India’s Data Centre Boom Has A Security Blind Spot

India’s Data Centre Boom Has A Security Blind Spot
Data centre security

Data centres have evolved from specialised computing facilities into critical infrastructure powering the modern digital economy. As India rapidly expands its data centre footprint, these facilities are increasingly becoming targets for cyberattacks, physical disruptions and even geopolitical threats.

The stakes are also rising. Data centres now support AI platforms, financial systems, government workloads and other critical infrastructure, meaning an attack or disruption can have consequences far beyond the facility itself.

A recent incident involving the Kudankulam Nuclear Power Plant highlights the growing cybersecurity risks. Last month, nearly 19,000 files allegedly linked to the plant surfaced on the dark web after ransomware group World Leaks claimed a breach involving one of its contractors.

The files included facility blueprints, supplier details and inspection records. Reliance Group said that there was a “partial breach” involving data stored on a server hosted by Yotta Data Services. Yotta said it detected suspicious activity on May 29, and isolated the affected server. The company also told Inc42 in a statement that only the single customer-managed server was impacted, with no effect on any other services of Yotta.

Data Centres Are Big Targets

India’s data centres attracted $1.56 Bn in foreign investment in H1 2026, driven by demand for AI and cloud services. At the same time, the threat landscape facing these facilities is becoming more complex.

According to Afcom’s State of Data Centre 2026 report, human threats, such as insider attacks and external manipulation, are the biggest concern for data centres. Ransomware was close behind, while other major risks included AI-powered identity attacks, advanced persistent threats and DDoS attacks.

As data centres become critical to AI, financial services, government and national security, they are also becoming bigger targets for insider threats, physical attacks and social engineering.

This makes the security of third-party infrastructure increasingly important for enterprises that rely on data centre and cloud providers.

The Burden of Responsibility After Data Breaches

The financial stakes of a breach are rising. According to IBM’s 2026 Cost of a Data Breach Report, the average total organisational cost of a data breach in India reached ₹25.5 Cr in 2026, up 15.9% from ₹22 Cr in 2025.

For enterprises relying on third-party data centres and cloud infrastructure, however, the financial impact of an incident can extend beyond the cost of compromised data, potentially including service disruption, recovery costs, regulatory exposure and contractual liabilities.

India’s data centres come under the ambit of a combination of national privacy legislation, cyber incident reporting rules and infrastructure standards. Data centre operators and cloud providers must comply with overarching mandates and compliance requirements such as the DPDP Act, Cert-In regulations, and the IT Act, 2000, IT Rules, 2011 and the IT Rules, 2021.

For instance, if a data centre processes personal data on behalf of a customer, it may be considered a Data Processor. However, the primary legal responsibility remains with the Data Fiduciary, which can impose obligations on the data centre through contracts, including data security and breach reporting. “Practically, this translates to several contractual obligations being imposed on the Data Processor by the Data Fiduciary, including implementing security measures and notifying breaches,” said Avisha Gupta, partner at Dentons Link Legal.

From a customer perspective too, greater accountability is being sought from data centre companies. According to data centre firm CtrlS’ CISO, Garimella Chandrasekhar Sarma, the industry is seeing a gradual shift towards broader definitions of security and resilience in data centre agreements. While SLA (service level agreement) traditionally focused on availability and performance, discussions now often include security, business continuity, incident response, recovery, and compliance. “The concept of resilience is broadening, while uptime remains essential, organisations are also focusing on how infrastructure adapts to disruptions and sustains operations,” said Sarma.

“The issues related to cybersecurity responsibilities in data centre arrangements are increasingly being determined via contractual structures, outlining the respective responsibilities for the controls, incident response activities, the requirements for data protection, time limits for notifications, liability caps and indemnity,” said Rajesh Chhabra, general manager (APAC, large markets) at cybersecurity firm Acronis.

Malcolm Gomes, chief operating officer, IDfy and head of Privy by IDfy, said enterprises often focus on their own consent and data governance practices but do not always map accountability into their relationships with data processors.

“We work with enterprises across BFSI, fintech, healthcare, and technology; many of whom rely heavily on third-party cloud and data centre infrastructure. What we see consistently is that organisations focus on their own consent and data governance posture but have not mapped the accountability chain into their processor relationships,” said Gomes.

“A Data Processing Agreement that exists on paper but was never operationalised with no security audit, no breach notification protocol, no real-time visibility, is not a safeguard. It is a liability waiting to surface,” he said.

Notably, India’s data centre security market is growing rapidly, driven by rising cyber threats, data breaches and regulatory requirements. Organisations are increasingly investing in integrated security solutions to protect critical data, with cloud adoption driving the largest segment and regulatory compliance emerging as the fastest-growing area, according to a report by Market Research Future. The India data centre security market size is projected to grow from $1.3 Bn in 2025 to $3.5 Bn by 2035 at a CAGR of 10.2% during the forecast period.

The issue of data centre security is gaining attention globally as data centres become increasingly important to national digital infrastructure.

The US may not yet have a single comprehensive regulatory framework governing data centres, but a growing collection of investment security, data protection, export control and supply chain measures is creating a complex compliance environment for operators, investors and technology providers.

Similarly, Singapore’s proposed Digital Infrastructure Bill, on which the public can now provide feedback, introduces a licensing regime to hold data centre and cloud services operators to higher standards of resiliency as they have become the backbone of everyday life.

Physical Threats Are Also Rising

Cybersecurity, however, is only one part of the risk equation. As data centres become more strategically important, they are also increasingly vulnerable to physical threats ranging from fires to attacks linked to geopolitical conflicts.

Amid the major conflict in March between the US-Israel coalition and Iran in the Middle East, Amazon Web Services’ data centre facilities were impacted. At least three AWS data centres, two in the United Arab Emirates (UAE) and one in Bahrain, were damaged by drone strikes.

Data centre security

This is one of the first instances of data centre disruption as a direct result of military activity. Notably, Iran’s armed forces launched the strike on the AWS facilities to potentially identify the role of these centres in supporting the military and intelligence activities of the US and Israeli forces, according to Iranian state TV.

The incident has shown how data centres can become targets amid geopolitical conflicts. There are other instances too.

In June, a blaze at the STT Global Data Centres India facility, owned by Singapore’s ST Telemedia and India’s Tata Communications, caused “extensive damage” to parts of the site, making data recovery difficult.

The incident left some customers fearing the loss of decades of data and caused network disruptions for Google Cloud services in India, according to a company letter and sources.

Another 2024 Reuters report spoke of a fire at a data centre operated by India’s largest telecom carrier, Reliance Jio, which caused a nationwide network outage for its users, according to a source with direct knowledge of the matter.

India’s Expanding Data Centre Footprint

The risks come at a time when India is witnessing an unprecedented expansion in data centre capacity. India generates nearly 20% of the world’s data, while the sector has attracted massive investments over the past 12–18 months. These include Google’s $15 Bn data centre project and Meta’s partnership with Reliance to develop a 168 MW facility in Gujarat.

Projects such as these are part of nearly $70 Bn worth of data centre investments already underway in India, with another $90 Bn in projects announced, according to the government. IT minister Ashwini Vaishnaw has described data centres as “growth engines” for economies such as India.

But as the scale and strategic importance of these facilities grow, so does their exposure to risk. Beyond challenges around power availability, land, connectivity and capital, operators now have to contend with a growing mix of cyberattacks, insider threats, physical disruptions and geopolitical risks. The central government has announced plans to make it easier to build and grow data centres. The next phase of policymaking could benefit from securing data centres as critical infrastructure.

[Edited by Nikhil Subramaniam]

The post India’s Data Centre Boom Has A Security Blind Spot appeared first on Inc42 Media.