Cybersecurity 2026

INDIA Law and Practice Contributed by: Anoop Narayanan, Priyanka Gupta and Harshita Sakarya, ANA Law Group

2. Critical Infrastructure Cybersecurity Regulation 2.1 Scope of Critical Infrastructure Cybersecurity Regulation India regulates cybersecurity for essential and critical entities primarily under the IT Act, supplemented by executive notifications, binding directions and sector- specific regulation. Section 70 of the IT Act empowers the central gov - ernment to designate any computer resource whose incapacitation would have a debilitating impact on national security, the economy, public health or pub - lic order as Critical Information Infrastructure (CII), and notify them as “Protected Systems” under the IT Act. The designation is based on the functional criticality and systemic importance of the system, rather than on the size, turnover or corporate structure of the entity operating it. The NCIIPC is the competent authority responsible to oversee the protection of CII. Once a system or network is designated as critical, the operator is sub - ject to enhanced cybersecurity obligations, includ - ing compliance with security guidelines, audits, risk assessments and co-ordinated incident response protocols. In practice, critical infrastructure designation and sec - toral oversight extend to entities operating in sectors considered essential to national functioning, including: • power and energy; • banking and financial services; • telecommunications; • transport (including aviation and rail); • government and defence-related systems; and • digital public infrastructure platforms. The NCIIPC regularly advises on reducing vulner - abilities of the CII, and against cyberterrorism, cyber - warfare and other threats. The NCIIPC Guidelines prescribe the development of audit and certification agencies for the protection of the CII. The NCIIPC also exchanges cyber-incidents and other informa - tion relating to attacks and vulnerabilities with CERT-In and concerned cybersecurity organisations in India.

Additionally, the DPDPA introduces a risk-based des - ignation mechanism for critical data fiduciaries. Under Section 10 of the DPDPA, the Central Government may designate any Data Fiduciary as a Significant Data Fiduciary (SDF) after considering the following factors: • volume and sensitivity of personal data processed; • risk to the rights of individuals; • potential impact on national security or public order; • use of emerging or advanced technologies; and • systemic importance of the service. SDFs are classified by the government based on actu - al risk, not merely size. Therefore, any entity could be designated an SDF based on the sensitivity of the data it handles. Designation is discretionary, anticipatory and flexible, allowing the regulator to pre-emptively impose heightened standards where risk is high. 2.2 Critical Infrastructure Cybersecurity Requirements The CERT-In Rules require all cybersecurity incidents to be reported, including attacks on critical infrastruc - ture and compromise of critical systems/information. The NCIIPC Rules lay down the cybersecurity prac - tices and procedures to be followed in respect of CII and Protected Systems. The NCIIPC Rules prescribe that all organisations having a “Protected System” shall constitute an Information Security Steering Com - mittee (ISSC) under the chairmanship of the Chief Information Security Officer (CISO) of the organisa - tion. The ISSC must oversee all security audits and risk-acceptance decisions of the organisations and is required to undertake the following responsibilities: • plan, establish, implement, operate, monitor, review, maintain and continually improve Informa - tion Security Management System (ISMS) of the Protected System as per latest NCIIPC Guidelines or an industry accepted standard duly approved by the NCIIPC; • identify and classify critical segments into catego - ries for targeted protection; • conduct mandatory cybersecurity audits by CERT- In empanelled auditors;

196 CHAMBERS.COM

Powered by