Why India needs a comprehensive critical infra law, ASAP

During Operation Sindoor, some Pakistani linked accounts spread a claim that a cyberattack had shut down 70 per cent of India’s power grid. The claim was false, and the PIB cleared it within hours. But for those few hours, it still worked because it sounded believable, because anyone reading it could immediately understand that India’s grid is a real target. What almost nobody paused to ask in that moment was the more important question. What law is actually protecting it? The honest answer is that India mostly has one cyber security law, written in 2000 and updated in 2008, and it was never really designed to deal with a bridge, a railway yard, or a power substation. It was built for computer systems, not for the wider world of infrastructure. That gap is not just theoretical. Modern conflict now treats grids, ports, cables, and data centres as targets in their own right, not just as things that get damaged by accident. The very meaning of infrastructure has expanded far beyond what Parliament imagined nearly twenty years ago. And this government has already shown, by striking nine coordinated targets across the Line of Control in one operation, that it can act decisively when it wants to. The next test is whether it can show the same decisiveness in the laws that protect India’s infrastructure. The law we have was written for a smaller, weaker India Section 70 of the Information Technology Act, 2000, is still the main law the system relies on, but it was never designed for a country with the kind of security challenges this government is dealing with today. It defines Critical Information Infrastructure as a computer resource whose failure could harm national security, the economy, public health, or safety, and it allows the government to notify such a resource as a protected system.  Section 70A, which was added in 2008, created the National Critical Information Infrastructure Protection Centre under the National Technical Research Organisation, with reporting routed through the National Security Adviser. In practice, this has meant protecting the IT systems of institutions like ICICI, HDFC, and the National Payments Corporation of India by placing them under the protected systems category. But the definition matters here. The law protects computer resources, and only computer resources. It does not directly cover a bridge, a power substation, a water treatment plant, or a railway yard unless a computer system happens to be the point where everything fails. That leaves big gaps. There is no comprehensive national registry, no mandatory audit system covering both physical and cyber sides with unified and consistent national obligations, no sector-wide threat modelling, and no compensation framework for ordinary citizens who are affected when something goes wrong. That old framework may have made sense then. But this government is now defending a 2026 India against drone incursions, coordinated sabotage, and mixed cyber-physical attacks that Parliament in 2008 could not have fully imagined. What counts as critical infrastructure now? Cut out the jargon, and critical infrastructure simply means everything a country cannot afford to lose for more than a few days without the state starting to look weak. That includes roads, bridges, and tunnels, railways, police stations, airports, and ports, the power grid and telecom networks that everything else now depends on, data centres that hold the digital equivalent of a nation’s records; and hospitals and water systems that keep people alive. A generation ago, most of this meant concrete and steel. Today, the physical and digital have become tightly linked. A ransomware attack on a hospital can be just as dangerous as a device at its gate, and a cut cable can do more economic damage in one afternoon than many floods do in a month. When undersea cables in chokepoints like the Red Sea or the Strait of Hormuz get damaged, a large chunk of India’s westward internet traffic suddenly comes under strain. And you don’t feel that impact in some abstract cyberspace; you feel it in everyday UPI payments that start lagging, trading screens that freeze, and government cloud services that begin to fail. In the same way, when a premier institution like AIIMS has its systems knocked out by a targeted cyberattack, it’s not just an IT outage. It’s a moment when the Republic’s ability to care for its own citizens is temporarily switched off by a few lines of malicious code. So any law written for today’s India that only protects one side of this reality and leaves the other exposed is already out of date the day it’s passed. What the law should contain? None of this stuff needs inventing. Pretty much all of these ideas already exist in some form in the laws or day to day practice of working democracies. And a government with a majority this big really has no good excuse for still stitching the whole system together bit by bit. What it

Why India needs a comprehensive critical infra law, ASAP
During Operation Sindoor, some Pakistani linked accounts spread a claim that a cyberattack had shut down 70 per cent of India’s power grid. The claim was false, and the PIB cleared it within hours. But for those few hours, it still worked because it sounded believable, because anyone reading it could immediately understand that India’s grid is a real target. What almost nobody paused to ask in that moment was the more important question. What law is actually protecting it? The honest answer is that India mostly has one cyber security law, written in 2000 and updated in 2008, and it was never really designed to deal with a bridge, a railway yard, or a power substation. It was built for computer systems, not for the wider world of infrastructure. That gap is not just theoretical. Modern conflict now treats grids, ports, cables, and data centres as targets in their own right, not just as things that get damaged by accident. The very meaning of infrastructure has expanded far beyond what Parliament imagined nearly twenty years ago. And this government has already shown, by striking nine coordinated targets across the Line of Control in one operation, that it can act decisively when it wants to. The next test is whether it can show the same decisiveness in the laws that protect India’s infrastructure. The law we have was written for a smaller, weaker India Section 70 of the Information Technology Act, 2000, is still the main law the system relies on, but it was never designed for a country with the kind of security challenges this government is dealing with today. It defines Critical Information Infrastructure as a computer resource whose failure could harm national security, the economy, public health, or safety, and it allows the government to notify such a resource as a protected system.  Section 70A, which was added in 2008, created the National Critical Information Infrastructure Protection Centre under the National Technical Research Organisation, with reporting routed through the National Security Adviser. In practice, this has meant protecting the IT systems of institutions like ICICI, HDFC, and the National Payments Corporation of India by placing them under the protected systems category. But the definition matters here. The law protects computer resources, and only computer resources. It does not directly cover a bridge, a power substation, a water treatment plant, or a railway yard unless a computer system happens to be the point where everything fails. That leaves big gaps. There is no comprehensive national registry, no mandatory audit system covering both physical and cyber sides with unified and consistent national obligations, no sector-wide threat modelling, and no compensation framework for ordinary citizens who are affected when something goes wrong. That old framework may have made sense then. But this government is now defending a 2026 India against drone incursions, coordinated sabotage, and mixed cyber-physical attacks that Parliament in 2008 could not have fully imagined. What counts as critical infrastructure now? Cut out the jargon, and critical infrastructure simply means everything a country cannot afford to lose for more than a few days without the state starting to look weak. That includes roads, bridges, and tunnels, railways, police stations, airports, and ports, the power grid and telecom networks that everything else now depends on, data centres that hold the digital equivalent of a nation’s records; and hospitals and water systems that keep people alive. A generation ago, most of this meant concrete and steel. Today, the physical and digital have become tightly linked. A ransomware attack on a hospital can be just as dangerous as a device at its gate, and a cut cable can do more economic damage in one afternoon than many floods do in a month. When undersea cables in chokepoints like the Red Sea or the Strait of Hormuz get damaged, a large chunk of India’s westward internet traffic suddenly comes under strain. And you don’t feel that impact in some abstract cyberspace; you feel it in everyday UPI payments that start lagging, trading screens that freeze, and government cloud services that begin to fail. In the same way, when a premier institution like AIIMS has its systems knocked out by a targeted cyberattack, it’s not just an IT outage. It’s a moment when the Republic’s ability to care for its own citizens is temporarily switched off by a few lines of malicious code. So any law written for today’s India that only protects one side of this reality and leaves the other exposed is already out of date the day it’s passed. What the law should contain? None of this stuff needs inventing. Pretty much all of these ideas already exist in some form in the laws or day to day practice of working democracies. And a government with a majority this big really has no good excuse for still stitching the whole system together bit by bit. What it would actually look like is pretty simple. India would need a proper legal definition of critical infrastructure that covers both the physical and the digital side, not just the cyber only wording that’s currently sitting in Section 70. It would need a national register of critical assets, public and private, that gets updated regularly instead of only being dusted off when a crisis hits. And it would need clear sector by sector classification, so energy, transport, telecom, water, health, finance and data infrastructure don’t all get bounced from one ministry to another after something goes wrong. The system would also have to insist on regular resilience and security audits, rather than waiting for a failure to make the news. Operators, whether they’re public or private, would need to be made responsible for looking at risks and modelling threats ahead of time. On top of that, cyber security standards should actually have legal force behind them, instead of just being advisory circulars that nobody really has to follow. A proper framework would also need clear emergency response rules and interagency coordination, so a sabotage incident doesn’t create the same jurisdictional mess that often follows a protest or a law-and-order situation. There should be clear liability for negligence in design, construction, maintenance and operation, plus regular drills, mandatory incident reporting, and a fast-track investigation the moment sabotage is even suspected. And if ordinary people get harmed, there should be a proper compensation and restoration system so recovery doesn’t just rely on informal goodwill after the fact. This is the basic operating manual that every serious government in India is competing with already has in place. There’s really no reason a government sitting on a majority this large should still be missing it. What other nations have done? The United States has been having something like this since 2013. Think of it as drawing up a clear list of the sixteen most important parts of the house, the ones that, if they collapsed, would bring the whole building down. Security, the economy, public health, etc. Presidential Policy Directive 21 does exactly that. Then in 2024 they updated the rules so one single agency, the Cybersecurity and Infrastructure Security Agency, became the main coordinator for all of them. And every two years there’s a national risk report that forces everyone to check the foundations again instead of just hoping they’ll hold. Australia’s version, the Security of Critical Infrastructure Act from 2018, is tighter and easier to adapt. It covers eleven sectors, keeps a national register of the key assets, makes risk management plans and incident reporting compulsory, and, this is the crucial bit, gives the minister a last-resort power to tell a private company ‘do this’ or ‘stop doing that’ when national security is at stake. That last power is the one that really matters for any Indian government that cares about sovereignty. It means Canberra never has to stand outside a private port or power company asking nicely for cooperation. It can simply issue the order. The European Union’s approach is probably the most useful to look at. Its NIS2 Directive covers sixteen sectors of ‘essential’ and ‘important’ entities, and it sits alongside a separate Critical Entities Resilience Directive that deals specifically with physical security. So a single power utility ends up protected on both its digital side and its physical side by design, not by accident. That’s exactly the gap Section 70 falls into, like having a strong lock on the front door but leaving the back window wide open, and it’s exactly the gap this government’s law should close. None of this means India has to copy anyone else’s blueprint wholesale. No serious person is saying Delhi should take orders from Washington, Canberra or Brussels on how to run its own house. It’s simply pointing out that a government aiming for a five trillion dollar economy and a permanent seat at the top table can’t keep protecting its most important systems with the legal equivalent of a side door left ajar. Parliament needs to finish what it started Here is the reason for optimism, and it comes from this government’s own side. In February 2026, Rajya Sabha MP Kartikeya Sharma introduced the Critical Infrastructure (Resilience, Protection and Accountability) Bill, 2026. The basic idea behind it is simple and right: when public infrastructure fails, and people die, responsibility now gets spread so widely across contractors and consultants that, in the end, nobody is clearly answerable. The Bill would change that. It would move major infrastructure failures from civil liability into criminal liability, require digital twins and a national monitoring dashboard, and extend defect liability on large projects to twenty five years. It covers dams, expressways, power grids, ports, and transit systems. This is a real and serious proposal, and it should be supported, not allowed to quietly fade away like so many private member’s bills do. But it only answers one part of the problem. It tells us what should happen when a bridge collapses because of negligence. It says nothing about what should happen when a hostile state, or someone taking advantage of unrest especially looting police stations of weapons, deliberately cuts the cable instead. If the government is serious about finishing this work, it should take Sharma’s accountability framework and combine it with a proper security and sabotage response framework. Then it should pass the whole thing as a government bill, backed by the full strength of its majority, instead of leaving a good idea stuck in the Rajya Sabha’s private member’s list, where too many good ideas end up being forgotten. Zero tolerance for sabotage, applied lawfully and without apology This is the point where the argument has to be made cleanly, without any careless wording. If the law gets drafted sloppily here, critics will jump on it and use it against the government, and there’s no reason to hand them that kind of ammunition. India already has a legal base for punishing the deliberate destruction of public property during unrest. It just needs updating for today. The Prevention of Damage to Public Property Act, 1984, already covers damage to things like water, power, transport and telecom systems, and it can put offenders away for up to five years. Back in 2009 the Supreme Court also made it clear that once organised participation is shown, the burden of proof can shift to the accused, and High Courts can assess the damage and order compensation. Uttar Pradesh, under Yogi Adityanath, didn’t wait for Delhi. Its tribunal-based recovery ordinance already lets the state attach the property of people found responsible for damage during riots and unlawful agitations. That’s a model other states, and now Parliament, should be looking at. The Law Commission also pointed out in 2024 that a 2015 attempt to modernise the 1984 Act was quietly dropped, even though the scale of damage during unrest has only got bigger since then. A national Critical Infrastructure Protection Act should take that idea further. It should create a fast track offence for deliberate attacks on critical assets, fibre cables, substations, rail yards, water systems, with quick arrest, fast prosecution, and penalties tough enough to actually deter people. It should also give security forces clear legal power to stop sabotage while it’s still happening. But that power has to be written carefully. Protest and dissent are protected by the Constitution, so a law like this should target sabotage, not ordinary public order policing. Its real strength should come from being precise. It should focus only on deliberate attacks on the systems that keep the country running. A narrow, clear law is far more likely to survive a court challenge and win public trust. A vague one would just create a fresh issue for the opposition to exploit. Conclusion This is not an argument against the government of the day. In fact, it is the opposite. This government has already shown that it can move at the speed a serious state needs, on the battlefield, on ceasefire terms, and on the big strategic decisions that matter. So it has no real excuse left for moving slowly on the two reforms sitting right in front of it. A state that could strike nine targets across the border in one coordinated operation can surely find the parliamentary time to pass a law protecting its own grid. And it can certainly find the will to make its information system as confident and effective as its foreign policy. Operation Sindoor proved that this government can win the argument on the battlefield. The unfinished job is making sure it can win the argument about itself just as quickly, and making sure that no foreign or domestic actor ever again gets ninety days to control the story, or an open door to a substation, before the Indian state moves in to shut it.