0.0992
7667766266
x

Cyber Security Rules for Power Sector

iasparliament Logo
August 18, 2026

Prelims: Current events of national and international relations | Science and Technology

Why in news?

Recently the Central Electricity Authority (CEA) notifies new regulations to protect power sector from cyber-attack.

  • Effective from – April 1, 2027.
  • Power sector faced nearly 2 lakh cyberattacks during Operation Sindoor, all of which were discontented.
  • CoverageApplies to entities owning, operating or managing
    • Operational Technology (OT) infrastructure linked to the interconnected power system.
    • IT infrastructure physically or logically connected to OT systems.
  • For generating companies, captive plants and energy storage systems - 50 MW and above.
  • Key data security measures
    • Sensitive data, including cloud-hosted and historical data, must be encrypted, securely stored, protected from unauthorised access.
    • Requirements also apply to vendors and cloud service providers.
  • Cyber Incident Reporting
    • Cybersecurity incidents must be reported to CSIRT-Power and CERT-In within 6 hours.
    • Cyber sabotage involving critical systems: Report within 24 hours.
  • IT–OT Security
    • Mandatory segregation of IT and OT systems.
    • OT equipment/services must be procured from trusted sources.
    • Remote OT operations, where required, must:
      • Be conducted within India.
      • Use a dedicated communication channel isolated from the internet.
  • Cybersecurity Audits – New critical systems must undergo cybersecurity audits, vulnerability Assessment, penetration Testing (VAPT) before commissioning.
  • Vulnerability remediation
    • Critical/High – Within 1 month
    • Medium/Low – Within 3 months
  • Institutional Requirements
    • Appointment of Chief Information Security Officer (CISO) and Alternate CISO.
    • 24×7 information security function.
    • Annual self-audits and maintenance of:
      • Cyber-risk assessments
      • Asset registers
      • Incident-response plans.
  • Capacity Building & Monitoring
    • Mandatory cybersecurity training for personnel handling critical systems.
    • Continuous monitoring of IT and OT systems.
    • Periodic cybersecurity exercises.
  • Institutional Support
    • CSIRT-Power was established at CEA in April 2023 as an extended arm of CERT-In.
    • Helps power utilities detect, respond to and manage cyber incidents.

                                             CEA rules 2026

Reference

Times of India| Cyber Security Rules for Power Sector

Login or Register to Post Comments
There are no reviews yet. Be the first one to review.

ARCHIVES

sidetext