India’s Power Sector Is Redrawing Its Cyber Security Perimeter

The CEA’s new Cyber Security in Power Sector Regulations bring vendors, software, cloud systems, distributed resources and board-level accountability into the security framework for the power system.

Cybersecurity in the power sector has generally been associated with networks, control systems and critical infrastructure. The Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026 point to a broader conception of what needs to be protected.

Notified on 31 July 2026, the regulations cover Operational Technology (OT) and connected Information Technology (IT) infrastructure, cyber governance, incident reporting, procurement, vendors, critical systems, distributed generation resources, audits, data protection and crisis management. The main provisions come into force from 1 April 2027, while certain provisions will take effect on dates to be separately notified by the Central Electricity Authority (CEA) with prior Central Government approval.

The regulations goes beyond the cybersecurity function. They change who is responsible, when cybersecurity enters the lifecycle of an asset, and how cyber risk is connected with the continued operation of the power system.

From IT security to operational resilience

The regulations apply to entities owning, operating or managing OT infrastructure associated with the interconnected power system, along with IT infrastructure physically or logically connected to it. Generating companies, captive generating plants, and organisations having Energy Storage Systems are covered where installed capacity is 50 MW or more. Power exchanges and OTC platforms are also included, subject to specified exceptions.

The framework requires OT systems to be physically isolated from the internet and IT systems. Where business requirements make interconnection necessary, it can be permitted subject to hardened logical separation, risk assessment, approval by the head or board and continuous monitoring. OT environments must also be segmented according to criticality, security requirements and risk assessment.

The reason is straightforward. A compromise of an office IT system may disrupt business processes. A compromise of OT can affect the operation of physical power infrastructure.

The regulations therefore link cybersecurity with business continuity. An entity’s Cyber Security Policy must align with its Business Continuity Plan and cover its OT and IT environments, as applicable.

Cybersecurity, in this framework, is ultimately about keeping critical operations running and restoring them safely when digital systems are compromised.

The cyber security perimeter extends to vendors

The regulations bring the technology supply chain into the security framework.

“Vendor” is defined broadly to include OEMs, suppliers, system integrators, contractors and cloud service providers, among others. Vendors supplying systems to covered entities must provide recovery procedures, security patches and updates, end-of-life information, bills of material and mechanisms for vulnerability disclosure.

For critical infrastructure, knowing who supplied a system is only the starting point. Operators also need visibility into what sits inside it, how its components are maintained, when support will end, how vulnerabilities will be disclosed and who can access it.

The regulations reinforce this through requirements on cyber supply-chain risk management and procurement from trusted sources.

Cybersecurity therefore moves into procurement and vendor management. Technical specifications, contracts and project processes will have to account for risks that may previously have been treated as the supplier’s responsibility.

Cyber security moves upstream

Cybersecurity also enters the asset lifecycle before a system begins operating.

Before commissioning a new critical system, or replacing one, entities must conduct cybersecurity audits, including vulnerability assessment and penetration testing. Procurement processes must include Factory Acceptance Tests and Site Acceptance Tests covering cybersecurity requirements.

Software changes receive similar treatment. The Cyber Security Policy must distinguish between updates requiring prior cybersecurity audit clearance and those that can be assessed during the next audit. The Second Schedule identifies updates affecting core generation, transmission, distribution or load-management processes, access controls, third-party integrations, security protocols and incident-response systems among those that may require prior audit.

A software change in a critical power system can therefore become an operational-risk decision, rather than a routine IT activity. Cybersecurity has to be considered when an asset is specified, procured, tested, commissioned and modified.

The grid edge is part of the equation

The regulations specifically address Distributed Generation Resources of prosumers.

Vendors associated with these resources are responsible for securing applications, monitoring and control servers, real-time data and cloud-hosted information, with such data required to reside within India. Remote access and operation of grid-connected devices, and the exchange of real-time data with remote applications, aggregators and distribution licensees, must use secure channels with mutual authentication and encryption.

This provision reflects a changing power system.

As rooftop solar, storage, aggregation and digitally controlled distributed resources expand, more intelligence and control sit outside conventional utility infrastructure. The distinction between the utility’s digital environment and the customer’s digital environment becomes less useful when both can interact with the grid.

The cybersecurity perimeter therefore follows the connections through which data, commands, and control can move.

Cybersecurity reaches the boardroom

The regulations establish a clear governance structure. Every covered entity must designate a Chief Information Security Officer (CISO) and Alternate CISO. The CISO reports to the head of the entity, the role is ring-fenced for cybersecurity matters, and a dedicated Information Security Division operating round the clock is required. The Cyber Security Policy and Cyber Crisis Management Plan are subject to senior-level approval and review.

Incident management also carries defined timelines. Cybersecurity incidents must be reported within six hours to CSIRT-Power and CERT-In. Where an incident is concluded to be cyber sabotage in a critical system, the reporting period is 24 hours.

Major audit findings, including critical and high-risk vulnerabilities, must be reported to the head or board of the entity. The Ministry of Power’s CISO may also, in specified circumstances, seek audit closure reports and initiate third-party verification.

Cyber risk is consequently becoming a management and governance issue. Boards will need visibility into the systems that matter, the parties that can access them, the risks attached to those relationships and the organisation’s ability to recover from a compromise.

A cyber incident is also a confidence event

The regulations recognise another dimension of resilience. A Cyber Crisis Management Plan must identify stakeholders, assign roles and responsibilities and establish how internal and external stakeholders will be communicated with during a crisis. Entities must also ensure essential communications remain available during a cyber crisis and test their plans through exercises and mock drills.

That matters because a cyber incident affecting power infrastructure does not remain a technical matter for long. Regulators, employees, vendors, customers, investors and other system participants may all need information while the facts are still developing.

The technical response determines how an incident is contained and how quickly operations can be restored. Communication shapes how stakeholders understand the situation and the organisation’s response.

A resilient organisation therefore needs both capabilities: the ability to manage the incident, and the ability to communicate with credibility while managing it.

The perimeter has changed

The regulations contain detailed requirements covering cyber-asset registers, risk assessments, backups, data retention, trusted-source procurement and certification.

Critical-system audits are required at least once every financial year, while critical and high-risk vulnerabilities identified during an audit must be addressed within one month, with appropriate compensatory controls where necessary.

Their wider message is clear. The security of the power system can no longer be considered within the physical boundary of a utility. It extends to the technology it procures, the vendors that maintain it, the software running it, the distributed resources connected to it and the people responsible for governing and communicating about it.

The challenge before April 2027 for the power sector is therefore larger than meeting a new compliance framework. It is to build the ability to operate, recover, and retain stakeholder confidence when the digital systems supporting the physical power system come under stress.

The CEA has widened the perimeter that the sector must protect. The sector now has to decide whether its governance, procurement, operational and communication practices are ready to match it.

As India’s power system becomes more digital and distributed, is the sector’s cybersecurity thinking keeping pace with the changing perimeter?

_________________________

Want more insights like this?

Click here to join our WhatsApp Channel for strategic communications insights, leadership perspectives, industry observations, in-depth analysis, and practical communications tips.

________________________

Also read: Can a Smart Meter Be Accurate and Still Fail the Consumer?

When Authority Scales Faster Than Judgment

India’s Connectivity Standards Are Being Rewritten

What If the Most Important Skill in Legal Practice Is the One Lawyers Talk About Least?