
The Central Electricity Authority (CEA) has notified new regulations requiring power sector entities to store sensitive data, including information on cloud platforms and historical records, in an encrypted and secure environment. The…
The Central Electricity Authority (CEA) has notified new regulations requiring power sector entities to store sensitive data, including information on cloud platforms and historical records, in an encrypted and secure environment. The Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026, which take effect from April 1 next year, apply to entities owning or managing operational technology (OT) and connected IT infrastructure. For generating companies and energy storage systems, the rules cover installations of 50 MW and above.
A power ministry official said the sector faced nearly 2 lakh cyberattacks during Operation Sindoor last year, but all attempts were thwarted. The new rules mandate reporting cyber-security incidents to CSIRT-Power and CERT-In within six hours, with cyber sabotage involving critical systems reported within 24 hours. Entities must segregate IT and OT systems, procure OT equipment from trusted sources, and ensure remote operation of OT systems is carried out within India through an isolated communication channel.
New critical systems must undergo cybersecurity audits before commissioning, with critical vulnerabilities fixed within one month. Organisations must appoint a chief information security officer (CISO) and an alternate CISO, maintain a 24-hour security function, conduct annual self-audits, and provide cybersecurity training for personnel operating critical systems.
Source: timesofindia.indiatimes.com
This story was synthesised by AI from the source linked above.