India's Power Grid Doesn't Need Another Power Plant: It Needs Better Cybersecurity

With growing instances of cybersecurity threats, India's power sector is set for its biggest overhaul, with mandatory governance, audits, data protection, and incident response measures coming into force from April 2027

India's Power Grid, Power Sector, India's Power Sector, Data Protection, Digital Infrastructure

India's power grid is no longer just a network of transmission lines, substations, and power plants. It has evolved into a vast digital infrastructure powered by millions of smart meters, digital control systems, cloud platforms, SCADA, and Operational Technology (OT). As a result, cyberattacks are no longer limited to data theft: they now pose a serious national security threat capable of disrupting the country's electricity supply.

Cyber Security In Power Sector

Against this backdrop, the Central Electricity Authority (CEA) has notified the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026, introducing, for the first time, a comprehensive and mandatory cyber security framework for India's power sector.

The regulations will come into force on April 1, 2027.

In the notification, CEA authorised officer Sharvan Kumar stated that the new framework prescribes uniform and stringent cybersecurity standards for power generation, transmission, and distribution utilities, National, Regional, and State Load Dispatch Centres, as well as power exchanges. The regulations will be mandatory for all power generation entities with an installed capacity of 50 MW or above.

Under the new regulations, every entity must appoint a Chief Information Security Officer (CISO). The CISO will report directly to the head of the organisation, and each entity will be required to establish a dedicated Information Security Division operating round the clock. Organisations must also deploy trained cybersecurity personnel.

Every organisation will also be required to conduct a comprehensive cybersecurity audit at least once every financial year. In addition, all critical systems must obtain ISO/IEC 27001 certification or an equivalent technical security certification.

Sensitive Data Must Remain Within India

The regulations mandate that all sensitive information and data must be securely stored in encrypted form and hosted only within India. This requirement also applies to data stored on cloud infrastructure.

Critical IT and Operational Technology (OT) systems must be segregated from the internet. Where connectivity is operationally essential, it will only be permitted after comprehensive risk assessment, continuous monitoring, and implementation of additional cybersecurity controls.

Stricter Compliance For Vendors

The regulations extend beyond power utilities. System integrators, cloud service providers, and other vendors will also be required to comply with stringent cybersecurity provisions through service-level agreements. Any cybersecurity breach attributable to a vendor can invite regulatory action.

The regulations designate the Computer Security Incident Response Team–Power (CSIRT-Power) as the nodal agency for cybersecurity in the power sector. The agency will collect cyber threat intelligence, issue alerts and advisories, coordinate incident response, and ensure sector-wide compliance with cybersecurity standards.

This is a free story, Feel free to share.

facebooktwitterlinkedInwhatsApp