Cybersecurity at nuclear installations accorded highest priority; AERB, external govt agencies assess security at plants: Centre
The Centre stated that cybersecurity at nuclear installations is accorded the highest priority, with security assessed by the Atomic Energy Regulatory Board (AERB) as well as external government agencies
The statement follows reports that a ransomware group published a large number of files described as linked to the Kudankulam Nuclear Power Plant
The published files were reported to originate from a third-party engineering contractor's systems rather than from the plant's own operational control systems
Officials clarified that nuclear plant control systems in India are air-gapped — stand-alone and not connected to the internet or any outside network — distinguishing this incident from a breach of reactor safety or control systems
Atomic Energy Regulatory Board (AERB)
AERB is India's independent nuclear and radiological safety regulator, constituted on 15 November 1983 under Section 27 of the Atomic Energy Act, 1962, by an order of the President of India. It regulates and oversees safety at all stages of the nuclear fuel cycle and at operating nuclear power plants, distinct from the Department of Atomic Energy (DAE), which is the policy and operating arm (through NPCIL for power generation).
Key Details
- Statutory basis: Atomic Energy Act, 1962, Section 27
- Composition: a full-time Chairman, an ex-officio Member, four part-time Members, and a Secretary
- Functions: framing safety codes/standards, licensing nuclear facilities, safety inspections, and — via bodies like the Safety Review Committee for Operating Plants (SARCOP) — ongoing oversight of operating reactors including Kudankulam
- AERB's role in cybersecurity is part of its broader "defence-in-depth" safety mandate, covering physical, radiological, and information/cyber security of nuclear facilities
AERB's assessment of the Kudankulam facility's security, cited in the Centre's statement, falls within its statutory mandate to certify that nuclear installations meet safety and security standards, including protection against cyber threats to operational systems.
Air-Gapped Systems and Nuclear Plant Control Architecture
An air-gapped system is a computer or network that is physically isolated from unsecured networks, including the public internet, so it cannot be remotely accessed or compromised over a network connection. Critical infrastructure operators, including nuclear plants, commonly rely on air-gapping as a primary cyber-defence measure for safety-critical control systems (SCADA/ICS), separate from administrative or business IT networks that may be internet-connected.
Key Details
- Nuclear plant reactor control and safety systems are typically kept on isolated, stand-alone networks precisely because a network-based attack on such systems could have catastrophic safety consequences
- Business/administrative systems (used by contractors, vendors, HR, procurement) are commonly internet-connected and therefore more vulnerable — this is where the Kudankulam-linked breach reportedly originated (via a third-party engineering contractor's data)
- Global precedent: the 2010 Stuxnet attack on Iran's Natanz enrichment facility demonstrated that even air-gapped industrial control systems can be compromised via infected removable media, which is why physical/personnel security is treated as part of cyber-defence for nuclear facilities
The distinction between the compromised contractor systems and the air-gapped reactor control systems is the technical basis for the government's assurance that the breach did not compromise nuclear plant safety or security functions.
Institutional Framework for Cybersecurity of Critical Infrastructure
India's cybersecurity governance for critical sectors operates through two complementary bodies under the Information Technology Act, 2000. CERT-In (Indian Computer Emergency Response Team), established in 2004 under Section 70B of the IT Act and functioning under the Ministry of Electronics and IT (MeitY), is the national nodal agency for cybersecurity incident response across the general internet ecosystem. NCIIPC (National Critical Information Infrastructure Protection Centre), operating under the National Technical Research Organisation (NTRO), has the narrower mandate of protecting notified Critical Information Infrastructure (CII) sectors.
Key Details
- Legal basis: Sections 70, 70A, and 70B of the IT Act, 2000 empower government to designate "protected systems" (Section 70) and establish NCIIPC (Section 70A) and CERT-In (Section 70B)
- NCIIPC's defined CII sectors include banking/finance/insurance, power and energy, telecom, transport, health, and strategic/public enterprises — nuclear power generation falls within this critical-sector ambit
- CERT-In issues cybersecurity directions, alerts, and mandatory incident-reporting timelines (six hours for specified incident categories under its 2022 directions)
- For a facility like Kudankulam, response coordination typically spans AERB (nuclear-safety regulator), CERT-In (incident response), NCIIPC (CII protection), and the operating entity NPCIL (Nuclear Power Corporation of India Limited)
The Centre's statement that "external government agencies" also assess security at nuclear plants refers to this multi-agency architecture — AERB for nuclear-safety-specific oversight, alongside CERT-In and NCIIPC for the broader cybersecurity and critical-infrastructure-protection mandate under the IT Act.
- AERB constituted: 15 November 1983, under Section 27 of the Atomic Energy Act, 1962
- CERT-In established: 2004, under Section 70B of the IT Act, 2000; NCIIPC established under Section 70A
- Kudankulam Nuclear Power Plant: India's largest nuclear power plant by capacity, located in Tamil Nadu, built with Russian collaboration (VVER reactor technology)
- Reported breach: nearly 19,000 files linked to a third-party engineering contractor (Units 3 and 4 construction-related data), not the plant's operational control systems
- CERT-In mandatory incident reporting window: 6 hours for specified categories of cybersecurity incidents (2022 directions)
- Operating entity for Indian nuclear power plants: Nuclear Power Corporation of India Limited (NPCIL), under the Department of Atomic Energy