Top 5 Cyber Security Compliance Mistakes Indian Companies Must Avoid
Cyber attacks on Indian companies are rising fast—but most failures still come down to the basics. From missed reporting deadlines to unchecked vendor risks, here are 5 compliance mistakes Indian companiescan’t afford to ignore.

In 2025 alone, CERT-In recorded over 29 lakh cyber security incidents in India. That is roughly 8,000 attacks every single day. Indian organisations faced an average of 2,011 cyberattack attempts every week — significantly above the global average, according to industry reports.
And yet, according to Cisco's 2025 Cybersecurity Readiness Index — published in May 2025 — only 7% of Indian organisations have the level of cyber security maturity needed to effectively handle a real attack. That means 93 out of every 100 companies are, right now, operating exposed.
The incidents speak for themselves. In January, Tata Technologies was hit by ransomware. In February alone, Raymond Ltd, Niva Bupa, and Angel One all disclosed security incidents within days of each other. Two Delhi hospitals were hacked on the same night in June 2025 — patient records gone, systems down, staff writing everything by hand. What makes these incidents striking is not their scale. It is that they reflect the same basic compliance failures, repeated across industries, year after year.
The laws are clear. The DPDP Act is enforceable. CERT-In has one of the strictest breach-reporting deadlines in the world. Non-compliance can cost a company up to ₹250 crore. Cyber security is no longer something leadership can delegate to the IT team and check on once a quarter. It is a governance responsibility — and the cost of getting it wrong is climbing fast.
Here are the five mistakes Indian companies keep making.
Mistake 1: Doing Just Enough to Pass the Audit
Most companies approach cyber security compliance like a one-time exam. Prepare for the audit, clear it, and move on — until the next cycle. What this misses entirely is that cyber threats do not pause between audit windows.
Regulators are no longer just checking whether a policy document exists. They want to see whether it is actually being followed — in how data is handled daily, in vendor contracts, in whether employees know what to do when something goes wrong.
The Hathway breach of 2024 — which exposed data belonging to over 41.5 million customers — is still relevant here because the root cause was an unpatched vulnerability in a content management system. Not a sophisticated nation-state attack. A basic fix that was never made. A gap that no audit caught, or that was noted and never acted on.
Compliance checked off on paper does not protect a company in the real world. Compliance that is genuinely lived does.
The leadership question: If regulators asked to see how the organisation actually handles personal data today — not what the policy says, but what actually happens — would the answer hold up?
Mistake 2: Not Being Ready for the 6-Hour Reporting Clock
When a cyber security incident is detected, CERT-In requires it to be reported within six hours. Not six working days. Not once lawyers have reviewed everything. Six hours from the moment someone notices something is wrong.
This is one of the toughest reporting deadlines anywhere in the world. And most companies are not built to meet it. There is no pre-approved notification draft. No single person with the authority to file the report. No rehearsed sequence of steps. So when an actual incident hits, the first critical hour is typically spent in a room full of people arguing about who is responsible for what.
The stakes for getting it wrong go beyond a financial penalty. Under the IT Act, responsible officers can face up to a year in imprisonment for failure to report cyber incidents.
When Raymond Ltd disclosed a breach in February 2025, they moved quickly to contain it. That speed came from preparation, not instinct. Most organisations, without that preparation, would still be in the "figuring it out" phase long after the six-hour window had closed.
The leadership question: Is there one person in the organisation — right now — who has the authority to file a CERT-In report at 2 AM, and knows exactly how to do it?
Mistake 3: Trusting Vendors Without Verifying Them
Many serious breaches did not start inside the target company. They started with a vendor.
According to IBM's Cost of a Data Breach Report 2025 — which surveyed Indian organisations specifically — third-party vendor and supply chain compromise was the second most common cause of data breaches in India in 2025, accounting for 17% of all incidents. Only phishing ranked higher, at 18%.
This played out directly in 2025. The Bashe ransomware group claimed responsibility for a malware attack on a third-party vendor portal connected to ICICI Bank, allegedly using it to harvest credentials and access banking infrastructure. The bank was the intended target. The vendor was the entry point. This pattern — attackers exploiting a trusted but less-secured supplier — is now the dominant model for attacks on India's BFSI sector.
The DPDP Act addresses this in clear terms. Any vendor that processes personal data on behalf of a company must be bound by a legal contract enforcing the same data protection standards. This is not a formality. It is an enforceable obligation with direct liability implications. And yet, many organisations still have no formal vendor security assessment process in place.
The leadership question: Has the organisation independently verified the cyber security posture of its most critical vendors — not asked them to self-certify, but actually verified?
Mistake 4: Leaving Cyber Security to the IT Team
A cyberattack is not an IT emergency. It is a business emergency.
Revenue stops. Customers leave. Share prices fall. Regulators investigate. And the leadership team finds itself in the middle of a crisis it was never included in preparing for.
This is the most persistent structural failure in Indian organisations. Cyber security is treated as a technical function. The board hears about it once or twice a year in a summary presentation. Nobody at the top is deeply familiar with the risk, the plan, or their own role in it — until it is too late to matter.
Cisco's 2025 Cybersecurity Readiness Index found that 81% of Indian organisations anticipate a cyber security incident disrupting their business within the next 12 to 24 months. That is a staggering level of expected disruption — and a majority of those same organisations do not have leadership-level incident ownership in place.
SEBI's Cyber Security and Cyber Resilience Framework, which came into effect for regulated entities, explicitly requires board-level accountability for cyber security posture. This is the regulatory direction of travel — leadership cannot treat security as someone else's problem.
The June 2025 attack on two Delhi hospitals makes the real-world cost visible. Both facilities were taken down on the same night. Patient records accessed. OPD and IPD digital workflows disrupted. Staff reverting to paper. The attacks were not unusually sophisticated. The facilities were simply unprepared at every level — and there was no leadership framework in place to respond quickly or effectively.
The leadership question: Does the board have a genuine, working understanding of the organisation's cyber risk — with a named person accountable for it and a rehearsed response plan — or just an annual slide deck?
Mistake 5: Underestimating the People Problem
No amount of technology fully eliminates the human vulnerability. In India in 2025, phishing remained the single most common cause of data breaches at 18%, according to IBM's 2025 report. That figure has not meaningfully improved in years — because the technical defences have improved, but the human behaviour has not kept pace.
The threat itself is evolving fast. In 2025, AI is being used to generate phishing emails that are contextually precise, grammatically flawless, and personalised to the recipient. Voice cloning tools can impersonate a CFO or senior executive on a phone call convincingly enough to fool even cautious employees. Indian financial institutions have already seen multi-crore fraud attempts using this approach — a cloned voice, a plausible story, and a request to authorise a transfer.
The standard response — a generic annual cyber security awareness session — has not worked and will not work. Cisco's 2025 index found that 52% of Indian employees do not fully understand how attackers are using AI, and only 66% of organisations feel confident their teams grasp AI-related threats at all. The training gap is real, and it is widening.
IBM's 2025 report also found that organisations in India that were breached took an average of 263 days to identify and contain the incident. That is nearly nine months. Much of that delay traces back to employees not recognising warning signs early enough, and internal teams not knowing what to look for or who to tell.
The leadership question: If a convincing, AI-generated phishing email landed in the finance team's inbox today — one that appeared to come from a board member — what would actually happen?
Closing Line
India's digital economy is on its way to representing a fifth of the country's GDP by 2030. The attack surface is growing at the same pace.
The numbers from 2025 are not abstract. IBM's Cost of a Data Breach Report 2025 found that the average cost of a data breach in India hit an all-time high of ₹22 crore (INR 220 million) — a 13% rise from the previous year, and a figure that has been climbing consistently every year. Add potential DPDP Act penalties of up to ₹250 crore, and the financial exposure from a single serious incident can threaten the viability of even a large organisation.
The companies that approach cyber security compliance as a living, board-owned, continuously practised discipline are the ones that contain damage when incidents occur. The ones that treat it as a checklist are the ones that spend nine months figuring out they were breached — and then explain it publicly.
That is an avoidable situation. But only if the work starts now.
Frequently Asked Questions
Why is cyber security and compliance training important for employees?▼
Effective employee training is crucial for ensuring that staff understand their compliance responsibilities and the regulatory environment in which they operate. By fostering a culture of compliance, trained employees are more likely to adhere to regulations and report potential violations. Regular training programs also help SMEs adapt to evolving regulations, minimizing the risk of non-compliance.
Do SMEs need to comply with more than one compliance regulation?▼
Yes, SMEs may need to comply with multiple regulations. For example, if an SME handles personal data of individuals in India, they must adhere to the DPDP. If the same business processes the personal data of individuals in the EU, they will also need to comply with GDPR.
How can SMEs track and document their compliance efforts effectively?▼
SMEs should begin by keeping simple, organized records of their security rules, steps they take to protect data, and any checks they do, like security reviews or audits. Regularly update these records and keep track of employee training, security incidents, and any outside assessments to show that you are following the rules. This makes it easier to stay on top of compliance and show proof if needed.
How does communication strengthens stakeholder relationships▼
Transparent and consistent communication fosters trust and collaboration, ensuring stakeholders feel valued and engaged in cyber security initiatives.
How does understanding compliance requirements help small businesses build trust with their customers?▼
Understanding compliance requirements helps small businesses build trust with their customers by showcasing their commitment to protecting sensitive information. When businesses adhere to regulations, they present themselves as reliable and responsible, which reassures customers and strengthens relationships. Furthermore, compliance minimizes the risk of operational disruptions, ensuring that businesses can consistently deliver on their promises to customers.
How Small Businesses Can Solve Compliance Challenges and Which Tools to Use (gaper.io)
Request a demo
Reduce human cyber and compliance risks with targeted training.
Get a guided walkthrough — at a time that suits your timezone.