Wealth of lacunae: On the Kudankulam nuclear plant data leak

A ransomware attack on a contractor for the Kudankulam nuclear power project has led to the leak of sensitive infrastructure documents. Experts criticize the lack of transparency and inconsistent breach disclosure policies among Indian organizations regarding cybersecurity incidents.
Why it matters
The incident raises significant concerns about the cybersecurity posture of critical national infrastructure and the adequacy of current data protection disclosure regimes.
The ransomware attack against a contractor involved in the Kudankulam nuclear power project is concerning, even if nothing threatening the plant’s integrity was stolen. In 2019, malware was found on the same facility’s administrative network, but the NPCIL maintained that the operational reactor network was unaffected. The new incident extends the same theme. India’s breach disclosure regime is inconsistent and often plainly opaque. Affected organisations tend to believe admitting a breach will damage public confidence, share prices, contracts, and invite regulatory scrutiny. So, they tend to ease their language in public statements and avoid disclosure until compelled. Many organisations also lack mature incident response capabilities, not uncommonly because they treat cybersecurity as a matter of compliance rather than necessity. So, assessing what data has been affected in the early stages of an attack becomes technically impossible.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in