Cyber resilience starts with sourcing reform

Government departments and public sector enterprises remain at risk not only because institutional strength and regulatory rules are still developing, but also because procurement cycles are painfully slow
Kudankulam Nuclear Power Plant in Tamil Nadu
Kudankulam Nuclear Power Plant in Tamil NaduPhoto|PTI
Updated on

The cybersecurity breach linked to the Kudankulam Nuclear Power Plant, which exposed sensitive contractor files on the dark web, should be a wake-up call for India to tighten cybersecurity procurement rules to better protect critical systems. The Nuclear Power Corporation of India Ltd reported on July 14 that the ransomware group World Leaks had targetted files associated with the plant through an external server operated by a private contractor. Although officials rated the incident as medium severity because the plant’s physical safety was not immediately threatened, the exposure of technical plans, supplier information, inspection records and equipment reviews could enable more sophisticated attacks against contractors and supply chains.

This is the second major cybersecurity breach incident involving Kudankulam after the 2019 breach linked to the North Korean State-backed Lazarus Group, which attempted to break into the plant’s administrative network using the DTrack malware. Kudankulam remains India’s only nuclear power plant operating pressurised water reactors. Although the immediate value of the stolen data may be limited, the second breach shows weaknesses in India’s cyber readiness against espionage and the security of its supply chains.

NPCIL has listed several corrective measures, including tighter audits of contractors and third-party data centres, stronger encryption for classified documents and continuous monitoring of the dark web. These are necessary steps, but they address only part of the problem. The government must also change procurement policies governing cybersecurity technologies.

Government departments and public sector enterprises remain at risk not only because institutional strength and regulatory rules are still developing, but also because procurement cycles are painfully slow. Cybersecurity tenders often take six to seven months to clear procedural steps. By the time new systems are bought, the threat scene has already changed, leaving organisations dependent on outdated technologies. Equally concerning, detailed requests for proposals placed in the public domain may reveal parts of the security system that adversaries could use.

Transparency is equally important. Reports suggest that most cybersecurity incidents in India go unreported, making it harder to identify trends and improve security. Faster reporting, quicker procurement, greater care in handling sensitive technical details and continued investment in cybersecurity skills are all part of the solution. Technology is only part of the answer. Strong institutions, a cyber-aware workforce and timely decision-making are equally important.

X
The New Indian Express
www.newindianexpress.com