DPI Brief — August 17, 2026

India’s DPI ecosystem saw significant movement this week across identity, cybersecurity, and infrastructure security layers. Here are the five most important updates.

1. UIDAI Extends Free Aadhaar Email Updates via Mobile App — L1 (Identity)

UIDAI has made email address updates linked to Aadhaar free through its mobile app until 31 December 2026, waiving the usual ₹50–75 fee. Users can update via the Aadhaar app with OTP verification and face authentication, with changes typically reflecting within 2–3 hours. The move lowers the barrier for citizens to maintain a secondary recovery channel alongside mobile numbers — a small but meaningful improvement to the identity layer’s resilience, especially as Aadhaar increasingly underpins financial services, e-KYC, and welfare delivery.

2. CEA Notifies Landmark Cyber Security Regulations for Power Sector — L7 (Trust) × L6 (Governance)

The Central Electricity Authority has notified the Cyber Security in Power Sector Regulations, 2026 under the Electricity Act 2003, effective 1 April 2027. The framework is comprehensive: mandatory CISO appointments, IT/OT network segregation, data residency requirements for cloud-hosted operational data, and vulnerability remediation timelines (high-risk within one month, medium/low within three months). Cybersecurity incidents must be reported to CSIRT-Power and CERT-In within six hours; critical cyber-sabotage within 24 hours. Remote OT operations are restricted to India-only, isolated channels. This regulation effectively extends India’s CERT-In ecosystem into the power sector — India’s most critical physical infrastructure — and signals that sectoral CERT frameworks are becoming the norm.

3. CERT-In and SIA-India Release Joint Cybersecurity Guidelines for Space Sector — L7 (Trust)

CERT-In and the Society of India Aerospace Engineers (SIA-India) have issued joint cybersecurity guidelines for India’s space sector, calling on space enterprises to adopt “secure-by-design” architecture aligned with national security imperatives. The guidelines come as India’s private space industry accelerates — IN-SPACe is simultaneously proposing a ₹500 crore third-party insurance cap for private launches. As space becomes a new domain for both commercial activity and geopolitical competition, cybersecurity of satellite communications, ground stations, and launch infrastructure is a nascent but critical concern. The guidelines signal that India’s trust infrastructure is expanding beyond traditional IT to cover emerging sectors.

4. CERT-In Issues High-Severity Advisory for Google Chrome Vulnerabilities — L7 (Trust)

CERT-In has issued a high-severity vulnerability note flagging multiple critical flaws in Google Chrome across Windows, macOS, and Linux. The vulnerabilities stem from “use-after-free” memory errors in core components including V8, TabStrip, HTML, Extensions, and Blink rendering engine. Successful exploitation allows remote code execution, system takeover, and denial-of-service conditions. The advisory urges immediate browser updates. With Chrome commanding over 70% desktop browser share in India, this affects hundreds of millions of users — many of whom use Chrome as their primary gateway to UPI apps, DigiLocker, and government portals.

5. NIELIT Launches CYBER KUSHTI 2026 — National Cybersecurity & AI Hackathon — L7 (Trust)

NIELIT (under MeitY) launched CYBER KUSHTI 2026 on 15 August — a national hackathon that tests human judgment in cybersecurity assessments rather than traditional vulnerability hunting. Teams receive identical, deliberately imperfect Security Assessment Packages containing AI-generated findings with false positives, duplicates, and omitted real vulnerabilities. Participants must produce corrected, prioritized assessments and defend their decisions. Registration is open until 10 September (free), with three rounds culminating in an in-person final on 9 October in New Delhi. CERT-In is the knowledge partner. The format reflects a growing recognition that as AI tools proliferate in security operations, the ability to evaluate and prioritise machine-generated findings is as important as the ability to find vulnerabilities in the first place.


Layers covered: L1 (Identity), L6 (Governance), L7 (Trust)

Sources: Times of India — Aadhaar Email Update, Times of India — CEA Cyber Security Rules, DD News — CERT-In Space Guidelines, Times of India — CERT-In Chrome Advisory, The Statesman — CYBER KUSHTI 2026