UPSC MainsGeneral Studies Paper IIIInternal SecurityPractice question

Cyber Attacks on Critical Infrastructure and Strategic Assets

Cyber attacks on critical infrastructure pose a significant threat to India's strategic assets. Examine.

Examine~250 words3 min readmedium
Attempt it first, timed · optional

Write the answer on paper, as in the exam. Start the timer, keep to the word target.

00:00/ 11 min · 250 words

Done writing? Photograph the sheet and see how it scores against this model answer, with feedback on what to fix.

Upload your answer sheet

How to approach

Begin by defining Critical Information Infrastructure (CII) under Section 70 of the Information Technology Act, 2000, contextualizing the threat scale. In the body, examine sector-wise threats to strategic assets (power, defence, finance, healthcare) with concrete case studies, followed by systemic vulnerabilities. Conclude with structural and institutional measures to fortify national cyber defence.

Model answer

453 words

Introduction

Under Section 70 of the Information Technology Act, 2000, Critical Information Infrastructure (CII) is defined as any computer resource whose incapacitation or destruction has a debilitating impact on national security, the economy, public health, or safety. With CERT-In recording over 15 lakh cybersecurity incidents annually, cyber attacks targeting CII have emerged as a primary instrument of grey-zone, sub-conventional warfare against India's sovereign strategic assets.

Threats to India's Strategic Assets across Critical Sectors

  • Power and Energy Installations: Supervisory Control and Data Acquisition (SCADA) and Operational Technology (OT) networks are prime targets for state-sponsored sabotage. The 2019 Dtrack malware breach at the Kudankulam Nuclear Power Plant and the targeting of Regional Load Despatch Centres by state-backed actor RedEcho revealed hostile intent to paralyze national transmission grids and nuclear facilities.
  • National Deterrence and Defence Logistics: Advanced Persistent Threat (APT) groups engage in strategic pre-positioning across dual-use infrastructure—such as railway signalling, port traffic management systems, and command-and-control networks—aiming to degrade military mobilization and operational readiness during kinetic conflicts.
  • Financial Architecture and Digital Public Infrastructure: Coordinated distributed denial-of-service (DDoS) attacks and malware targeting interbank payment systems, clearing houses, and Unified Payments Interface (UPI) rails pose systemic risks to financial stability, cross-border settlements, and digital sovereignty.
  • Healthcare and Governance Systems: The 2022 ransomware attack on AIIMS New Delhi shut down critical patient management systems, locked laboratory records, and compromised sensitive health profiles of top dignitaries, underscoring vulnerabilities in civilian emergency backbones.

Key Structural Vulnerabilities in India's Strategic Infrastructure

  • IT-OT Convergence: The historical air-gap separating operational technology from business enterprise networks is increasingly bridged for automation, exposing legacy industrial controllers to external internet-facing exploits.
  • Supply-Chain Vulnerabilities: Substantial dependence on imported telecommunications gear, embedded chips, proprietary firmware, and foreign supervisory hardware creates avenues for pre-installed hardware Trojans and hidden backdoors.
  • Asymmetric Attribution and Interdependence: Modern critical infrastructure is tightly interconnected; a localized disruption in power dispatch cascades instantly into transport, banking, and civilian logistics.

Way Forward for Enhancing Cyber Resilience

  • Adopting Zero Trust Architecture: Shift CII networks towards Zero Trust Architecture (ZTA) incorporating strict micro-segmentation, continuous least-privilege verification, and stringent access governance aligned with global standards.
  • Rigorous Supply-Chain Provenance: Expand the Trusted Telecom Portal framework to encompass hardware and firmware used in electric power, transport, and atomic energy sectors.
  • Institutional Integration: Operationalize dedicated Sectoral Computer Emergency Response Teams (such as CSIRT-Power and CSIRT-Fin), mandate periodic cyber-range wargaming overseen by the National Critical Information Infrastructure Protection Centre (NCIIPC), and enhance coordination with the tri-service Defence Cyber Agency (DCyA).

Conclusion

Securing India's strategic assets requires transitioning from reactive patch management to an integrated, proactive cyber deterrence posture. By combining indigenized hardware sourcing, strict supply-chain auditing, and inter-agency coordination under NCIIPC and CERT-In, India can build resilient digital infrastructure capable of withstanding state-sponsored hybrid warfare.

Key facts to remember

definition
Critical Information Infrastructure (CII)

Defined under Section 70(1) of the IT Act, 2000 as any computer resource the incapacitation or destruction of which shall have debilitating impact on national security, economy, public health or safety.

case study
Kudankulam Nuclear Power Plant Cyber Breach (2019)

A cyber intrusion utilizing the Dtrack malware infiltrated the administrative network of the Kudankulam facility, demonstrating the susceptibility of nuclear and power installations to targeted reconnaissance.

case study
AIIMS New Delhi Ransomware Incident (2022)

A major ransomware attack compromised servers at India's premier public hospital, paralyzing outpatient and emergency care systems and jeopardizing millions of digital health records.

statistic

CERT-In tracked and remediated over 15.9 lakh cyber security incidents across India in 2023, reflecting a massive expansion in the threat surface.

CERT-In / Ministry of Electronics and Information Technology
scheme
National Critical Information Infrastructure Protection Centre (NCIIPC)

Created under Section 70A of the Information Technology Act, 2000, it functions as the national nodal agency for taking all measures to protect India's critical information infrastructure.

Frequently asked questions

What makes IT-OT convergence particularly risky for critical infrastructure?

Historically, Operational Technology (OT) networks controlling physical equipment were air-gapped and isolated. Connecting them to Information Technology (IT) enterprise systems for remote monitoring introduces vulnerabilities that allow attackers to remotely disrupt physical machinery like power turbines and railway signals.