Energy & utilities cybersecurity · India
From April 2027, grid security is a regulation, not a guideline.
On 31 July 2026 the Central Electricity Authority notified the Cyber Security in Power Sector Regulations, 2026, in force from 1 April 2027. This page turns them into a list of what to have ready — and the evidence to prove it — clears up five myths starting with the air gap, and shows how testing works around live control systems.
Reviewed 24 September 2026 · 8 sources cited
The short answer
Indian power-sector entities fall under the CEA (Cyber Security in Power Sector) Regulations, 2026 from 1 April 2027. They require a qualified CISO and alternate reporting to the head of the organisation, incident reports to CSIRT-Power and CERT-In within six hours, critical networks isolated from the internet, a cyber asset register and a risk plan updated every six months, sensitive data kept encrypted in India, and logs and audit reports retained.
July 2026
The grid has been a target. Now it has a rulebook.
The Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026 were notified on 31 July 2026 under the Electricity Act, 2003, with MeitY’s concurrence, and come into force on 1 April 2027 — some provisions later, by separate orders. They apply to entities that own, operate or manage operational technology linked to the interconnected power system, and the IT connected to it. For generating companies, captive plants and energy storage, they apply to installations of 50 MW and above; power exchanges are covered under specified provisions.
They set up CSIRT-Power, under the Ministry of Power, as the sector’s coordinating agency, with directives that bind both utilities and their vendors. Each entity needs a CISO and an alternate — senior, Indian citizens and residents, engineers with at least fifteen years in power or IT, reporting to the head of the organisation, serving at least three years and working only on cyber security. Incidents go to CSIRT-Power and CERT-In within six hours. IT networks containing critical information infrastructure must be isolated, physically or logically, from the internet and other networks. There must be a cyber asset register, a risk assessment and mitigation plan updated every six months, a crisis management plan vetted by CERT-In, and logs and audit reports kept for set periods.
The reason is not hypothetical. In February 2021 Recorded Future reported that a China-linked group it called RedEcho had targeted ten Indian power sector organisations, including four of the five Regional Load Despatch Centres that balance the grid. In 2022 it reported likely intrusions at seven or more State Load Despatch Centres in North India, near the Ladakh border. Verizon’s 2026 data puts the motive plainly: of the utility breaches where the motive was known, 71% were espionage.
Testing in this sector is different. Control systems cannot be scanned like office networks: an active probe can restart a controller or drop a protection relay offline. We work passive-first on anything operational, test the IT side and the boundary actively, and do nothing to live control systems without the owner’s written instruction.
Requirement by requirement
The 2026 regulations as a readiness list
What each main requirement means in practice, and the evidence CSIRT-Power or an auditor is likely to ask for.
| Requirement | What it means in practice | Evidence to keep |
|---|---|---|
| CISO and alternate CISO | Senior, Indian citizen and resident, engineering background, 15+ years’ experience, reporting to the head of the organisation, at least three years in post, cyber security only; contact details published | Appointment orders, reporting line, and the published contact |
| Six-hour reporting | Incidents reported to CSIRT-Power and CERT-In within six hours; a separate timeline where an incident is found to be cyber sabotage of critical systems | A runbook naming who files, and an incident register in CSIRT-Power’s format |
| Isolation of critical networks | IT networks containing critical information infrastructure isolated physically or logically from the internet and other networks | Network diagrams, firewall rules, and test results showing the isolation holds |
| Know your assets and risks | A cyber asset register, and a cyber risk assessment and mitigation plan updated every six months and reviewed every year | The register, the plan and its revision history |
| Policy and crisis plan | Cyber security policy reviewed annually; crisis management plan vetted by CERT-In; CISO reviews compliance every quarter | Policy versions, the CERT-In vetting, quarterly compliance reviews |
| Web services audited first | Public-facing web services deployed only after a cyber security audit | Audit reports and fixes for each public-facing service |
| Safe updates and trusted supply | Software updates tested and confirmed free of vulnerabilities; equipment and services procured from trusted sources | Update test records, supplier records against government guidelines |
| Data kept in India | Sensitive data and backups encrypted and stored exclusively in India | Data-location records for every system and cloud service |
| Logs and records retained | ICT and OT-IT interconnection logs and forensic records for 180 days; incident logs for 365 days; remote-access records for a year; audit reports for three to four years | Retention settings, and proof the logs exist when asked for |
Summarised from reporting of the CEA (Cyber Security in Power Sector) Regulations, 2026; check the notified text and CSIRT-Power’s formats. Some provisions come into force after 1 April 2027 by separate orders. SemperWise is not CERT-In empanelled or an IEC 62443 certification body; where the regulations or CSIRT-Power require either, appoint them directly. General information, not legal advice.
What gets assumed
Five things utilities believe about their cyber risk.
Each is common in control rooms and boardrooms. Each is contradicted by the regulations or the record.
What people assume“Our control systems are air-gapped.”
What is actually trueVery few are, in practice: historians feed the office, vendors connect for maintenance, and schedules arrive from despatch centres. The regulations assume those links exist — they require OT-IT interconnection logs and remote-access records to be kept. What they demand is isolation of critical networks that is designed, documented and shown to hold, not assumed.
What people assume“The regulations don’t matter until 2027.”
What is actually trueThey apply from 1 April 2027, but a qualified CISO, a complete asset register, a six-monthly risk plan and 180 days of logs cannot be produced in March. CERT-In’s six-hour reporting already applies today.
What people assume“Attackers go after the big grid operators, not us.”
What is actually trueThe campaign Recorded Future reported in 2021 targeted ten power sector organisations — four of the five Regional Load Despatch Centres among them — and two seaports; in 2022 it reported likely intrusions at seven or more State Load Despatch Centres. Espionage campaigns map the whole system, not only its biggest nodes.
What people assume“Our renewable plant is too small to be covered.”
What is actually trueFor generating companies, captive plants and storage, the regulations apply at 50 MW and above — which includes many solar and wind parks. Below that, many plants are still monitored and managed remotely through vendor platforms that deserve the same scrutiny.
What people assume“A reputed vendor means a secure system.”
What is actually trueThe regulations require equipment and services from trusted sources, software updates tested and confirmed free of vulnerabilities before use, and make CSIRT-Power’s directives binding on vendors as well as utilities. Vendor remote access is one of the most common ways into operational networks.
The attack path
From the office network toward the grid
The composite path in utility intrusions, and how each step is tested — actively in IT, passively in OT.
-
1
A foothold in IT
A phished login, an exposed remote-access gateway, or a vendor’s maintenance connection with shared credentials.
External perimeter, remote access and vendor connections — tested actively
-
2
Across the corporate network
Weak Active Directory permissions and flat networks carry the attacker toward engineering and operations staff.
Active Directory privilege paths — tested actively
-
3
The IT/OT boundary
Historians, jump hosts, data diodes that are not, and firewall rules that grew over the years. This is where “isolated” is tested for real.
Boundary testing from the IT side; firewall rule review
-
4
SCADA, EMS and substation systems
Operator workstations, SCADA and energy-management servers, remote terminal units and protection relays.
Passive only — traffic capture, asset and firmware inventory, configuration review
-
5
Access to operations
An attacker who can see or change operations at a load despatch centre or a plant — the goal espionage campaigns work toward, quietly.
Most of the work happens before the boundary. If the office network cannot reach the control systems, the rest of the path does not exist — which is exactly what the isolation requirement asks you to demonstrate.
Evidence
What the numbers say about energy and utilities
Campaigns against India’s grid, global utility breach patterns, and the thresholds in the new regulations. Each is linked in the sources.
Verizon’s figures describe utility breaches in its global dataset, not Indian ones specifically.
Next step
Start the evidence now, not in March 2027.
A 30-minute call with a practitioner who scopes around live control systems. No charge, and no obligation.
- Where you stand against the 2026 regulations, requirement by requirement
- A written line between what is tested actively and what passively
- How to show that critical networks are isolated, not just drawn that way
- A fixed price, with a retest of every fix included
Where SemperWise fits
What we do for power and utility companies
Services are people doing the work; SemperWise One is the platform that keeps the evidence current between engagements. Nothing is sent to a live control system without your written instruction.
“Is our isolation real?”
Network and Active Directory testing from the IT side up to the OT boundary, with firewall rule review — proof that critical networks are isolated.
Network penetration testing“Our public-facing services.”
Testing of customer portals, billing and outage apps before deployment, as the regulations require.
Web application testing“Our plants and substations.”
Passive review of control networks — asset and firmware inventory from traffic, configuration and architecture review — the same production-safe approach set out on our manufacturing page.
VAPT, OT-safe“The asset register and risk plan.”
In SemperWise One, an asset inventory, a risk register and a compliance calendar that keep the six-monthly risk plan and quarterly reviews on schedule.
Compliance automation“Our vendors and their remote access.”
Vendor assessments against trusted-source and update requirements, with remote-access arrangements recorded and reviewed.
Vendor and questionnaire tooling“The six-hour report.”
Incident-reporting runbooks for CSIRT-Power and CERT-In, and tabletop exercises with operations and IT together.
CERT-In compliance“What do we expose?”
Continuous discovery of internet-facing systems — remote-access gateways, forgotten web services, exposed management pages.
Attack surface managementTerms
Power-sector security terms, defined
- CEA regulations
- The Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026, notified on 31 July 2026 and in force from 1 April 2027.
- CSIRT-Power
- The Computer Security Incident Response Team for the power sector, under the Ministry of Power; the sector’s coordinating agency, whose directives bind utilities and vendors.
- CII
- Critical information infrastructure — systems whose incapacity would have a debilitating impact on national security, the economy or public safety.
- RLDC · SLDC
- Regional and State Load Despatch Centres — the control rooms that balance supply and demand on the grid in real time.
- OT
- Operational technology — the systems that monitor and control physical equipment, from SCADA servers to protection relays.
- SCADA · EMS
- Supervisory control and data acquisition, and energy management systems — the software that runs grid and plant operations.
- IT/OT boundary
- The point where office and business networks meet operational networks — where isolation is designed, and where it most often fails.
- Air gap
- Complete physical separation of a network from all others; rarely true of operational networks in practice.
- Cyber asset register
- The inventory of IT and OT assets the regulations require every covered entity to maintain.
- CCMP
- Cyber crisis management plan; under the 2026 regulations it must be vetted by CERT-In.
- Trusted source
- A supplier of equipment or services that meets the central government’s trusted-source guidelines.
- Passive testing
- Assessment that observes rather than sends traffic — capturing and analysing what the network already carries.
Questions
Energy & Utilities security — answered.
What buyers in this sector ask us before they commit to anything.
What are the CEA Cyber Security in Power Sector Regulations, 2026?
Binding regulations made by the Central Electricity Authority under the Electricity Act, 2003, with MeitY’s concurrence, notified on 31 July 2026 and in force from 1 April 2027, with some provisions to follow by separate orders. They set up CSIRT-Power, require a qualified CISO and alternate, six-hour incident reporting, isolation of critical networks, an asset register and risk plan, data kept encrypted in India, and retention of logs and audit reports.
Who do the 2026 power sector regulations apply to?
Entities that own, operate or manage operational technology linked to the interconnected power system, and the IT systems connected to it. For generating companies, captive generating plants and energy storage, the threshold is installations of 50 MW and above. Power exchanges and over-the-counter platforms are covered under specified provisions.
How fast must a power utility report a cyber incident?
Within six hours, to CSIRT-Power and CERT-In, under the 2026 regulations; CERT-In’s own Directions already require six-hour reporting today. A separate timeline applies where an incident is found to be cyber sabotage of critical systems. Keep an incident register in the format CSIRT-Power prescribes, name who files the report out of hours, and rehearse it with operations and IT together — the clock starts when the incident is noticed, not when it is understood.
What does the CISO requirement involve?
A senior manager appointed as CISO, with an alternate, and neither post left vacant. As reported, the CISO must be an Indian citizen and resident with an engineering degree or equivalent and at least fifteen years in the power or IT sector, report directly to the head of the organisation, serve at least three years, focus only on cyber security, and have contact details published.
Are our control systems really air-gapped?
Test it rather than assume it. Historians, vendor maintenance links, schedule feeds and engineering laptops usually connect operational networks to something. The regulations require critical networks to be isolated physically or logically and require OT-IT interconnection logs and remote-access records to be kept — so isolation has to be demonstrable. Testing from the IT side toward the boundary shows whether it holds.
Can you test OT and SCADA systems safely?
Yes, by not touching them actively. We test IT and the IT/OT boundary actively, and assess control networks passively — capturing traffic, building asset and firmware inventories, and reviewing configuration and architecture. Nothing is sent to live control systems, relays or controllers without the owner’s written instruction; where active testing is genuinely needed, it belongs on a test bench or spare equipment.
Does this apply to renewable energy plants?
Solar, wind and hybrid plants of 50 MW and above, and storage at that size, are within the regulations’ thresholds for generating companies and storage. Where such plants are monitored and controlled remotely through inverter and plant-management platforms, that makes vendor access, remote monitoring portals and the plant’s link to the despatch centre the places to look first.
What about gas and water utilities?
The CEA regulations cover the power sector. Gas distribution and water utilities face the same operational-technology risks, and CERT-In’s six-hour reporting and log-retention duties apply to them as they do to any organisation in India. The same principles — know your assets, isolate control networks, control vendor access, test passively in OT — carry over directly.
Sources
Checked by our research desk on 24 September 2026. Regulations and figures move; where a number here matters to a decision, follow it to the source.
- CEA notifies cybersecurity in power sector rules 2026 — MediaNama, August 2026
- CEA notifies CEA (Cyber Security in Power Sector) Regulations, 2026 — Renewable Watch, 14 August 2026
- Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026 — InsightsIAS, 17 August 2026
- China-linked group RedEcho targets the Indian power sector amid heightened border tensions — Recorded Future, February 2021
- Continued targeting of Indian power grid assets by Chinese state-sponsored activity group — Recorded Future, 2022
- 2026 Data Breach Investigations Report (utilities) — Verizon, 2026
- Draft Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2024 — CEA, August 2024
- Directions under sub-section (6) of section 70B of the IT Act, 2000 — CERT-In, 28 April 2022
Next step
Ready by April 2027, without touching the grid.
A 30-minute call, no charge. You leave knowing where you stand against the 2026 regulations, what evidence to start collecting, and how your IT and OT can be tested without risk to live control systems — with a written scope and fixed price if the work makes sense.