India’s Data Centre Boom Has A Security Blind Spot

by · Inc42

SUMMARY

  • India’s rapidly expanding data centre infrastructure is facing a growing mix of cybersecurity, physical and geopolitical threats, raising concerns over the resilience of critical digital infrastructure.
  • As data centres power AI, cloud, financial services and government systems, disruptions can have consequences far beyond the facility, with the average cost of a data breach in India reaching ₹25.5 Cr in 2026.
  • From the alleged Kudankulam-linked breach and rising ransomware threats to data centre fires and geopolitical attacks, the story examines the evolving risk landscape and how enterprises, operators and regulators are allocating responsibility for security and losses.
  • Added to Saved Stories in Login

Data centres have evolved from specialised computing facilities into critical infrastructure powering the modern digital economy. As India rapidly expands its data centre footprint, these facilities are increasingly becoming targets for cyberattacks, physical disruptions and even geopolitical threats.

The stakes are also rising. Data centres now support AI platforms, financial systems, government workloads and other critical infrastructure, meaning an attack or disruption can have consequences far beyond the facility itself.

A recent incident involving the Kudankulam Nuclear Power Plant highlights the growing cybersecurity risks. Last month, nearly 19,000 files allegedly linked to the plant surfaced on the dark web after ransomware group World Leaks claimed a breach involving one of its contractors.

The files included facility blueprints, supplier details and inspection records. Reliance Group said that there was a “partial breach” involving data stored on a server hosted by Yotta Data Services. Yotta said it detected suspicious activity on May 29, and isolated the affected server. The company also told Inc42 in a statement that only the single customer-managed server was impacted, with no effect on any other services of Yotta.

Data Centres Are Big Targets

India’s data centres attracted $1.56 Bn in foreign investment in H1 2026, driven by demand for AI and cloud services. At the same time, the threat landscape facing these facilities is becoming more complex.

According to Afcom’s State of Data Centre 2026 report, human threats, such as insider attacks and external manipulation, are the biggest concern for data centres. Ransomware was close behind, while other major risks included AI-powered identity attacks, advanced persistent threats and DDoS attacks.

As data centres become critical to AI, financial services, government and national security, they are also becoming bigger targets for insider threats, physical attacks and social engineering.

This makes the security of third-party infrastructure increasingly important for enterprises that rely on data centre and cloud providers.

The Burden of Responsibility After Data Breaches

The financial stakes of a breach are rising. According to IBM’s 2026 Cost of a Data Breach Report, the average total organisational cost of a data breach in India reached ₹25.5 Cr in 2026, up 15.9% from ₹22 Cr in 2025.

For enterprises relying on third-party data centres and cloud infrastructure, however, the financial impact of an incident can extend beyond the cost of compromised data, potentially including service disruption, recovery costs, regulatory exposure and contractual liabilities.

India’s data centres come under the ambit of a combination of national privacy legislation, cyber incident reporting rules and infrastructure standards. Data centre operators and cloud providers must comply with overarching mandates and compliance requirements such as the DPDP Act, Cert-In regulations, and the IT Act, 2000, IT Rules, 2011 and the IT Rules, 2021.

For instance, if a data centre processes personal data on behalf of a customer, it may be considered a Data Processor. However, the primary legal responsibility remains with the Data Fiduciary, which can impose obligations on the data centre through contracts, including data security and breach reporting. “Practically, this translates to several contractual obligations being imposed on the Data Processor by the Data Fiduciary, including implementing security measures and notifying breaches,” said Avisha Gupta, partner at Dentons Link Legal.

From a customer perspective too, greater accountability is being sought from data centre companies. According to data centre firm CtrlS’ CISO, Garimella Chandrasekhar Sarma, the industry is seeing a gradual shift towards broader definitions of security and resilience in data centre agreements. While SLA (service level agreement) traditionally focused on availability and performance, discussions now often include security, business continuity, incident response, recovery, and compliance. “The concept of resilience is broadening, while uptime remains essential, organisations are also focusing on how infrastructure adapts to disruptions and sustains operations,” said Sarma.

“The issues related to cybersecurity responsibilities in data centre arrangements are increasingly being determined via contractual structures, outlining the respective responsibilities for the controls, incident response activities, the requirements for data protection, time limits for notifications, liability caps and indemnity,” said Rajesh Chhabra, general manager (APAC, large markets) at cybersecurity firm Acronis.

RECOMMENDED FOR yOU