section 70A of the IT Act, 2000, not a separate statute.

Sources

  1. 1National Critical Information Infrastructure Protection Centre, Government of Indianciipc.gov.in · tier 1
  2. 2Government Strengthens Cybersecurity Across Critical Sectors; Over 9,700 CERT-In Audits Conducted in 2024–25pib.gov.in · tier 1
  3. 3Cybersecurity of Power Gridspib.gov.in · tier 1
  4. 4Strengthening Cybersecurity in Power Sectorpib.gov.in · tier 1
  5. 5How safe is India's critical national infrastructure? — The Hindu (27 May 2026)thehindu.com · tier 4
At the end · practice MCQs
7 questions on this article
Check the answer for each question, or reveal all at once.
Practice MCQs →

Also on 27 May

All 27 May articles →