Search
Close this search box.

We are creating some awesome events for you. Kindly bear with us.

Enhancing Cybersecurity in the Indian Power Sector

Getting your Trinity Audio player ready...

The Central Electricity Authority (CEA) under the Ministry of Power, in collaboration with REC Limited and the Expert Group on Smart Metering (EGSM), organised a workshop on cybersecurity for distribution utilities in the power sector.

It gathered experts, industry leaders, and cybersecurity enthusiasts to explore and discuss the latest trends, innovations, and strategies in the realm of cybersecurity. Attendees participated in dynamic discussions covering cybersecurity preparedness, the threat landscape and challenges in incident response, best practices for critical information infrastructure (CII) in the distribution sector, cybersecurity requirements for cloud security, and cyber security testing of firewalls and routers.

Image credits: Press Information Bureau

The focal point of the event was the Guidelines for Cyber Security in the Power Sector issued by CEA in 2021. These guidelines mandate compliance from all responsible entities, which include transmission utilities, transmission licensees, load dispatch centres, generation utilities, distribution utilities, generation aggregators, regional power committees, and regulatory commissions. The guidelines aim to:

These guidelines also strive to construct a secure cyber ecosystem, fortify regulatory frameworks, ensure the security of remote operations and services, and safeguard the resilience of Critical Information Infrastructures (CII) against cyber threats.

Moreover, they aim to reduce risks associated with cyber supply chains, advocate for the use of open standards, drive research and development initiatives in cybersecurity, and nurture human resources specialised in this field.

Additionally, the guidelines emphasise fostering effective public-private partnerships, encouraging information sharing and cooperative efforts among stakeholders for a more robust cyber defence strategy.

The conference provided a platform for the exchange of knowledge, sharing best practices, and reinforcing collective resilience against cyberattacks in the Indian power sector.

Cyber intrusion attempts and attacks in critical sectors are conducted with malicious intent and aim to compromise the power supply system or undermine the security of grid operations. Such compromises can lead to equipment maloperations and damage, or even trigger cascading grid brownouts or blackouts. Responsible entities involved in the power sector as well as service providers, equipment suppliers, vendors, and consultants, share equal responsibility in ensuring the cybersecurity of the Indian power supply system.

These agencies are expected to promptly respond to each threat intelligence, advisories, and other inputs received from authenticated sources to ensure a continuous enhancement of their cybersecurity posture.

According to the guidelines, responsible entities must be ISO/IEC 27001 certified (including sector-specific controls as per ISO/IEC 27019). They are required to establish a Cyber Security Policy based on the principles issued by the National Critical Information Infrastructure Protection Centre (NCIIPC).

They must conduct an annual review of their Cyber Security Policy by a subject matter expert, and any changes to the policy should only be implemented after obtaining approval from the Board of Directors. Furthermore, responsible entities are required to collaborate with other industry stakeholders and academia to promote research and development activities in cybersecurity.

Additionally, they must ensure that cybersecurity issues are included as agenda items in their Board meetings at least once every three months. They must allocate an adequate annual budget to enhance the cybersecurity posture, with a progressive increase year over year. Every entity must appoint a Chief Information Security Officer (CISO) and ensure compliance with any qualifications specified by the Quality Council of India (QCI).

The entities must establish an Information Security Division (ISD) led by the CISO, which should be functional round-the-clock. The ISD should be staffed by an adequate number of engineers, each possessing a valid certificate demonstrating the successful completion of a cyber security course specific to the power sector from training institutes designated by CEA.

PARTNER

Qlik’s vision is a data-literate world, where everyone can use data and analytics to improve decision-making and solve their most challenging problems. A private company, Qlik offers real-time data integration and analytics solutions, powered by Qlik Cloud, to close the gaps between data, insights and action. By transforming data into Active Intelligence, businesses can drive better decisions, improve revenue and profitability, and optimize customer relationships. Qlik serves more than 38,000 active customers in over 100 countries.

PARTNER

CTC Global Singapore, a premier end-to-end IT solutions provider, is a fully owned subsidiary of ITOCHU Techno-Solutions Corporation (CTC) and ITOCHU Corporation.

Since 1972, CTC has established itself as one of the country’s top IT solutions providers. With 50 years of experience, headed by an experienced management team and staffed by over 200 qualified IT professionals, we support organizations with integrated IT solutions expertise in Autonomous IT, Cyber Security, Digital Transformation, Enterprise Cloud Infrastructure, Workplace Modernization and Professional Services.

Well-known for our strengths in system integration and consultation, CTC Global proves to be the preferred IT outsourcing destination for organizations all over Singapore today.

PARTNER

Planview has one mission: to build the future of connected work. Our solutions enable organizations to connect the business from ideas to impact, empowering companies to accelerate the achievement of what matters most. Planview’s full spectrum of Portfolio Management and Work Management solutions creates an organizational focus on the strategic outcomes that matter and empowers teams to deliver their best work, no matter how they work. The comprehensive Planview platform and enterprise success model enables customers to deliver innovative, competitive products, services, and customer experiences. Headquartered in Austin, Texas, with locations around the world, Planview has more than 1,300 employees supporting 4,500 customers and 2.6 million users worldwide. For more information, visit www.planview.com.

SUPPORTING ORGANISATION

SIRIM is a premier industrial research and technology organisation in Malaysia, wholly-owned by the Minister​ of Finance Incorporated. With over forty years of experience and expertise, SIRIM is mandated as the machinery for research and technology development, and the national champion of quality. SIRIM has always played a major role in the development of the country’s private sector. By tapping into our expertise and knowledge base, we focus on developing new technologies and improvements in the manufacturing, technology and services sectors. We nurture Small Medium Enterprises (SME) growth with solutions for technology penetration and upgrading, making it an ideal technology partner for SMEs.

PARTNER

HashiCorp provides infrastructure automation software for multi-cloud environments, enabling enterprises to unlock a common cloud operating model to provision, secure, connect, and run any application on any infrastructure. HashiCorp tools allow organizations to deliver applications faster by helping enterprises transition from manual processes and ITIL practices to self-service automation and DevOps practices. 

PARTNER

IBM is a leading global hybrid cloud and AI, and business services provider. We help clients in more than 175 countries capitalize on insights from their data, streamline business processes, reduce costs and gain the competitive edge in their industries. Nearly 3,000 government and corporate entities in critical infrastructure areas such as financial services, telecommunications and healthcare rely on IBM’s hybrid cloud platform and Red Hat OpenShift to affect their digital transformations quickly, efficiently and securely. IBM’s breakthrough innovations in AI, quantum computing, industry-specific cloud solutions and business services deliver open and flexible options to our clients. All of this is backed by IBM’s legendary commitment to trust, transparency, responsibility, inclusivity and service.