AIIMS Delhi and SolarWinds: When Trust in Digital Infrastructure Collapses

One was a 2 week ransomware siege that forced India’s top public hospital onto pen and paper. The other was a month-long espionage operation, hidden inside trusted software that went undetected across the US government and Fortune 500 companies until a security firm found it by accident. Most major breaches aren’t masterminds at work, they are ordinary, known risks such as an unpatched server, an unwatched build pipeline that became a crisis. AIIMS Delhi and SolarWinds show two different failures: one loud and aimed at a hospital, the other silent and aimed at the software supply chain everyone quietly depends on.

AIIMS Delhi (India, November 2022)

On 23rd November 2022, engineers managing servers at AIIMS New Delhi, a 2,500 bed public hospital, found 5 of roughly 100 servers compromised. The e-Hospital system running registration, admissions, billing and lab scheduling went dark. For nearly two weeks the hospital ran entirely on paper and the digital services weren’t fully restored until 6 December.

Media reports, citing police sources, put the ransom demand at roughly ₹200 crore ($23–24 million), allegedly from LockBit, though no payment or attribution was ever confirmed. What is confirmed is that an estimated 30–40 million patient records were compromised. Delhi Police classified the case as cyberterrorism under Section 66F of the IT Act, and the CBI, NIA, Intelligence Bureau, and CERT-In all joined the probe, with jurisdiction itself a point of confusion.

The root cause was that the AIIMS systems hadn’t been meaningfully upgraded in decades along with the weak network segmentation due to which the 5 compromised servers took down the whole digital backbone. When AIIMS faced a second intrusion attempt in November 2023, the government confirmed no breach and no disruption thus proving that these attacks are survivable when checks are in place.

The SolarWinds Hack (United States, 2019–2020)

SolarWinds’ Orion platform is unglamorous network monitoring software used by roughly 33,000 organizations reflecting that it had privileged access deep inside their networks. Around September 2019, suspected hackers quietly entered SolarWinds’ own build environment. In February 2020, they inserted a backdoor SUNBURST into Orion’s source code before it was compiled and signed. Between March and June 2020, roughly 18,000 customers downloaded that legitimate, malware-laced update. It sat undetected until December 2020, when cybersecurity firm FireEye discovered its own breach traced back to a corrupted Orion update. Attackers had used the access to reach a smaller set of roughly 100–200 high value targets, reportedly including the US Treasury, State, Homeland Security, Commerce, Justice and the Energy departments plus the National Institutes of Health, Microsoft, Cisco, Intel and Deloitte.

Nothing was encrypted or ransomed, this was intelligence gathering, which makes the cost harder to tally but no less real. SolarWinds spent over $40 million in three months on remediation, paid $26 million to settle a shareholder lawsuit, and fought a 2 year SEC case naming its CISO for allegedly misleading investors. Some estimates put economy-wide cleanup costs as high as $100 billion. The deeper lesson, hackers didn’t breach 18,000 organizations one by one, they breached 1 trusted vendor and let its own signed update do the work, since standard practice wasn’t built to question a signed update from a known vendor.

What Each Stakeholder Should Take Away

CEOs and Board Members: AIIMS shows what happens when internal risk goes unexamined for years. SolarWinds shows a signed, trusted update can be the attack itself. Ask which vendors or systems could halt operations for two weeks, treat routine updates as verifiable and rehearse a prolonged outage before one happens for real.

Regulators: India had no data protection law when AIIMS was breached. The DPDP Act wasn’t notified until August 2023, with full enforcement not expected until 2027. The US moved faster, the executive order arrived within 6 months, mandating Zero Trust and SBOM requirements but the adoption has been uneven, and the SEC’s CISO case was ultimately dismissed. Even fast regulation can end up short on teeth.

The Public: AIIMS was directly disruptive — delayed labs, exposed diagnoses. SolarWinds was quieter, aimed at governments and corporations, not consumer data but it’s a reminder that software behind the institutions holding your health data can be compromised even when nothing looks wrong but is worth expecting real security discipline and not just a reassurance message.

Interested:

Check out our website: https://sakram-arch.github.io/Sakram-Public/

Preferred Market Access Policy for Indian CyberSecurity Products

The government of India had announced a Preferred Market Access (PMA) policy for Cyber Security products through an order notifying the Public Procurement (Preference to Make in India).

MeitY shall be the nodal Ministry to monitor and administer this PMA policy.

The policy announcement is given at link given here.  Public Procurement (Preference to Make in India) Order 2017- Notifying Cyber Security Products in furtherance of the Order

iSPIRT has been pursuing with MietY, application of PMA for all Indian Software Products to promote the Indian Software product industry and it is heartening to note that at least one important sub-sector of Cybersecurity has caught the Government’s attention.

iSPIRT organised a PolicyHacks session to understand this policy announcement with Ashish Tandon Founder & CEO of Indusface and Mohan Gandhi of Entersoftsecurity.

Ashish has been following the policy announcement and has earlier published a blog at https://pn.ispirt.in/cybersecurityproductsprocurement/

You can watch the discussion with Ashish and Mohan at below given YouTube video, in a question and answer format with Sudhir Singh.

What are the essential features of this Policy?

Ashish described the main features stating that this is a policy that is going to help boost Cybersecurity products in India. Govt. of India identified areas that require boosting ‘make in India’ products for the sensitive areas of cybersecurity.

Is there a way product companies can register or Government is going to keep a registry of ‘made in India’ products?

Ashish explains the policy has provided for the formation of a committee that will further provide for a process for empanelment of Indian Cybersecurity products and Indian Cybersecurity product companies with some defined key aspects that would qualify for empanelment.

Ashish further explained that as the empanelment aspects are decided there may also come up with a process for testing and meeting standards and quality norms etc.

Are there are enough product companies in ‘Cyber Security’ space for empanelment?

Mohan Gandhi answered that there are several product companies, but this policy should further strengthen the ‘make in India’ aspect and companies based out of India with deep tech product can look at getting this advantage of this policy.

Whether the Policy will be applicable to “productized services”?

Ashish answered, that this policy is applicable to the only product and at best give preference to made in India products in turnkey projects wherein a large project cybersecurity product is involved.

How will this policy help Start-up companies in Indian Market?

Mohan mentioned, that one interesting thing about this policy is that, it clearly talks about intellectual property. There is a need to register and prove that the IP belongs to India. It will encourage small companies to register the IP and leverage the Indian IP even when they are selling abroad.

Is there enough clarity exist on process and enplanement etc.?

Ashish feels the policy has already prescribed setting up of an empowered committee who will look at these aspects and it is MeitY that will be responsible for doing this.

Ashish further also elaborated that this Policy will get further push once some companies start getting empanelled and processes and rules are framed under MeitY by the empowered committee.

In concluding remarks, both Ashish and Mohan felt that Cybersecurity ecosystem will get a boost by this policy as the policy is furthering the cause by advising Government departments for preferring Indian products. With Digital economy on anvil, there should be a huge demand in Government and Public sector enterprises for cybersecurity. Cybersecurity product market is today dominated by players from the US, Europe and Israel.

The policy has to be pushed hard to further encourage and coupled with StartupIndia policy, there should be all-out effort to promote the Indian Cybersecurity product companies.