Home India Ministry of Power Parliament Question: Cyber Security Measures to Safeguard th...
Date: 2025-12-11 Category: Not Applicable State: Union Government Country: India

Parliament Question: Cyber Security Measures to Safeguard the Country’s Power Grids

Issued by Ministry of Power · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

**Executive Summary** This document is the answer from the Minister of State in the Ministry of Power to Unstarred Question No. 1854 in Lok Sabha, answered on December 11, 2025. It outlines the cyber security measures taken by the Government of India to safeguard the country's power grids. The document details research and development efforts, cybersecurity guidelines and regulations, incident response mechanisms, and audit practices implemented in the power sector. **Key Points / Main Content** * **Research and Development:** * The POWERGRID Centre of Excellence (CoE) in Cybersecurity at IISc Bengaluru has been established to promote research and development in cybersecurity for power grid operations and transmission systems. * **Cyber Security Guidelines and Regulations:** * The Central Electricity Authority (CEA) issued the Cyber Security in Power Sector Guidelines, 2021 to ensure a cyber-secure power ecosystem. * These guidelines provide a comprehensive cyber assurance framework and strengthen cybersecurity governance. * The Draft Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2025 are under finalization to establish a detailed cybersecurity framework. * **Incident Response:** * The Ministry of Power (MoP) established the Computer Security Incident Response Team – Power (CSIRT-Power) at CEA on April 5th, 2023. * CSIRT-Power supports utilities in detecting, responding to, and managing cyber incidents. * MoP has constituted six sub-sectoral Computer Emergency Response Teams (CERTS) for Thermal, Hydro, Transmission, Grid Operation, Renewable Energy, and Distribution. * Each sub-sectoral CERT has been mandated to prepare a sub-sector-specific model Cyber Crisis Management Plan (C-CMP). * **Cybersecurity Implementation in Gujarat:** * Gujarat Energy Transmission Corporation Limited (GETCO) has implemented a comprehensive cybersecurity framework, including stricter access controls, endpoint protection, reduced system exposure, secure encrypted communication, deployment of next-generation firewalls, and antivirus solutions. * **Cybersecurity Status at the National Load Despatch Centre:** * No cybersecurity breaches or successful cyber-attacks have been reported in the operational systems of the National Load Despatch Centre in the past five years. * **Cybersecurity Audits:** * Cybersecurity audits are conducted periodically across the power sector in accordance with the Central Electricity Authority (Cyber Security in Power Sector) Guidelines, 2021. * Audits are carried out by third-party cybersecurity auditors empaneled by CERT-In. * In the past five years, 9 assessments of the Information Technology infrastructure (IT) and 5 assessments of the Operational Technology (OT) infrastructure have been carried out at the National Load Despatch Centre. Details enclosed at Annexure * Cybersecurity audits are periodically conducted across all SLDCs, covering both IT and OT infrastructure. **Impact Analysis** **Central Electricity Authority (CEA)** **Impact** Responsible for implementing and overseeing the Cyber Security in Power Sector Guidelines, 2021. Also for finalizing regulations by 2025. **Action Required** Continue to implement the existing cybersecurity guidelines and finalize the 2025 regulations. **Ministry of Power (MoP)** **Impact** Responsible for overseeing and supporting cybersecurity efforts in the power sector. **Action Required** Oversee the function of the CSIRT-Power and CERTS. **Power Utilities** **Impact** Must adhere to cybersecurity guidelines and regulations and implement appropriate measures to protect their systems. **Action Required** Implement necessary cybersecurity controls, participate in CSIRT-Power activities, and prepare sub-sector-specific Cyber Crisis Management Plans. **State Load Despatch Centres (SLDCs)** **Impact** Subject to regular cybersecurity audits covering both IT and OT infrastructure. **Action Required** Comply with cybersecurity audit requirements and implement necessary remediation measures.

Key Entities Referenced

Cyber Security in Power Sector Guidelines, 2021: Guidelines issued by the Central Electricity Authority to ensure a cyber-secure power ecosystem. Central Electricity Authority (CEA): The regulator that issued the Cyber Security in Power Sector Guidelines, 2021. Ministry of Power (MoP): The ministry responsible for establishing the Computer Security Incident Response Team – Power (CSIRT-Power) and other cybersecurity measures. Computer Security Incident Response Team – Power (CSIRT-Power): Established by the Ministry of Power at CEA to support utilities in detecting and managing cyber incidents. Gujarat: State where cybersecurity measures were implemented in the Gujarat Energy Transmission Corporation Limited (GETCO).
Official Source Record View Original Source →
See Full Document Text
GOVERNMENT OF INDIA MINISTRY OF POWER LOK SABHA UNSTARRED QUESTION NO.1854 ANSWERED ON 11.12.2025 CYBER SECURITY MEASURES TO SAFEGUARD THE COUNTRY’S POWER GRIDS 1854. SHRI PARSHOTTAMBHAI RUPALA: Will the Minister of POWER be pleased to state: (a) whether the Government has carried out any research or study on cyber security measures to safeguard the country’s power grids from potential cyber threats and attacks, if so, the details thereof including the infrastructure and security upgrades implemented in power grids across the country during the last five years particularly in the State of Gujarat; (b) whether the cyber security audits were conducted on the country’s power grids during the last five years and if so, the details thereof, year-wise; and (c) whether there have been any instances of cyber security breaches or attempted cyber attacks on the country’s power grids during this period and if so, the details thereof along with the remedial and preventive measures taken by the Government? A N S W E R THE MINISTER OF STATE IN THE MINISTRY OF POWER (SHRI SHRIPAD NAIK) (a)& (c) : The POWERGRID Centre of Excellence (CoE) in Cybersecurity at the Indian Institute of Science (IISc), Bengaluru has been established to promote research and development in cybersecurity, particularly for power grid operations and transmission systems. Central Electricity Authority (CEA) issued the Cyber Security in Power Sector Guidelines, 2021 to ensure a cyber-secure power ecosystem. These guidelines provide a comprehensive cyber assurance framework and strengthen the cybersecurity governance structure across all entities in the power sector. Further, the Draft Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2025 are under finalization to establish a detailed cybersecurity framework for the power sector. ….. 2– 2 – Ministry of Power (MoP) established the Computer Security Incident Response Team – Power (CSIRT-Power) at CEA on 5th April, 2023 as an extended arm of CERT- In. CSIRT-Power supports utilities in detecting, responding to, managing cyber incidents, and in improving overall cybersecurity preparedness. In addition, MoP has constituted six sub-sectoral Computer Emergency Response Teams (CERTs): (Thermal, Hydro, Transmission, Grid Operation, Renewable Energy, and Distribution). Each sub-sectoral CERT has been mandated to prepare a sub-sector- specific model Cyber Crisis Management Plan (C-CMP) for coordinated response and mitigation in the event of cyber-attacks. As per the information submitted by Gujarat Energy Transmission Corporation Limited (GETCO), in the State of Gujarat, a comprehensive cybersecurity framework has been implemented, including stricter access controls, endpoint protection, reduced system exposure, secure encrypted communication, deployment of next-generation firewalls between Remote Control Centres and the State Load Despatch Centre (SLDC), and installation of required antivirus solutions for malware protection. In the past five years, no cybersecurity breaches or successful cyber-attacks have been reported in the operational systems of the National Load Despatch Centre. (b) : Cybersecurity audits are conducted periodically across the power sector in accordance with the Central Electricity Authority (Cyber Security in Power Sector) Guidelines, 2021. These audits are carried out by third-party cybersecurity auditors empaneled by CERT-In. In the past five years, 9 assessments of the Information Technology infrastructure (IT) and 5 assessments of the Operational Technology (OT) infrastructure have been carried out at the National Load Despatch Centre. Details are enclosed at Annexure. Similarly, cybersecurity audits are periodically conducted by CERT-In empaneled auditors across all SLDCs, covering both IT and OT infrastructure, including Supervisory Control and Data Acquisition (SCADA) systems, the Unified Real-Time Dynamic State Measurement (URTDSM) system, and other critical assets. *****Annexure ANNEXURE REFERRED IN REPLY TO PARTS (b) OF UNSTARRED QUESTION NO. 1854 ANSWERED IN THE LOK SABHA ON 11.12.2025 ************* National Load Despatch Centre Financial Year (FY) IT (Month & Year) Supervisory Control and Data Acquisition System (Month & Year) F.Y. 2025–26 September-25 (Cycle-1) June-25 F.Y. 2024–25 April-24 (Cycle-1), June-24 January-25 (Cycle-2) F.Y. 2023–24 August-23 (Cycle-1), May-23 March-24 (Cycle-2) F.Y. 2022–23 July-22 (Cycle-1), September-22 January-23 (Cycle-2) F.Y. 2021–22 August-21 (Cycle-1), Project Under Upgradation February-22 (Cycle-2) ********

Continue your research