India’s Cyber Threat Landscape Is Now a National competitiveness Problem
India today sits in a paradox: it is one of the world’s fastest-growing digital economies and simultaneously one of its most heavily targeted cyber domains. The volume, sophistication and business impact of attacks now make cybersecurity a board-level and national-security issue, not just a technology problem. What is happening is not just “more attacks.” The threat mix is shifting toward credential theft, phishing-led payment fraud, SIM-swap-enabled account takeover, cloud exposures, ransomware-driven data extortion and AI-assisted impersonation.
India’s cyberattack numbers in perspective
Check Point’s State of Cyber Security in India 2025 report shows that organisations in India faced an average of 2,011 cyberattacks per week in 2025, significantly above global averages. Across all industries, India is consistently described as “one of the most heavily targeted countries globally”, underscoring that this is not an isolated spike but a structural pattern. Subsequent threat intelligence indicates that by late 2025, Indian organisations were seeing around 3,195 to 3,291 weekly attacks, compared with roughly 1,800–2,000 globally, widening the gap further.
Sector hotspots: education, healthcare, government and BFSI
Education has emerged as the single most targeted industry in India, with institutions facing between 4,248 and 9,817 attacks per organisation per week, far exceeding other sectors. Healthcare, government and business services also experience elevated pressures, with some reports putting weekly attacks on Indian healthcare organisations above 8,600 and on government/military entities around 4,700. BFSI remains a prime focus because of the concentration of financial and identity data and its tight interlink ages with the broader economy.
Behind these per-organisation statistics lies a broader surge in reported cyber incidents across the country. Government data compiled by CERT-In and tabled in Parliament show that reported cyber incidents rose from around 1.4 million in 2021 to 2.041 million in 2024 and 2.944 million in 2025, more than doubling over four years. Parallel analyses note that these incidents span phishing, ransomware, website defacement, data breaches, denial-of-service attacks and unauthorised scanning, indicating stress across both citizen-facing and enterprise systems. The trend line is unambiguous: more organizations are being hit, more often, and at greater operational scale.
The cost of a breach in India
The IBM Cost of a Data Breach 2024 report finds that the average cost of a data breach in India reached a record high of about Rs. 19.5 crore (INR 195 million) in 2024, up 39 percent since 2020 and 9 percent year-on-year. Lost business which includes operational downtime, customer churn and reputational damage accounts for a substantial part of this increase, with lost business costs alone rising nearly 45 percent over the prior year. Industry analysts suggest that by 2025, typical breach costs for Indian enterprises were trending even higher, towards the Rs. 22 crore mark, especially in regulated, data-heavy sectors.
Attackers’ favourite entry points
Phishing and stolen or compromised credentials consistently emerge as the most common initial attack vectors in Indian breaches, each accounting for roughly 18 percent of observed incidents. Business email compromise (BEC), social engineering and classic phishing are also among one of the most expensive causes of breaches, with BEC incidents in India averaging about Rs. 21.5 crore per breach. Cloud misconfiguration is another critical vector, representing around 12 percent of initial breach causes and often leading to long detection and containment times when multiple environments are involved.
India’s malware problem is equally stark: one 2025 threat-intelligence study found around 369 million malware detections in a year, including large volumes of Trojans and file infectors. Trojans alone made up over 40 percent of detections and are frequently linked to credential theft, ransomware deployment and silent persistence inside networks. Multiple reports highlight infostealer malware designed to harvest credentials and tokens from browsers and devices as a key driver behind account takeovers and lateral movement within organisations.
Mobile threats are rising rapidly, with some analyses indicating that about 42 percent of detected mobile threats are outright malware, followed by potentially unwanted programs and adware. These patterns are particularly concerning in a market where smartphone-based payments, banking and identity services have become ubiquitous, especially via UPI and app-based financial services. Regionally, states such as Delhi,
Telangana and Tamil Nadu stand out as malware hotspots, reflecting dense urbanisation and high digital adoption, but also uneven security controls across enterprises and small businesses.
Root Causes and Global Context
- The first root cause is that digital expansion has progressed faster than the corresponding maturity of security systems and controls. India’s digital growth is a strategic success, but it has enlarged the attack surface faster than many institutions have matured their controls. India’s digital public infrastructure, UPI, Aadhaar, e-KYC, cloud-based platforms and widespread mobile broadband has dramatically increased the number of digital endpoints and data repositories in a short period. This rapid expansion has outpaced security investments in many organisations, particularly in MSMEs, educational institutions and smaller hospitals, which often run legacy or end-of-life systems with weak access controls. The result is a vast, heterogeneous attack surface where sophisticated attackers can often find a weak link, whether in an organisation’s own environment or a less-protected vendor in its supply chain. In other words, more of India’s economy now depends on systems whose disruption would hit national security, public health, or financial stability.
- The second root cause is operational complexity. Check Point found that 71% of organizations rely on more than 10 cloud security tools and 49% face a shortage of skilled security professionals. Many Indian organisations still treat cybersecurity primarily as an IT function rather than a core business and risk-governance issue. Studies highlight gaps in patch management, identity and access management and network segmentation, alongside chronic under-investment in skilled cybersecurity talent. Incident detection and response processes are frequently fragmented, leading to long dwell times. Global IBM data show that breaches involving data across multiple environments can take over 320 days to identify and contain, and Indian trends closely mirror this complexity. Rising spend is important, but it does not automatically produce resilience when organizations till have fragmented visibility, duplicated tools and delayed remediation.
- The third root cause is uneven implementation of policy and governance. India does not lack cyber rules. RBI requires board-approved cyber policy, incident response and prompt incident reporting from banks. CERT-In’s 2022 directions require covered entities to report specified incidents within six hours. RBI’s 2024 fraud-risk framework requires regulated entities to immediately report fraud incidents to law enforcement and to mandatorily report frauds of Rs 1 lakh or more. And the DPDP Rules, require affected individuals to be informed without delay when a personal data breach occurs. The challenge is not the absence of frameworks; it is the gap between framework and field execution.
Globally, India is facing the same pressures as others are seeing, but at larger public scale. Microsoft’s 2025 report says government and IT were the most impacted sectors worldwide and initial access remains heavily tied to public-facing applications, valid accounts, social engineering and phishing. Recent academic work on digital payment use in India also argues that perceived cybersecurity risk and grievance redressal materially shape trust in digital payments. That makes cyber risk a development issue as much as a technology issue: poor security erodes adoption, not just uptime.
What Indian organisations need to prioritise now
From a business standpoint, the combination of high attack volumes, rising breach costs and tightening regulation demands a strategic, board-owned approach to cyber risk. Cybersecurity needs to be integrated into enterprise-risk management, with clear risk appetite definitions, regular reporting to the board and alignment between cyber-spend and business-critical assets. In practice, this means moving beyond annual audits to continuous oversight, scenario-based discussions and clear accountability for cyber outcomes at senior-management level.
1. Building a modern security architecture
Technically, Indian organisations must accelerate the shift from perimeter-centric models to zero-trust architectures that assume breach and continuously verify users, devices and services. This entails strong identity and access management, multi-factor authentication, micro-segmentation and pervasive encryption for sensitive data at rest and in transit. Given the prominence of cloud misconfigurations and multi-cloud environments in recent breaches, cloud-security posture management and secure-by-design practices for new applications are equally critical.
2. Strengthening detection, response and resilience
Detection and response capabilities, often the weakest link, need sustained investment in log management, security information and event management (SIEM), endpoint detection and response (EDR/XDR) and well-rehearsed incident-response playbooks. IBM’s data show that organisations able to detect and contain breaches in under 200 days can save several crores compared with those that take longer, highlighting the economic case for faster response. For Indian enterprises, regular tabletop exercises, red-team simulations and crisis-communication planning should become routine, particularly in regulated sectors like BFSI, healthcare and telecom.
3. Managing third-party and supply-chain risk
Modern Indian enterprises are deeply enmeshed in vendor ecosystems, cloud providers, fintech partners, IT services vendors and specialised SaaS solutions, which can all expand the attack surface. Several high-profile global incidents have originated in supply chains rather than core systems and Indian regulators are increasingly sensitive to third-party risk in banking and critical infrastructure. Robust vendor-risk management, security clauses in contracts, independent assurance and continuous monitoring of key partners are essential to avoid “security by assumption”.
4. People, culture and citizen awareness
Technology cannot compensate for weak cyber hygiene and low awareness among employees and citizens. Phishing, social-engineering and fraud statistics in India, particularly the Rs. 36,450 crore in financial cyber-fraud losses reported to the National Cyber Crime Reporting Portal by early 2025, show how effectively attackers exploit human trust and process gaps. Continuous, context-rich awareness programmes for staff and citizen-facing campaigns on safe digital practices, are crucial complements to technical controls.
5. The role of government and regulators going forward
On the state side, sustaining and scaling institutions such as CERT-In, NCIIPC and sectoral CERTs will be central to managing systemic cyber risk as digital penetration deepens. Policy priorities include clarifying overlaps between various agencies, improving threat-intelligence sharing with the private sector and incentivising timely, high-quality reporting rather than box-ticking compliance. In parallel, investment in domestic cybersecurity R&D, start-up ecosystems and skills development can help build indigenous capabilities instead of relying solely on imported technologies.
Towards a resilient digital India
India’s cyber story is not just one of vulnerability; it is also one of opportunity to embed resilience into the very fabric of its digital economy. The same ambition that built world-class platforms in payments and identity can be channelled into building world-class defences, governance frameworks and talent pipelines for cybersecurity. If policymakers, regulators, boards and technology leaders move in concert, India can shift the narrative from being “one of the most targeted” markets to one of the most resilient, turning cyber-risk into a managed, strategic dimension of its digital rise.
Authored by:

Rupinder Kaur Sodhi
Chief Manager (Research)
State Bank Staff College
Hyderabad

