MNRE has directed ALMM-listed wind turbine manufacturers to submit cybersecurity compliance details, including India-based data centres, servers, operational control and R&D centres, while seeking measures to prevent real-time data transfer outside India.
| Photo Credit:
The Ministry of New & Renewable Energy (MNRE) has directed wind turbine manufacturers, enlisted under the Approved List of Models and Manufacturers (ALMM), to submit details of their setting up data and R&D centres within India and efforts to prohibit transfer of real time data outside the country.In an order issued last week, the Ministry has directed the ALMM-listed manufacturers to furnish the status report on these cyber security compliance protocols by the month-end.Data and operational control to remain in IndiaAs part of the cyber security compliance norms under the ALMM list, entities are required to mandatorily locate their data centre and servers within the country. All the data relating to the wind turbine must be stored and maintained inside India.The entities cannot transfer the real-time operational data outside India and the operational control of the wind turbine must be conducted exclusively from a facility located within the country.They are also required to mandatorily set up their R&D centres in India within one year from July 31, 2025--when the Ministry had updated the procedure for inclusion of wind turbine models in the ALMM list.Niti Aayog flags cybersecurity risksThe Niti Aayog in a March 2024 report emphasized that wind turbines’ capability to exchange information through Power Plant Controllers (PPCs) poses a significant cybersecurity threat.The PPC software is of critical importance and associated with risks used in the device which connects the wind farm directly to the national or state grid. The PPC OEMs of foreign origin, especially neighboring countries, need to be examined and call needs to be taken for their suspension while not adhering to the protocol.The government policy arm also emphasised on the potential risks associated with cyberattacks on wind turbines, including the compromise of grid operations, especially when managed remotely by owners stationed outside India.Niti Aayog seeks tighter certification and approvalsNiti Aayog suggested that the Grid Controller of India must obtain all relevant certificates and IPRs, software and device/ hardware from the OEMs of foreign origin especially from neighboring countries and send them for certification and approval by Central Electricity Authority of India (CEA), Ministry of Electronics and Information Technology (MeitY) and Standardization Testing and Quality Certification (STQC).Clearances from these organizations or any other relevant organization needs to be made mandatory prior to permission of connectivity to the national or state grid, it also recommended.AI and next-generation firewalls for protectionOn cyber security protection for the PPC software, the Aayog stressed on deployment of Layer 7 Firewall or NGFW (Next Generation Firewall) with DPI capability capable of understanding ICS protocols at the POI (Point of Interconnection) at utility end.It also suggested exploring artificial intelligence (AI)/ machine learning (ML) based threat detection, end point detection & response tools, and vulnerability management modules to build a cyber-resilient environment.Published on August 27, 2026






