NEW DELHI: Power sector entities will have to ensure that sensitive data, including information hosted on cloud platforms and historical records, is stored in accordance to the new cybersecurity regulations, amid greater reliance on interconnected networks and digital systems, and the need to protect the critical infrastructure from cyber threats.The power sector faces particular risks, as a cyberattack on critical systems can disrupt electricity generation, transmission or distribution, said a power ministry official, adding the sector faced nearly 2 lakh cyberattacks during Operation Sindoor last year, but all attempts were thwarted and the national power system remained operational.The regulations — notified by Central Electricity Authority (CEA) — also require such data to be stored in an encrypted, secure and protected environment. The requirement also extends to vendors, including cloud service providers, handling such data.Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026, notified recently and which will take effect from April 1 next year, will cover entities that own, operate or manage operational technology (OT) infrastructure associated with interconnected power system along with IT infrastructure physically or logically connected to it.For generating companies, captive generating plants and entities having energy storage systems, the regulations will apply to installations of 50 MW and above.Govt had earlier set up CSIRT-Power at CEA in April 2023 as an extended arm of CERT-In, the national agency for responding to cyber-security incidents, to help utilities detect, respond to and manage cyber incidents.The new regulations require entities to report cyber-security incidents to CSIRT-Power and CERT-In within six hours. An incident determined to be cyber sabotage involving critical systems will have to be reported within 24 hours.Power sector organisations will have to segregate IT and OT systems and ensure that OT equipment and services are procured from trusted sources. Remote operation of OT systems, where necessary, will have to be carried out within India through a dedicated communication channel isolated from the internet.
Share your thoughts in the comments
Be respectful · TOI community guidelines
The regulations also require new critical systems to undergo cybersecurity audits, including vulnerability assessment and penetration testing, before commissioning. Critical and high-risk vulnerabilities found during audits will have to be addressed within one month, while medium- and low-risk vulnerabilities will have to be addressed within three months.Organisations will also have to appoint a chief information security officer (CISO) and alternate CISO, maintain a 24-hour information security function, conduct annual self-audits and maintain cyber-risk assessments, asset registers and incident-response plans.The framework also mandates cyber-security training for personnel involved in operating and maintaining critical systems, besides continuous monitoring of IT and OT systems and periodic cybersecurity exercises.








Leave a Reply