CEA notifies new cybersecurity regulations for power sector

CEA notifies new regulations to protect power sector from cyber attack

The Central Electricity Authority (CEA) has notified the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026, which will take effect from April 1, 2027, according to Medianama, or April 1, 2026, according to Times of India. The rules mandate power sector entities to store sensitive data, including cloud-hosted information and historical records, in an encrypted and secure environment within India.

CEA notifies new cyber security rules for power sector

Entities must appoint a chief information security officer (CISO) who is an Indian citizen and resident, and an alternate CISO. Cybersecurity incidents must be reported to CSIRT-Power and CERT-In within six hours, while cyber sabotage involving critical systems must be reported within 24 hours. The regulations apply to entities that own or manage operational technology (OT) infrastructure linked to the interconnected power system, including generating companies with installations of 50 MW and above.


Sources (2): timesofindia.indiatimes.com, medianama.com

This story was synthesised by AI from the 2 sources linked above. Methodology and corrections.

Updated: this story now draws on 2 sources.

Ask their opinion on this story
They have read this article, our coverage, and the web.
AI simulations of historical figures. Responses are generated from the historical record, not authentic statements.

0 Votes: 0 Upvotes, 0 Downvotes (0 Points)

Share your opinion

Loading Next Post...
Search Trending
Ask their opinion
Loading

Signing-in 3 seconds...

Signing-up 3 seconds...

All fields are required.