Journal du Club des Cordeliers - India Orders Wind Turbine Makers to Report on Data Localization for Cybersecurity

NYSE - LSE
CMSD -0.05% 21.169 $
RBGPF -0.62% 70.69 $
BCC -1.08% 77.93 $
JRI -0.5% 12.338 $
RYCEF -0.24% 20.7 $
CMSC -0.12% 21.285 $
AZN -1.77% 161.665 $
BCE -0.11% 23.375 $
RELX 0.38% 36.44 $
BP -1.1% 41.88 $
RIO -1.49% 103.24 $
BTI -0.25% 56.139 $
GSK 0.24% 50.39 $
VOD 0.59% 15.975 $
NGG -0.13% 79.325 $
India Orders Wind Turbine Makers to Report on Data Localization for Cybersecurity
India Orders Wind Turbine Makers to Report on Data Localization for Cybersecurity

India Orders Wind Turbine Makers to Report on Data Localization for Cybersecurity

The Ministry of New and Renewable Energy (MNRE) has directed all wind turbine manufacturers listed under the Approved List of Models and Manufacturers (ALMM) to submit detailed status reports on their cybersecurity compliance protocols by the end of the current month. The directive specifically requires manufacturers to demonstrate data localization and operational control within India, marking a significant step in securing critical energy infrastructure against digital threats.

Text size:

The Ministry of New and Renewable Energy (MNRE) has issued a directive requiring all wind turbine manufacturers listed under the Approved List of Models and Manufacturers (ALMM) to submit comprehensive status reports on their cybersecurity compliance protocols. The ministry has set the end of the current month as the deadline for these submissions.

According to reports, the mandatory requirements focus heavily on data localization and ensuring operational control remains within India. This order appears to be implemented under the notified "Procedure for inclusion/updating Wind Turbine Model in the Revised List of Models and Manufacturers of Wind Turbines (RLMM)."

The directive aligns with a draft amendment dated April 17, 2025, which mandated specific compliances to strengthen cybersecurity standards across the renewable energy sector. The move comes amid growing concerns about the vulnerability of critical infrastructure to digital attacks.

Recent global incidents have highlighted the risks facing power grids and telecommunications. On August 24, a minor power plant in the UK was targeted by a cyber-attack that kept it offline for four days. Such events underscore the fragility of electricity grids, telecom infrastructure, and data centers, which are essential to national activities and increasingly targeted during geopolitical tensions.

The context for such security measures is rooted in the history of cyber warfare. In 2007, Estonia faced a major cyber-attack attributed to Russia, an incident widely regarded as the first instance of one nation threatening another primarily through internet-based attacks. The assault targeted government websites, banks, and communication firms, occurring more than a decade before India launched its Unified Payments Interface (UPI).

With the integration of artificial intelligence into critical systems, experts warn that the risks posed by such threats are likely to increase. While the central Digital Personal Data Protection (DPDP) Act does not mandate data localization, sectoral regulators are increasingly treating it as a standard requirement.

The specific focus on wind turbines follows earlier warnings from NITI Aayog, India’s government think tank. In 2024, NITI Aayog highlighted the cybersecurity risks associated with wind turbines, noting that their connection to electricity grids could make them vulnerable without robust cyber-defense systems.

In a report released that year, NITI Aayog stated: "Wind turbines’ capability to exchange information through Power Plant Controllers poses a significant cybersecurity threat. The PPC (Power Plant Controller) software is of critical importance and associated with risks- used in the device which connects the wind farm directly to the national/state grid."

The think tank emphasized that original equipment manufacturers (OEMs) of foreign origin, particularly those from neighboring countries, need to be examined closely. The report called for potential suspension of OEMs that do not adhere to security protocols, citing the risk of grid operations being compromised when managed remotely by owners stationed outside India.

The new MNRE order reinforces these concerns by demanding proof of local data handling and operational control, aiming to safeguard national infrastructure from external digital interference.

B.Bonnet--JdCdC