India has built one of the world’s most ambitious digital backbones: the identity, payments and data rails that now carry public services and much of the economy, with a fast-growing layer of AI and compute on top. The harder question is no longer how much India can build, but how much of what it has built is actually controlled by it.
That is what lies at the heart of sovereign infrastructure. Not simply where data and compute physically sit, but who holds the keys to them, under whose laws they operate, and whether critical systems can keep running and be restored on domestic terms when something fails. It spans data residency and sovereign cloud, home-grown AI compute, control over the technology and supplier stack, and the resilience to recover without waiting on decisions made elsewhere.
There is no doubt that India has moved decisively on building the backbone. The chips and the legal scaffolding will take years; what should be moving faster is the operational discipline: domestic control of the keys, the data and the recovery that turns this infrastructure into sovereign infrastructure. Three patterns make this gap visible.
Where the Gap Shows
The first is compute. Procurement cycles for government and enterprise tenders routinely stretch to three or six months, long enough for the pricing of hardware, GPUs and cloud to reset more than once. Nowhere is this clearer than the rush for GPU capacity: state governments and central agencies have moved into AI infrastructure, often before the use cases, or the data governance, fragmented data environments and specialised skills, that would justify it are in place. Compute acquired as a signal of ambition, ahead of the control needed to run it sovereignly, risks low utilisation and limited impact despite heavy capital outlay.
The second is data. The digital footprint of the Indian state now reaches well beyond the eight to ten ministries that once drove government technology, into citizen services, agriculture, health and transport, and into AI labs across hundreds of colleges. As that footprint multiplies, so does the question of where all this data resides and who can reach it. Education, healthcare and manufacturing, the most heavily digitised sectors of the past five years, already absorb nearly 47 per cent of all recorded attacks on Indian organisations. The reach has grown faster than the discipline needed to govern and defend it.
The third is resilience. Mid-tier banks, cooperative banks, mid-sized hospitals and Tier 2 and 3 manufacturers carry the same exposure as the largest enterprises on far tighter budgets, as do many public institutions and regional service providers, yet sovereign-grade continuity has been built mainly for the top of the pyramid. These institutions hold citizen records, process public funds and run essential services. A digital backbone is only as sovereign as its least-protected layer.
Where the Policy Still Falls Short
Most security spending in India still favours prevention: perimeter, endpoint, detection. These remain necessary but, on their own, are insufficient. Less than one per cent of incidents last year were ransomware, yet they did the most damage to services, production and access to data. The lesson is not to abandon prevention, but to weight the budget towards what happens after an attack: whether systems can be restored quickly, and on whose terms.
On the government side, that question of whose terms runs into a policy gap. Critical sectors are each shaping their own cloud rules, states are building their own data centres, and central ministries are each finding their own path, but nobody has connected these into one roadmap. Railways and the power sector have gone further, standing up their own entities, RailTel and PowerGrid’s PowerTel, specifically to keep data-centre infrastructure and data in-house; proof that deliberate sector-level control is possible once a sector decides it matters enough.
By the numbers
- 47%
- Share of attacks targeting digitised sectors
- <1%
- Ransomware share of incidents, yet most damaging
The US offers one useful reference: FedRAMP grades government applications by sensitivity, so citizen-facing services and defence systems sit on different tiers of control. Where recovery environments sit, who controls the encryption keys, and who can compel access are sovereignty decisions as much as technical ones. This is where resilience and sovereignty converge: a system that keeps running through disruption and recovers under domestic control is the working definition of a sovereign digital backbone.
What India Will Be Measured on Next
Four shifts will close the gap. Investment moving from acquiring capacity towards governing and recovering it: immutable backups, tested recovery and continuity plans. Clear milestones for departments and states to work towards, so procurement and policy decisions follow one roadmap instead of each moving separately.
Supply-chain governance becoming more architectural, with every contract, integration and access path treated as part of the operating perimeter. And sovereign-grade continuity, once reserved for large enterprises, reaching the mid-market through managed and cloud-based models priced to their economics, giving mid-sized institutions not just access to enterprise-grade tools but real control over their own data and recovery.
India’s digital ambitions are no longer constrained by infrastructure. They are shaped by the resilience and sovereignty of the systems, institutions and supply chains beneath them. Building the backbone was the first challenge. Keeping it dependable, and under sovereign control, at scale is where the attention is turning to next.
The author is Sr. Director, Sales, Hitachi Vantara. Views are personal.

