Built for the plantsthat run themselves.
A solar or wind farm is an industrial estate with almost nobody on site: thousands of inverters and turbine controllers, a handful of engineers, vendors logging in from somewhere else, and a grid connection the regulator watches closely. ASTRICS gives that estate one operational understanding — every asset, what it generates, who owns it, and what happens to the plant if it fails.
India had 162 GW of solar and 57 GW of wind connected in June 2026. From 1 April 2027 every generating company and energy-storage owner at 50 MW or more comes under the CEA cyber security regulations.
Sources: CEA installed capacity report, June 2026; CEA (Cyber Security in Power Sector) Regulations, 2026, Regs 1(2) and 2(1)
The renewable estate,as ASTRICS reads it.
Every asset below lands in the same register, the same single line diagram and the same risk queue — with its source, its owner and its consequence attached.
Inverters and trackers
Hundreds per block, one firmware baseline. Discovered on the wire, grouped by block and string, and ranked by the megawatts behind them.
Turbine controllers
Every nacelle is a controller with a network link. Its firmware, its communications and its vendor access path are part of the record.
Plant controller and SCADA
Where grid set-points arrive and generation is curtailed. Critical by definition — modelled as the single point it is.
Battery storage
Battery and energy management systems bring their own vendors, protocols and safety constraints. They sit in the same model as everything else.
Collector substation
Transformers, relays and the single line diagram — the same context overlay ASTRICS paints on any switchyard.
Remote access
OEM and O&M sessions are observed, attributed to a named vendor, and checked against the window they were approved for.
Why a farm is exposedin a way a station is not.
The risk in a renewable park is not exotic. It is the ordinary shape of the estate: unmanned, contractor-run, built on protocols that were never designed to say no.
Nobody on site
Operations and maintenance is a contract. The OEM has a portal, the O&M company has a VPN, and the plant has a gate. Whoever holds the credentials holds the plant.
One controller, the whole plant
The plant power controller turns grid instructions into set-points for every inverter. A curtailment command and a malicious write look the same on the wire.
Flat, trusting networks
Modbus TCP has no authentication. A device that can reach an inverter can write to it. Segmentation is the control, and it has to be proven, not drawn.
On the record
No cyber incident at an Indian solar or wind plant has been made public. The threat picture comes from the same inverters, controllers and vendors that are installed here.
- 2025
Forescout's SUN:DOWN research disclosed 46 new vulnerabilities across Sungrow, Growatt and SMA inverters and cloud platforms, including paths to take over fleets of inverters remotely.
Forescout Vedere Labs, March 2025
- 2022
The Viasat KA-SAT attack in the first hours of the Ukraine war cut remote monitoring to roughly 5,800 Enercon wind turbines in Germany. The turbines kept running; the operator could no longer see them.
Enercon; Alan Turing Institute CETaS
- 2021–22
Ransomware at Vestas and Nordex forced both manufacturers to shut IT systems and, at Nordex, remote access to turbines.
Vestas and Nordex statements
What the rules askof a renewable operator.
Summaries of the notified text as we read it in September 2026. Orientation, not legal advice — check the Gazette before you rely on a clause.
In scope at 50 MW
Regs 1(2), 2(1)The CEA (Cyber Security in Power Sector) Regulations, 2026 apply to generating companies, captive plants and energy storage owners with an installed capacity of 50 MW or more, from 1 April 2027. Smaller plants are encouraged to adopt CERT-In's 15 elemental controls.
A cyber asset register
Reg 5(25)Every cyber asset with its ownership, hardware, firmware, software and patch state; every critical system with its configuration, network architecture, data flows and protocols. Reviewed each financial year or on commissioning, whichever is earlier.
OT segmented by trust level
Regs 6(1), 6(8)The OT environment must be segmented into different trust levels on the basis of criticality, security requirements and risk assessment, and physically isolated from the internet and the IT system.
Remote access, on India's terms
Regs 5(17), 6(4), 8(15)Remote access is permitted only for troubleshooting and emergencies, with minimum duration, least privilege, multi-factor authentication and geo-fencing. Remote operation of OT must be from within India, approved by the head or board, over a channel isolated from the internet.
Audited every 9 to 15 months
Regs 5(22), 13(3)A CERT-In empanelled auditor at least once a financial year; the same agency not three times running; critical and high findings closed within a month of the report.
Vendors carry duties too
Regs 11, 12; MNRE, 2025–26Inverter and controller vendors have their own obligations under the regulation, including for distributed generation resources of prosumers. For rooftop systems under PM Surya Ghar, MNRE has separately required inverter data to be held on servers in India.
to report a cyber security incident to CSIRT-Power and CERT-In. Twenty-four hours where an incident is concluded as cyber sabotage in a critical system. (Reg 7(3)(a))
to address every critical and high-risk finding from the date the auditor submits the report; three months for medium and low. (Reg 13(3))
from NCIIPC identifying an asset as critical information infrastructure to apply for it to be notified as a protected system. (Reg 5(29))
How ASTRICS mapsto a renewable park.
One platform, one language, one source of truth. Understand, Govern, Protect, Orchestrate and Assure travel together, so every capability below reads the same record.
The register the regulation describes
Asset Inventory holds ownership, firmware, software and patch state as first-class columns, and tracks completeness against each — because an incomplete register is a failed control.
Trust levels, proven against traffic
Zones & Conduits declares the trust levels and continuously tests them against observed flows. Every mismatch becomes a dated finding, not a note in a review.
Consequence, not severity
The same vulnerability on one string inverter and on the plant controller are not the same risk. The Risk Queue ranks by what fails and how many megawatts go with it.
One fleet, one number per obligation
A portfolio is dozens of parks across states. Fleet Command shows readiness per site and per obligation, so the weakest plant is obvious before the auditor finds it.
Fleet Command
One posture number per obligation, across every site — built to answer “are we defensible today, and where are we not” in seconds, not in a reporting cycle.

Zones & Conduits
Chapter IV asks an operator to prove trust-level segmentation, not describe it. Declared zones and permitted conduits are continuously tested against observed traffic, and every mismatch becomes a dated finding.

Compliance Console — CEA 2026 & IEC 62443
Compliance as a live state rather than an annual project: every control carries its current verdict, the evidence behind it, and the clock attached to any failure.

What operators askbefore they buy.
Straight answers, in the terms the regulation and the plant already use. Bring the rest to a walkthrough.
Does a 50 MW solar plant fall under the CEA cyber security regulations?
Yes. The regulations apply to generating companies, captive generating plants and organisations with energy storage systems where installed capacity is 50 MW or more, for existing as well as upcoming infrastructure, from 1 April 2027. Below 50 MW an operator is encouraged, not required, to implement CERT-In's 15 elemental cyber defence controls.
We have a hybrid plant with battery storage. Does the storage count?
Organisations having an energy storage system are named in the applicability clause, with the same 50 MW threshold. In a hybrid plant the battery and energy management systems sit in the same ASTRICS model as the inverters and the plant controller, so one register and one set of verdicts covers the whole site.
Can our OEM still support us from overseas?
The regulation permits remote access only for troubleshooting and emergencies, under a defined procedure with minimum duration, least privilege, multi-factor authentication and geo-fencing. Remote operation of OT must take place within India with prior approval of the head or board. ASTRICS observes every remote session, attributes it to a named vendor, and records whether it stayed inside the window it was approved for.
We run thirty parks across four states. Is that thirty compliance programmes?
It is one programme with thirty sites in it. Fleet Command gives one posture number per obligation across every site, and the compliance console recomputes each site's verdicts continuously from live context, so the register, the findings and the auditor bundle are maintained rather than rebuilt before each audit.
Which protocols does ASTRICS understand on a solar or wind site?
Modbus TCP, SunSpec register maps, IEC 60870-5-104, IEC 61850 and DNP3 are the languages of a plant like this. The confirmed list for your estate is in the current Technical Integration Guide, available on request.
See ASTRICS against your own environment.
Book a walkthrough with the ASTRICS team and bring one site's worth of questions.
