India’s power sector must comply with new cybersecurity rules (AI-generated image) NEW DELHI: Power sector entities will have to ensure that sensitive data, including information hosted on cloud platforms and historical records, is stored in accordance to the new cybersecurity regulations, amid greater reliance on interconnected networks and digital systems, and the need to protect the critical infrastructure from cyber threats.The power sector faces particular risks, as a cyberattack on critical systems can disrupt electricity generation, transmission or distribution, said a power ministry official, adding the sector faced nearly 2 lakh cyberattacks during Operation Sindoor last year, but all attempts were thwarted and the national power system remained operational.The regulations — notified by Central Electricity Authority (CEA) — also require such data to be stored in an encrypted, secure and protected environment. The requirement also extends to vendors, including cloud service providers, handling such data.Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026, notified recently and which will take effect from April 1 next year, will cover entities that own, operate or manage operational technology (OT) infrastructure associated with interconnected power system along with IT infrastructure physically or logically connected to it.For generating companies, captive generating plants and entities having energy storage systems, the regulations will apply to installations of 50 MW and above.Govt had earlier set up CSIRT-Power at CEA in April 2023 as an extended arm of CERT-In, the national agency for responding to cyber-security incidents, to help utilities detect, respond to and manage cyber incidents.The new regulations require entities to report cyber-security incidents to CSIRT-Power and CERT-In within six hours. An incident determined to be cyber sabotage involving critical systems will have to be reported within 24 hours.Power sector organisations will have to segregate IT and OT systems and ensure that OT equipment and services are procured from trusted sources. Remote operation of OT systems, where necessary, will have to be carried out within India through a dedicated communication channel isolated from the internet.Join conversationView All Comments →Share your thoughts in the commentsInsightfulAgreeDisagreeSkepticalConcerningPromisingWorth ReadingBig DevelopmentPost CommentBe respectful · TOI community guidelinesThe regulations also require new critical systems to undergo cybersecurity audits, including vulnerability assessment and penetration testing, before commissioning. Critical and high-risk vulnerabilities found during audits will have to be addressed within one month, while medium- and low-risk vulnerabilities will have to be addressed within three months.Organisations will also have to appoint a chief information security officer (CISO) and alternate CISO, maintain a 24-hour information security function, conduct annual self-audits and maintain cyber-risk assessments, asset registers and incident-response plans.The framework also mandates cyber-security training for personnel involved in operating and maintaining critical systems, besides continuous monitoring of IT and OT systems and periodic cybersecurity exercises.Get the latest India News and Live updates. Download the TOI app.About the AuthorAtul MathurAtul Mathur is a Senior Assistant Editor at The Times of India with over 27 years of experience in journalism. Based in Delhi, he has spent much of his career reporting on governance, public policy and politics, churning out researched, data-driven stories that impact daily lives. Atul is known for investigative depth and strong human-interest narratives as he strives to bring clarity and context to complex issues. He currently tracks the energy sector, writing on power, renewable energy, coal and mines.Read MoreEnd of ArticleFollow Us On Social MediaVideosAir India Express Passenger Booked After Pistol Goes Off At Varanasi Airport During Security Check‘Derogatory’: PM Modi’s ‘Dimaagi Naxals’ Remark Triggers Row; Congress, CJP, Left Parties Hit BackActivist Devendra Mahto Stopped From Tiranga March As Jharkhand Student Protest Escalates On I-Day‘Came From The Top’: Mahua Moitra Alleges Late-Night Pressure, Seeks Speaker Om Birla’s InterventionDid Congress Leaders Signal Stop? Viral Vande Mataram Video Sparks Political Firestorm In New DelhiIndia Signs ₹1,577 Crore Drone Deals As Army Powers Up Precision Strikes And Unmanned WarfareAjit Doval Breaks Silence On Operation Sindoor, Reveals PM Modi’s Immediate Response After PahalgamPM Modi From Red Fort: India’s Self-Reliance Push, Semiconductor Boom And Manufacturing SurgeRahul Gandhi, Kharge Skip Red Fort Event Again As Congress Flags Threats To Democratic InstitutionsPM Modi From Red Fort: India’s Self-Reliance Push, Semiconductor Boom And Manufacturing Surge123Photostories8 foods that attract insects in your kitchen without you realising itHow to remove Rahu’s negative energy according to your birth date5 things parents should never let others do to their child at a social gatheringInside Karan Kundrra and Tejasswi Prakash’s opulent Dubai home: Large balconies, a private pool and moreVaani Kapoor goes full maximalist in Mayyur Girotra’s Kutch-embroidered suit, leaving us completely obsessedHimanshi Khurana on battling depression, traumatic childhood and breakup with Asim Riaz over religious differences; says ‘I felt I was betraying God’10 unusual foods from India that tourists are often afraid to try7 Food items naturally rich in vitamin D to add to your dietStop throwing away stale bread: 7 surprisingly useful ways to use itLove quote of the day by Maya Angelou: ‘I sustain myself with the love of family’123Hot PicksMartin Luther King JrRajasthan UCCDelhi trafficJharkhand protestEast Coast Railway GDCE recruitmentMP Class 10, 12 timetableIran warKarnataka bandhUP NEET UG counsellingTop TrendingPM ModiCM VijayBengaluru Namma MetroAsish BanerjeeManan KumarVirender Singh BasoyaJP NaddaWeather TomorrowBengaluru RapidoAbhijeet Dipke
NEW DELHI: Power sector entities will have to ensure that sensitive data, including information hosted on cloud platforms and historical records, is stored in accordance to the new cybersecurity regulations, amid greater reliance on interconnected networks and digital systems, and the need to protect the critical infrastructure from cyber threats.The power sector faces particular risks, as a cyberattack on critical systems can disrupt electricity generation, transmission or distribution, said a power ministry official, adding the sector faced nearly 2 lakh cyberattacks during Operation Sindoor last year, but all attempts were thwarted and the national power system remained operational.The regulations — notified by Central Electricity Authority (CEA) — also require such data to be stored in an encrypted, secure and protected environment. The requirement also extends to vendors, including cloud service providers, handling such data.Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026, notified recently and which will take effect from April 1 next year, will cover entities that own, operate or manage operational technology (OT) infrastructure associated with interconnected power system along with IT infrastructure physically or logically connected to it.For generating companies, captive generating plants and entities having energy storage systems, the regulations will apply to installations of 50 MW and above.Govt had earlier set up CSIRT-Power at CEA in April 2023 as an extended arm of CERT-In, the national agency for responding to cyber-security incidents, to help utilities detect, respond to and manage cyber incidents.The new regulations require entities to report cyber-security incidents to CSIRT-Power and CERT-In within six hours. An incident determined to be cyber sabotage involving critical systems will have to be reported within 24 hours.Power sector organisations will have to segregate IT and OT systems and ensure that OT equipment and services are procured from trusted sources. Remote operation of OT systems, where necessary, will have to be carried out within India through a dedicated communication channel isolated from the internet.
Share your thoughts in the comments
Be respectful · TOI community guidelines
The regulations also require new critical systems to undergo cybersecurity audits, including vulnerability assessment and penetration testing, before commissioning. Critical and high-risk vulnerabilities found during audits will have to be addressed within one month, while medium- and low-risk vulnerabilities will have to be addressed within three months.Organisations will also have to appoint a chief information security officer (CISO) and alternate CISO, maintain a 24-hour information security function, conduct annual self-audits and maintain cyber-risk assessments, asset registers and incident-response plans.The framework also mandates cyber-security training for personnel involved in operating and maintaining critical systems, besides continuous monitoring of IT and OT systems and periodic cybersecurity exercises.