
When the Grid Is the Target: Inside India's National Cyber Security Strategy
State-backed hackers have breached India's grid control centres, a nuclear plant and its top hospital. India's National Cyber Security Strategy is Tier-1 rated yet never enacted into law: bold in ambition, thin at the grid's edge.
By Sayonsom Chanda
In 2017, ransomware built to hit other targets shut down India's largest container port and left the country the third-worst-hit nation on earth. In the years since, state-backed intruders from China and North Korea have been caught inside the load-dispatch centres that balance India's power grid, the servers of its most prestigious hospital, and the control systems of a nuclear plant. India's answer was a sweeping National Cyber Security Strategy: comprehensive in ambition, Tier-1 rated by the ITU, and yet, remarkably, never actually written into law.

The 2017 wake-up call #
India did not choose the timing of its reckoning with cyber risk; the timing chose India. When the WannaCry and NotPetya ransomware waves swept the world in 2017, India was the third-worst-hit nation, and the damage reached well beyond office laptops. The cascade froze operations at the Jawaharlal Nehru Port Trust, the country's largest container terminal, stranding cargo at a single choke point in the national supply chain. Neither weapon had been built with India in mind. That was precisely the lesson: in a hyper-connected infrastructure, self-propagating malware draws no line between its intended target and the innocent bystander. For a country staking its economic future on the Digital India programme, and taking justified pride in the global success of UPI, the attack was an existential wake-up call.
The 2013 national cyber policy, drafted for a gentler era, had simply not imagined threats of this scale or sophistication. The numbers made the gap vivid: reported cyber incidents in India roughly quadrupled from 53,000 in 2017 to more than 208,000 in 2018. In response, the Data Security Council of India (DSCI) convened industry and government to build a comprehensive twenty-one-area framework that became the intellectual backbone of the draft National Cyber Security Strategy (NCSS) 2020.
A grid in the crosshairs #
If ransomware was the wake-up call, the power grid was where the threat turned strategic. In 2021, Recorded Future revealed that RedEcho, a Chinese state-sponsored group, had compromised four of India's five Regional Load Dispatch Centres using ShadowPad malware, striking at the digital nerve centres that keep supply and demand in balance across the national grid. The campaign intensified almost immediately after the June 2020 Galwan Valley clash (Insikt Group, 2021). By 2022, a related cluster, TAG-38, had targeted seven regional electricity substations near the Ladakh border (Recorded Future, 2022), quietly gathering the access needed to trigger cascading blackouts during a future military crisis.
The grid was not the only critical system in the crosshairs. In September 2019, North Korea's Lazarus Group penetrated the Kudankulam Nuclear Power Plant with DTrack malware, reportedly reaching domain-controller-level access, while related North Korean actors simultaneously probed ISRO during the Chandrayaan-2 mission (ORF, 2019). The pattern has only sharpened since. Russia's AcidRain attack disabled Viasat satellite modems one hour before the invasion of Ukraine; the February 2026 Iran-Israel escalation fused cyber and kinetic strikes; and in May 2025, India's grid absorbed roughly two lakh, or 200,000, cyberattacks during Operation Sindoor (The420.in, 2025). The threat the NCSS was designed to contain has, in short, grown faster than the institutions built to contain it.

Seven institutions, one crowded mandate #
India's cyber defence is run not by one agency but by seven, with overlapping portfolios and mandates. CERT-In serves as both regulator and first responder; its 2022 directive requiring incident reports within six hours is the strictest such rule in the world. The National Critical Information Infrastructure Protection Centre (NCIIPC), reporting directly to the Prime Minister's Office, guards critical infrastructure across six key sectors. The Defence Cyber Agency runs military cyber operations with roughly 1,000 personnel. The Indian Cyber Crime Coordination Centre (I4C) knits together state law-enforcement and has, through its fraud-reporting system, prevented losses exceeding INR 7,130 crore. DSCI led the industry consultations that shaped the framework. And as of 2025, the National Cyber Security Coordinator has been designated the lead body for strategic direction, tasked with pulling these disparate parts into alignment (Carnegie Endowment, 2025).
Which of them matters most? Despite its limited enforcement power, the NCIIPC has the strongest claim. It is the only institution charged with defending systems whose failure would be catastrophic: the power grid and SCADA networks that RedEcho targeted, the nuclear facility systems breached by Lazarus, the satellite ground stations that a Viasat-style strike could disable. The ITU's 2024 Global Cybersecurity Index awarded India coveted Tier 1 status, but flagged organisational measures, precisely this thicket of overlapping mandates, as the country's weakest area (PIB, 2024).
What makes India's strategy different #
Five features set the NCSS apart from the strategies of peer nations. The first is architecture: three pillars, Secure, Strengthen, Synergise, bind domestic capacity and international engagement across twenty-one areas within a single document, a breadth that more narrowly scoped strategies such as Australia's or Singapore's do not attempt. The second is industrial policy: Make-in-India is baked into the strategy through a dual supply-chain framework that separates procured foreign equipment from domestically developed technology, aiming to keep embedded spyware out of critical systems.
The third feature is the one most relevant to the grid: the explicit integration of SCADA and operational-technology (OT) security with enterprise IT. This acknowledges that a grid control centre operates under fundamentally different security assumptions than a corporate network, a distinction many national strategies gloss over. The fourth follows from India's federal structure. State Load Dispatch Centres fall under state commissions with limited cyber expertise, yet they are precisely the assets nation-state actors go after, so the strategy emphasises state-level capacity building with central funding modelled on the eGovernance initiative. The fifth is unique to India's digital stack: as of early 2026, no other country has built a cybersecurity strategy around a real-time payment and identity system on the scale of UPI and Aadhaar. Together, these mark the NCSS as a document shaped by India's own threat landscape and constitutional reality, not imported from a Western template.
The AIIMS attack: a flashpoint that forced action #
No single incident did more to convert cyber policy from paper to practice than the ransomware attack on AIIMS Delhi in late 2022. Some 2 TB of data across five servers, an estimated 40 million patient records including the health records of senior political leaders, were exposed, and the hospital reverted to manual, paper-based record-keeping for more than two weeks. Investigators traced the intrusion to ChamelGang, a group with ties to China and digital footprints leading back to Hong Kong and Henan province.
The response mobilised the machinery the strategy had built: CERT-In led the technical investigation, the Delhi Police's IFSO unit and the National Investigation Agency ran the criminal inquiry, and the National Informatics Centre restored the crippled servers. What they found was damning. The IT estate had not been meaningfully updated in thirty years; there was no network segmentation to contain a breach; and the backup systems had never been tested for their ability to actually restore data. The episode laid bare the gulf between security policy adopted on paper and the reality of systems that predated modern cybersecurity itself. The fallout was concrete: CERT-In issued healthcare-sector security guidelines, generalisable to other services; the six-hour incident-reporting rule was pushed through; and the political sensitivity of the leaked records helped speed the Digital Personal Data Protection (DPDP) Act into law in August 2023, now being rolled out across India in 2026. AIIMS was the flashpoint that turned intention into action.
A web of cyber partnerships #
On paper, India has assembled an impressive web of cyber diplomacy. Bilateral agreements span the United States, Japan, the United Kingdom, Australia, France, Israel, Canada, South Korea, Germany, Singapore and the European Union. At the multilateral level, India sits in the Quad Senior Cyber Group, chairs BIMSTEC cybersecurity cooperation, and joins SCO cyber dialogue alongside China and Russia, even as its delegates help negotiate the UN Convention Against Cybercrime adopted in December 2024. Notably, New Delhi still declines to sign the Budapest Convention, citing data sovereignty and the pointed grievance that it was never invited to help write it (Insights on India, 2024).
Of all these arrangements, the US-India partnership under the iCET/TRUST framework stands apart, the only bilateral technology relationship anchored at National Security Advisor level in both capitals. It has accelerated semiconductor investment with direct supply-chain implications, spurred joint workshops on post-quantum cryptography, and produced the January 2025 cybercrime MoU (ETV Bharat, 2025). The February 2026 Centre of Excellence in Cybersecurity with Israel matters too, drawing on Israel's hard-won experience defending critical infrastructure under sustained attack. And yet India simultaneously keeps a seat at the SCO table, across from the very states whose proxies have been caught inside its grid and nuclear systems. How long that balancing act holds, in a world where cyber conflict is continuous rather than episodic, is an open question.
Can the strategy protect space and nuclear assets? #
Not yet. In theory, the NCSS correctly identifies SCADA and OT protection as a priority, and the February 2026 Space Cyber Security Guidelines, which advise, but do not enforce, six-hour reporting for satellite operators, represent genuine progress. But advice is not armour. Lazarus reached facility-specific malware inside Kudankulam in 2019; Russia neutralised Viasat's modems within sixty minutes of crossing into Ukraine; and in the 2026 Iran-Israel escalation, cyber and kinetic operations were directed against energy infrastructure in the same breath, the integrated attack that Indian planners have war-gamed since RedEcho, now real. The NCIIPC's authority over nuclear and space entities remains advisory, with no penalty for non-compliance, and the Defence Cyber Agency has yet to graduate into the full Cyber Command that an integrated strategic defence demands. Until binding OT-security standards carry real enforcement at every nuclear facility and ISRO ground station, the answer to whether the strategy can safeguard India's space and nuclear assets is no.
Why it works, where it falls short #
By the numbers that flatter it, the NCSS has succeeded. India climbed from 47th in the 2018 Global Cybersecurity Index to Tier 1 by 2024 (PIB, 2024); CERT-In's six-hour reporting rule is the world's strictest; and the DPDP Act, the Telecommunications Act and the National Cyber Reference Framework (NCRF) all flow from it. The awkward truth beneath the accolades is that the strategy itself was never formally enacted into a legal instrument. India's cyber spending, roughly US $225 million, is orders of magnitude below that of comparable economies. The power sector's SCADA systems, the very networks RedEcho and TAG-38 went after, still lack mandatory standards enforceable at the state level, or the trained defenders to guard them. Operation Sindoor showed real resilience, with the grid withstanding 200,000 attacks, but the margin was thinner than anyone should be comfortable with.
Five fixes for the road ahead #

Closing the gap, on this assessment, requires five concrete moves:
Enact the strategy in law, with binding provisions modelled on Australia's Critical Infrastructure Act 2018.
Raise the cyber budget to around 0.25 per cent of the Union budget.
Make the NCRF mandatory for power-sector entities.
Upgrade the Defence Cyber Agency into a full Cyber Command.
Stand up dedicated OT-security centres at every Regional Load Dispatch Centre, staffed by engineers fluent in both power systems and network defence.
That last point is the throughline. India's cyber resilience will ultimately be decided at the grid's operational edge, where electrical engineering and cybersecurity have to become a single discipline rather than two.
Sources #
BreachRx. (2023). India's CERT-In directive.
Carnegie Endowment for International Peace. (2025). Mapping India's cybersecurity administration in 2025.
Communications Today. (2025). Information security spending in India to total $3.4 billion in 2026.
CyberPeace Institute. (2021). WannaCry is not history.
Data Security Council of India. (2020). National Cyber Security Strategy 2020: DSCI submission. NASSCOM.
GBB. (2022). The rise of ransomware: AIIMS cyber attack.
Harro. (2026). CERT-In's space cybersecurity framework.
India TV News. (2025). Fact check: 70% of India's power grid not hit by Pakistan cyberattack.
InsightsIAS. (2024). UN Convention Against Cybercrime.
McKinsey Global Institute. (2019). Digital India: Technology to transform a connected nation.
MediaNama. (2024). China-backed hacker group behind 2022 AIIMS attack.
MIT Technology Review. (2022). Russia hacked an American satellite company.
Observer Research Foundation. (2019). Cyber-attack against KNPP and ISRO.
Press Information Bureau. (2024). India achieves Tier 1 status in Global Cybersecurity Index 2024 (PRID/2057035).
Press Information Bureau. (2025). 9,700+ CERT-In audits in 2024-25 (PRID/2148943).
Programs.com. (2025). Cybersecurity workforce shortage statistics.
Recorded Future. (2022). Continued targeting of Indian power grid assets.
Seqrite. (2025). Operation Sindoor: Anatomy of a cyber siege.
The420. (2025). India blocks 200,000 cyberattacks during Operation Sindoor.
The Hacker News. (2021). Chinese hackers targeted India's power grid.
University of Washington. (2025). Cybersecurity profile 2025: India.