Cyber Security Protects Systems. What Protects Stakeholder Confidence?

– By Mayuri Singh and Nishant Saxena

A rooftop solar inverter is no longer just electrical hardware. It is a connected digital asset linked to communication devices, dataloggers, monitoring systems, APIs and cloud infrastructure. The risk, therefore, is not limited to whether the equipment functions. It also concerns whether the organisation can explain, protect and take responsibility for the digital environment around it.

The Ministry of New and Renewable Energy’s latest office memorandum under the PM Surya Ghar programme requires applications, associated monitoring and control servers, and real-time data, including information hosted on cloud platforms, to be stored in an encrypted, secure and protected environment within India. It also requires inverter manufacturers to provide daily generation data through an API to the National Portal.

These are specific compliance obligations for inverter manufacturers. For energy companies, utilities and other participants in the connected power ecosystem, however, they raise a broader question:

Can the organisation explain its connected infrastructure clearly, establish who is accountable for what, and communicate credibly if that infrastructure is compromised or disrupted?

This is where cybersecurity acquires a strategic communications dimension.

Making the invisible understandable

The MNRE office memorandum requires inverter manufacturers to provide written confirmation to REC, with a copy to MNRE, within 30 days. The prescribed declaration covers India-based storage of applications, servers and real-time data, daily generation-data sharing through the National Portal API and continuing compliance. It also requires inverter and datalogger details, the location of servers or cloud infrastructure and an official Point of Contact.

These requirements are important not only because they create compliance obligations. They also require an organisation to understand its own digital environment well enough to make specific representations about it.

A company must know where information resides, how it is collected, transferred and handled, which systems and vendors are involved, who is responsible for each part of the technology chain, who can answer questions when a stakeholder seeks clarification. This internal understanding must then be converted into an assurance that an external stakeholder can assess.

A regulator may need evidence of compliance. A customer may want to know how data is handled. An investor may be concerned about operational resilience. A distribution licensee may require clarity on system responsibility. These audiences do not need identical information, but each needs an answer that is accurate, relevant and credible.

The communications challenge is therefore not to simplify technical information indiscriminately. It is to translate complexity without losing accuracy, so that each stakeholder can understand what matters to them and make an informed judgment.

An organisation that cannot explain its own digital environment will find it difficult to establish confidence in that environment.

Responsibility across the technology chain

The physical architecture of rooftop solar may appear straightforward. Its digital ecosystem can involve several different actors and systems.

Information may move between the inverter, communication equipment, monitoring systems, cloud infrastructure, distribution-side systems and the National Portal, with different parties responsible for different parts of the chain. Earlier MNRE requirements had already addressed communication protocols involving M2M SIMs and inverter communication devices, dataloggers and RMS for communication with the centralised IoT-SCADA platform.

This creates a communications problem that can remain invisible until an incident occurs.

Technical responsibility may be distributed, but stakeholder accountability cannot remain unclear.

A consumer may approach the installer. The installer may need to consult the inverter OEM. The OEM may depend on another technology provider or cloud-service provider. Meanwhile, a regulator or distribution licensee may seek information from several parties.

The technology chain can therefore have multiple owners. The organisation must still know who owns the explanation.

The Point of Contact required under the MNRE memorandum is a practical expression of this principle. It creates an identifiable channel through which questions and concerns can be routed. The broader question for energy organisations is whether similar clarity exists internally: who establishes the facts, who validates them, who communicates with which stakeholder, and who has authority to speak when the situation is still evolving.

These are strategic communications questions, not merely questions of communications infrastructure.

Cyber resilience has a stakeholder dimension

The broader regulatory direction is visible in the recently notified Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026, which will come into force from 1 April 2027.

The regulations expressly include grid-connected rooftop solar systems within the definition of Distributed Generation Resources. For such resources, vendors are required to ensure secure storage of applications, monitoring and control servers, real-time data and associated historical data within India. They also prescribe secure channels, mutual authentication and encryption for remote access, remote operation and real-time information exchange.

The regulations’ provisions on cyber-crisis management are particularly significant. A Cyber Crisis Management Plan must identify stakeholders and their roles and responsibilities, specify the manner and mode of communication with internal and external stakeholders, and ensure that essential communications remain available during a cyber crisis. The plan must also be tested through exercises and mock drills at least annually.

This has an important implication as communication is no longer simply what happens after a cyber incident. The organisation’s ability to communicate with stakeholders is part of how it prepares for that incident.

A technical disruption can create uncertainty about what has happened, which systems are affected, who is responsible and what stakeholders should do. If an organisation must resolve those questions only after an incident begins, technical recovery is being accompanied by an avoidable governance problem.

The ability to communicate accurately under pressure therefore becomes part of organisational resilience.

Constructing a credible account

A cyber incident rarely arrives as a complete, settled narrative. Information emerges in fragments.

The technical team may know that a system is affected. Legal may be assessing obligations. The regulator may be seeking information. Customers may already be asking questions. Senior management may still be establishing what is known.

Different stakeholders can therefore encounter different pieces of the story. The challenge is to create a coherent account without claiming certainty the organisation does not possess.

That requires distinguishing between what happened, what is known, what remains under investigation, which systems and stakeholders may be affected, who is responsible for the response, and what stakeholders need to know now.

This is not about controlling a narrative. It is about preventing fragmented information from becoming fragmented accountability.

Technical credibility and regulatory compliance remain the foundation of trust. When an incident tests that foundation, stakeholder confidence will also depend on whether the organisation can provide a clear and credible account of its actions.

Strategic communication is not maximum disclosure

Cybersecurity does not call for greater disclosure in every direction.

A regulator may need evidence of compliance. A distribution licensee may require operational information. A customer may need to understand the implications for their data or service. A technology partner may require technical information to address a vulnerability.

These audiences do not need the same information. The task is to determine what should be communicated, to whom, by whom, through which channel and at what point.

That requires judgement about stakeholder expectations, technical accuracy, regulatory obligations, confidentiality and timing. This is disciplined disclosure, not indiscriminate transparency.

It also depends on the quality of the organisation’s internal information.

The CEA regulations require asset registers containing information on ownership, hardware, firmware, software, patches, network architecture, data flows and communication protocols, alongside cyber-risk assessments and mitigation plans.

Primarily, these are cyber-governance requirements. They also have a communications consequence: an organisation cannot communicate credibly about infrastructure it cannot account for internally.

The better the internal understanding of the system, the stronger the foundation for external communication.

From compliance to institutional credibility

The issue extends beyond crisis communication. An energy company increasingly needs to demonstrate, before anything goes wrong, that it understands its digital exposure, knows where responsibility lies and has considered the interests of stakeholders affected by a cyber event.

The CEA regulations assign the Chief Information Security Officer a nodal and coordination role on cyber-security matters, including coordination with stakeholders and oversight of the Cyber Security Policy and Cyber Crisis Management Plan.

Strategic communications brings a complementary discipline to that governance. It asks whether the organisation can translate its technical and regulatory understanding into communication that is accurate, credible and appropriate for each stakeholder.

Before a crisis, that means asking:

→ Can leadership explain the organisation’s cyber exposure without overstating its preparedness?

→ Are accountability lines clear across OEMs, installers and technology providers?

→ Do regulatory submissions, customer communications, and public statements rest on the same verified facts?

→ Have communication responsibilities been tested alongside technical response procedures?

→ Can the organisation communicate uncertainty honestly without creating unnecessary alarm?

These questions are important because cybersecurity can become a reputational issue before it becomes a headline.

An organisation that demonstrates a clear understanding of its systems, responsibilities, and stakeholders builds institutional credibility. One that cannot explain them clearly may face a confidence problem even when the technical issue is contained.

Parting Thoughts

India’s rooftop-solar ecosystem is acquiring a substantial digital layer. The MNRE’s latest office memo brings data location, communication, and accountability into sharper regulatory focus, while the CEA regulations extend cyber responsibilities across vendors and distributed generation resources, and explicitly incorporate stakeholder communication into cyber-crisis management.

The implication goes beyond compliance for energy companies. Cybersecurity protects the system. Strategic communications shapes how the organisation explains that protection, establishes accountability and sustains stakeholder confidence when that protection is tested.

As connected energy assets multiply, the ability to do both will increasingly form part of institutional resilience.

Is your organisation treating cyber resilience as a technology responsibility, or as a leadership and stakeholder responsibility too?

_________________________

Want more insights like this?

Click here to join our WhatsApp Channel for strategic communications insights, leadership perspectives, industry observations, in-depth analysis, and practical communications tips.

________________________

Also read: Can a Smart Meter Be Accurate and Still Fail the Consumer?

When Authority Scales Faster Than Judgment

India’s Power Sector Is Redrawing Its Cybersecurity Perimeter

What If the Most Important Skill in Legal Practice Is the One Lawyers Talk About Least?