Sameer Jain, Managing Director, Primus Partners stated that the Kudankulam incident marks a significant shift from the 2019 malware attack, underscoring how third-party vendors have become one of the most critical cybersecurity vulnerabilities for essential infrastructure.He said that while the reactor's Operational Technology (OT) systems remained air-gapped and uncompromised, storing sensitive engineering drawings on commercial cloud infrastructure effectively circumvented the physical safeguards protecting the facility. He added that organisations can build robust digital defences around critical infrastructure, but if contractors handling sensitive engineering assets store designs on inadequately secured commercial cloud platforms, the security perimeter has effectively already been breached. Cyber resilience, he noted, is only as strong as the weakest link in the broader supply chain.
