Skip to main content
Table of Contents

India’s CEA Issues Updated Guidelines for Power Grid Companies

... min read
Share

Last week the cybersecurity radar saw two blips: a UK power plant outage and India’s updated Central Electricity Authority (CEA) power grid guidelines. This news is a call to action – leadership teams managing Operational Technology (OT) or supply chain risk must adapt to mandated data sovereignty rules and continuous audit requirements.

Image: Rose Galloway Green/Unsplash

UK Power Plant Hacked: Iranian Attack Triggers 4-Day Outage

In late August 2026, reports revealed that a small British power generation facility experienced a four-day shutdown following a cyberattack that occurred in July.

Media reports and initial intelligence assessments linked the attack to hackers associated with Iran, though official UK authorities (including the National Cyber Security Centre) have refrained from formal public attribution while investigations continue.

The impacted facility was a small-scale (~15 MW) gas-fired peaking plant used to support the grid during periods of high demand. The government and security agencies have not publicly disclosed the plant’s name or exact location.

The outage did not cause any power blackouts or threaten the stability of the wider UK electricity network, as the plant’s capacity was too small to affect overall grid operations.

Security leaders must evaluate aggregate risk. While one compromised small site is a minor disruption, an organized attack on multiple sites could lead to major outages. A synchronized cyberattack targeting dozens of small, loosely secured distributed energy resource (DER) sites could trigger systemic cascade failures across the grid.

India’s updated CEA power grid guidelines

India’s Central Electricity Authority (CEA) has introduced significant updates and comprehensive overhauls to its power grid frameworks to accommodate the massive integration of renewable energy, battery storage, and enhanced cybersecurity.

To protect critical infrastructure from digital threats, the CEA released updated cybersecurity guidelines for Power Sector companies:

Applicability: The guidelines are applicable to generating companies, transmission utilities, and major BESS installations (50 MW and above) – owning or managing Operational Technology (OT) and IT infrastructure.

Mandates: Utilities must enforce strict physical and logical isolation between IT and OT systems, appoint a CISO, store sensitive operational data securely within India, and source OT equipment only from trusted vendors.

Incident Reporting: Crucially, organizations must report cybersecurity incidents to CSIRT-Power and CERT-In within an enforceable 6-hour window, and potential cyber-sabotage events within 24 hours.

 

We tell stories about how technology impacts and transforms business and lives. We write about tech for societal and business impact.

Designed, Developed and Managed by DARIS

Copyright ©2026 – DIGITAL CREED, Mumbai, India. All rights reserved.