During Operation Sindoor, some Pakistan-linked accounts claimed a cyberattack had shut down 70 percent of India’s power grid. The claim was false, and the PIB clarified it within hours. However, the claim gained attention because India’s power network is a genuine strategic target. The bigger question remains: does India have a modern law to protect such critical assets?
India currently depends mainly on the Information Technology Act, 2000, with updates made in 2008. However, that framework was designed around computer systems, not today’s wider infrastructure landscape. Modern conflicts now target grids, ports, cables, and data centres as strategic assets. Therefore, India needs laws that match its current security environment.
The current law protects systems, but leaves major gaps
Section 70 of the Information Technology Act defines Critical Information Infrastructure as computer resources whose failure can affect national security, economy, public health, or safety. Meanwhile, Section 70A created the National Critical Information Infrastructure Protection Centre under the National Technical Research Organisation.
However, the current approach focuses mainly on computer resources. It does not directly cover bridges, power substations, railway yards, or water treatment plants. These assets remain vulnerable when physical and digital threats combine.
Moreover, India lacks a comprehensive national registry for critical assets. It also needs unified audits covering both physical and cyber security. Additionally, sector-wise threat modelling and citizen compensation systems require stronger attention.
Today’s battlefield is becoming information-driven and increasingly autonomous. Space, technology, communication networks, and infrastructure security now shape national strength. Therefore, India requires a broader legal framework.
A modern critical infrastructure law should cover both digital and physical assets. It should create a national register with regular updates. Furthermore, it should classify important sectors like energy, transport, telecom, water, health, finance, and data infrastructure.
Regular security audits, mandatory reporting, emergency response rules, and stronger coordination between agencies should become legal requirements. Operators must understand risks before failures occur. Also, negligence in construction, maintenance, and operations needs clear accountability.
Other countries have already developed similar systems. The United States uses a framework covering sixteen important infrastructure sectors. Australia maintains a national register and requires risk management plans. The European Union combines digital protection with physical resilience measures.
India does not need to copy these models completely. However, these examples show the importance of combining physical and cyber protection under one framework.
The Critical Infrastructure (Resilience, Protection and Accountability) Bill, 2026, introduced by Rajya Sabha MP Kartikeya Sharma, also highlights accountability. The proposal focuses on infrastructure failures, digital twins, monitoring dashboards, and extended liability periods.
However, infrastructure protection also needs safeguards against deliberate sabotage. A complete framework must address hostile actions, cyber attacks, and targeted damage.
At the same time, such laws must protect democratic rights. They should focus on deliberate attacks against essential systems, not peaceful protests or dissent. A precise law can protect security while maintaining public trust.
India has shown the ability to take decisive strategic action when required. Therefore, the next challenge lies in building laws that protect the nation’s essential systems. A strong infrastructure security framework can ensure India remains prepared for future threats.














