CEA notifies new regulations to protect power sector from cyber attack

CEA notifies new regulations to protect power sector from cyber attack


India’s power sector must comply with new cybersecurity rules (AI-generated image)

NEW DELHI: Power sector entities will have to ensure that sensitive data, including information hosted on cloud platforms and historical records, is stored in accordance to the new cybersecurity regulations, amid greater reliance on interconnected networks and digital systems, and the need to protect the critical infrastructure from cyber threats.The power sector faces particular risks, as a cyberattack on critical systems can disrupt electricity generation, transmission or distribution, said a power ministry official, adding the sector faced nearly 2 lakh cyberattacks during Operation Sindoor last year, but all attempts were thwarted and the national power system remained operational.The regulations — notified by Central Electricity Authority (CEA) — also require such data to be stored in an encrypted, secure and protected environment. The requirement also extends to vendors, including cloud service providers, handling such data.Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026, notified recently and which will take effect from April 1 next year, will cover entities that own, operate or manage operational technology (OT) infrastructure associated with interconnected power system along with IT infrastructure physically or logically connected to it.For generating companies, captive generating plants and entities having energy storage systems, the regulations will apply to installations of 50 MW and above.Govt had earlier set up CSIRT-Power at CEA in April 2023 as an extended arm of CERT-In, the national agency for responding to cyber-security incidents, to help utilities detect, respond to and manage cyber incidents.The new regulations require entities to report cyber-security incidents to CSIRT-Power and CERT-In within six hours. An incident determined to be cyber sabotage involving critical systems will have to be reported within 24 hours.Power sector organisations will have to segregate IT and OT systems and ensure that OT equipment and services are procured from trusted sources. Remote operation of OT systems, where necessary, will have to be carried out within India through a dedicated communication channel isolated from the internet.

Share your thoughts in the comments