Vaishnaw cautions industry about cyberattacks, disruption that may target India's growing chip might
The Union Minister for Electronics and Information Technology cautioned the semiconductor industry to prepare for cyberattacks and other disruptions
The warning noted that India's rising capability to design and manufacture chips could be viewed as a threat by established players in the global chip value chain
The industry was urged to maintain constant vigilance as new investments and fabrication facilities come online under India's semiconductor push
The caution comes amid a broader effort to move India beyond chip packaging into a fuller domestic semiconductor supply chain, including design and fabrication
India Semiconductor Mission (ISM)
The India Semiconductor Mission was approved by the Union Cabinet in December 2021 to build a sustainable semiconductor and display manufacturing ecosystem in India. It provides fiscal incentives for setting up fabs, compound semiconductor units, assembly/testing (ATMP/OSAT) facilities, and chip design infrastructure, and is administered by a dedicated body under the Ministry of Electronics and Information Technology (MeitY).
The cybersecurity caution was issued in the context of this Mission's progress, as India moves from assembly/packaging toward fuller fabrication and design capability, making its facilities and supply chains higher-value targets.
Critical Information Infrastructure Protection — Section 70A, IT Act 2000
Semiconductor fabs, once operational, could plausibly fall within or feed India's "Critical Information Infrastructure" (CII), a category of computer resources whose incapacitation would have a debilitating impact on national security, economy, public health or safety, as recognised under India's cyber law framework.
Key Details
- Section 70A of the Information Technology Act, 2000 (inserted by the 2008 amendment) provides for a national nodal agency to protect Critical Information Infrastructure
- The National Critical Information Infrastructure Protection Centre (NCIIPC) was notified under Section 70A on 16 January 2014 and functions under the National Technical Research Organisation (NTRO)
- Section 70 of the IT Act allows the government to declare any computer resource that directly or indirectly affects the "Critical Information Infrastructure" as a "protected system," with enhanced penalties for unauthorised access
As India's chip manufacturing base expands, its fabs and supply-chain digital systems become candidates for CII-grade protection, linking the minister's warning to this existing statutory framework for safeguarding nationally critical facilities.
CERT-In — National Nodal Agency for Cyber Incident Response
The Indian Computer Emergency Response Team (CERT-In), functioning under Section 70B of the IT Act, 2000, is India's national nodal agency for cyber security incident response, covering collection, analysis, forecasting and coordination of responses to cyber incidents across sectors, including strategic industries.
Key Details
- CERT-In is designated under Section 70B of the IT Act, 2000 to issue guidelines, advisories and alerts on cyber security incidents and coordinate emergency response
- It can call for information from service providers, intermediaries, data centres and body corporates during an incident
- Non-compliance with CERT-In directions can attract imprisonment up to one year or a fine up to ₹1 lakh under Section 70B(7)
Any cyberattacks targeting semiconductor firms, as flagged in the minister's caution, would be handled and coordinated through the CERT-In incident-response framework alongside sector-specific security measures.
Global Semiconductor Geopolitics and Supply Chain Security
Semiconductors are widely regarded as a strategically critical technology because of their centrality to defence, telecommunications, computing and AI systems, making national semiconductor capability a subject of geopolitical competition, export controls, and supply-chain security concerns among major economies.
Key Details
- Existing global semiconductor supply chains are concentrated in a few economies (Taiwan, South Korea, USA, and others), giving rise to "chip war" dynamics involving export controls on advanced chips and manufacturing equipment
- India's semiconductor push is aimed at diversifying this concentrated global supply chain and reducing India's own import dependence on chips
- Rising domestic capability can invite both economic competition and non-conventional threats (cyberattacks, sabotage, IP theft) from actors seeking to preserve existing supply-chain dominance
The minister's caution frames India's semiconductor rise within this broader geopolitical contest, where established players in the chip value chain may see India's growing capability as a competitive threat.
- India Semiconductor Mission approved: December 2021, with ₹76,000 crore outlay (up to 50% fiscal support for fabs)
- ISM 2.0 announced in the 2026-27 Union Budget
- Section 70A, IT Act 2000 (2008 amendment): basis for NCIIPC, notified 16 January 2014, under NTRO
- Section 70B, IT Act 2000: legal basis for CERT-In as national cyber incident response nodal agency
- Section 70B(7): penalty for non-compliance — imprisonment up to 1 year or fine up to ₹1 lakh
- Nodal ministry for ISM: Ministry of Electronics and Information Technology (MeitY)