AdvertisementAd
№ 4821

The Hindustani.

A quiet newspaper for a noisy world. Edited in print, read on screen.

SearchSubscribe
BREAKING
Parliament passes contested budget · UN climate fund hits $40bn commitment · Fed signals extended rate pause; S&P 500 record high · Monsoon floods displace 84,000 in coastal Bengal · AI copyright ruling reshapes training economics · Lunar Gateway module clears final assembly review · Two world records fall at Zurich Diamond League · Venice Biennale opens with rebuke of the spectacular · Parliament passes contested budget · UN climate fund hits $40bn commitment · Fed signals extended rate pause; S&P 500 record high · Monsoon floods displace 84,000 in coastal Bengal · AI copyright ruling reshapes training economics · Lunar Gateway module clears final assembly review · Two world records fall at Zurich Diamond League · Venice Biennale opens with rebuke of the spectacular · 
Defence

India Releases National Cybersecurity Policy 2026 with Zero-Trust Mandate

All critical infrastructure operators — power, telecom, banking, defence — must implement zero-trust architecture within 24 months under the new framework.

Share story:
WhatsAppFacebook
India Releases National Cybersecurity Policy 2026 with Zero-Trust Mandate

Photograph: The Hindustani staff

NEW DELHI —

The Ministry of Electronics and Information Technology has released the National Cybersecurity Policy 2026, mandating zero-trust security architecture adoption for all critical infrastructure operators and government systems within 24 months — a significant tightening from the previous framework's advisory posture.

Zero-trust architecture requires continuous verification of every user, device, and network connection rather than assuming safety once inside a perimeter. The approach addresses the principal vulnerability exposed in India's most significant recent cyber incidents: the AIIMS Delhi ransomware attack and the UIDAI data breach, both of which exploited trusted internal network access.

The policy classifies 57 categories of critical information infrastructure — from power generation control systems and banking transaction platforms to the Aadhaar verification infrastructure and national election management systems — and assigns each a compliance timeline and minimum security standard.

A new National Cyber Security Coordinator's office will oversee implementation, with authority to conduct mandatory audits, issue compliance certificates, and impose operational restrictions on non-compliant operators. The government has allocated ₹3,200 crore for a subsidy and capacity-building programme to support smaller critical infrastructure operators who lack the technical resources to implement the required changes independently.

#cybersecurity#zero trust#critical infrastructure#NCSC#India policy

Reader Responses

Loading responses…

Leave a Response

Your comment will appear after editorial review.

0/1500

By submitting you agree to our editorial response guidelines.