The station, with everycontroller accounted for.
A power station is a city of controllers: the distributed control system, the burner management and safety systems, the turbine governor, the coal handling and water treatment PLCs, the switchyard beyond the step-up transformer. Most were commissioned a decade or more ago and will run for a decade more. ASTRICS gives the station one operational understanding of all of them — and of what the plant loses if any one of them is wrong.
Coal-fired plant made up 224 GW of India's 549 GW of installed capacity in June 2026, with 52 GW of hydro and 20 GW of gas. Every generating company at 50 MW or more comes under the CEA cyber security regulations from 1 April 2027.
Sources: CEA installed capacity report, June 2026; CEA (Cyber Security in Power Sector) Regulations, 2026, Reg 2(1)
The station estate,as ASTRICS reads it.
From the DCS controller in the unit control room to the relay in the switchyard, every asset lands in one register with its process, its owner and its consequence attached.
Distributed control system
The controllers and operator stations that run the unit. Modelled by loop and by consequence, so the record knows which controller trips the boiler.
Burner management and safety systems
The systems whose only job is to stop the plant safely. Their separation from the control network is a control in itself — and one ASTRICS tests continuously.
Turbine governor and excitation
Where the grid's frequency and voltage meet the machine. Vendor-specific, vendor-maintained, and critical by definition.
Balance-of-plant PLCs
Coal handling, ash handling, water treatment, cooling towers. Hundreds of small controllers whose failure is an outage in slow motion.
Step-up transformer and switchyard
The generator transformer, breakers and relays that connect the unit to the grid — the same overlay ASTRICS paints on any switchyard.
Historian and OEM diagnostics
The systems that leave the plant: performance monitoring, remote diagnostics, vendor portals. Every path out is a path in, and each one is in the record.
Why a station is exposedin a way it cannot patch away.
The risk in a power station is age, adjacency and access: long-lived controllers, safety systems that share networks they should not, and an administrative network that is closer to the unit than anyone would like.
Twenty-year controllers
A DCS commissioned in 2008 runs on operating systems nobody supports. Patching is an outage. The compensating control is knowing exactly what is there, what it talks to, and what it would cost to lose.
Safety on the same wire
The TRITON attack showed a safety instrumented system can be reached from the control network and reprogrammed. Segmentation between control and safety has to be proven against observed traffic, not assumed from a drawing.
The admin network is not far away
The 2019 malware found at Kudankulam was on the administrative network. The distance from there to the unit is a question every station should be able to answer with evidence.
On the record
- 2019
NPCIL confirmed that malware, later identified as DTrack, had been found on the administrative network of the Kudankulam Nuclear Power Plant. The plant control systems were reported to be isolated and unaffected.
Nuclear Power Corporation of India statement, October 2019
- 2017
TRITON, the first malware built to attack a safety instrumented system, triggered an emergency shutdown at a petrochemical plant when it tripped the Triconex controllers it was trying to reprogram.
FireEye Mandiant; Idaho National Laboratory CyOTE case study
- 2025
Hacktivists reportedly altered turbine settings at a small hydro plant at Tczew, Poland, through an internet-exposed human-machine interface.
Polish media and security researchers, August 2025 — as reported
What the rules askof a generating company.
Summaries of the notified text as we read it in September 2026. Orientation, not legal advice — check the Gazette before you rely on a clause.
In scope at 50 MW
Regs 1(2), 2(1)Generating companies and captive generating plants with installed capacity of 50 MW or more come under the CEA (Cyber Security in Power Sector) Regulations, 2026 from 1 April 2027.
Critical and non-critical, on paper
Regs 5(16), 8(4)Systems must be identified and segregated as critical and non-critical under a procedure in the Cyber Security Policy, and the register must classify every cyber asset by criticality and risk.
Tested before it goes live
Regs 5(27), 5(28)A cyber security audit including vulnerability assessment and penetration testing before commissioning any new critical system, including replacements — and details to CSIRT-Power within thirty days.
A risk plan every six months
Reg 5(26)A Cyber Risk Assessment and Mitigation Plan for every asset in the register, updated at least every six months and reviewed every financial year.
Trust levels and isolation
Regs 6(1), 6(6), 6(8)OT physically isolated from the internet and the IT system, its communications separate from IT's, and segmented into trust levels by criticality and risk.
Six hours, one month
Regs 7(3)(a), 5(22), 13(3)Incidents to CSIRT-Power and CERT-In within six hours; audits every nine to fifteen months; critical and high findings closed within a month.
to report a cyber security incident to CSIRT-Power and CERT-In. Twenty-four hours where an incident is concluded as cyber sabotage in a critical system. (Reg 7(3)(a))
to address every critical and high-risk finding from the date the auditor submits the report; three months for medium and low. (Reg 13(3))
from NCIIPC identifying an asset as critical information infrastructure to apply for it to be notified as a protected system. (Reg 5(29))
How ASTRICS mapsto a power station.
One platform, one language, one source of truth. Understand, Govern, Protect, Orchestrate and Assure travel together, so every capability below reads the same record.
The register with criticality built in
Asset Inventory carries accountable owner and criticality as first-class columns, and tracks completeness against every field the regulation names.
Risk ranked by what trips the unit
The Risk Queue orders the same vulnerability data by what failure would cost this station — the controller that trips the boiler ranks above the highest CVSS score in the estate.
Safety separation, tested
Zones & Conduits declares the control-to-safety boundary and tests it against observed traffic. A flow across it becomes a dated finding with the evidence attached.
The six-monthly plan, kept
Because verdicts and findings are recomputed continuously from live context, the risk assessment the regulation wants every six months is a state the platform already holds.
Asset Inventory
The Chapter III register as a living object. Accountable owner and criticality are first-class columns because the regulation asks for them — and completeness against each field is tracked, since an incomplete register is a failed control.

Risk Queue
The same vulnerability data everyone has, ordered by what it would cost this operator. The two highest CVSS scores in the estate rank 18th and 27th here — because consequence, not severity, decides the work.

Compliance Console — CEA 2026 & IEC 62443
Compliance as a live state rather than an annual project: every control carries its current verdict, the evidence behind it, and the clock attached to any failure.

What operators askbefore they buy.
Straight answers, in the terms the regulation and the plant already use. Bring the rest to a walkthrough.
Our DCS vendor says nothing can touch the control network. Does ASTRICS need to?
No. ASTRICS builds the record from passively observed traffic and from the sources the plant already has. Writes to control devices are not a permission it can be granted — that path does not exist in the product.
We are a captive plant inside a steel works. Are we in scope?
Captive generating plants are named in the applicability clause with the same 50 MW threshold as generating companies. A captive plant at or above 50 MW is in scope from 1 April 2027 regardless of what the parent business does.
How does the regulation treat a replacement controller?
A new or replaced critical system needs a cyber security audit including vulnerability assessment and penetration testing before commissioning, and its details go to CSIRT-Power within thirty days. ASTRICS records the change, its lineage and the evidence in the same register the auditor sees.
What is the difference between the CEA regulation and the CERT-In directions?
The CERT-In Directions of April 2022 bind every body corporate in India: six-hour reporting to CERT-In, 180 days of logs kept in India, time synchronised to NIC or NPL. The CEA regulation adds sector-specific duties for power entities — CISO, policy, register, segmentation, audits, CSIRT-Power reporting — and requires compliance with the CERT-In directions in addition.
See ASTRICS against your own environment.
Book a walkthrough with the ASTRICS team and bring one site's worth of questions.
