Cybersecurity for Indian SMBs 2026: A No-Jargon Starter Kit

A no-jargon, budget-aware cybersecurity starter kit for Indian SMBs. Learn the real threats, cheapest fixes, and what a defensible setup actually costs.

Amit Verma16 September 2026 12 min read
Cybersecurity for Indian SMBs 2026: A No-Jargon Starter Kit

Last year I got a call at 9pm from a friend who runs a 22-person textile trading firm in Surat. Their accountant had wired ₹6.8 lakh to a supplier's "new bank account" after receiving an email that looked exactly like it came from their regular vendor in Ludhiana. Same signature, same logo, same broken English the vendor always used. The only difference was one letter in the domain name. The money was gone by morning.

This wasn't a sophisticated hack. Nobody broke into a server. It was a plain email spoofing scam, the kind that costs Indian SMBs crores every year and almost never makes the news. According to CERT-In, India recorded over 15.9 lakh cybersecurity incidents in a single year, and the overwhelming majority of successful attacks on small businesses start with something as boring as an email. Ransomware, fake invoices, WhatsApp OTP theft, none of it requires a genius attacker. It requires a business with no basic defenses.

This post is a practical, budget-aware starter kit for cybersecurity for Indian SMBs that have no dedicated IT team and no appetite for a ₹10 lakh security audit. I'll walk you through the real threats, the cheapest effective fixes, a proper worked example of what a defensible setup costs, and the mistakes I keep seeing owners make. You can hand most of this straight to your vendor.

Key Takeaways
  • Over 80% of attacks on small firms start with email. Fixing your email (SPF, DKIM, DMARC, MFA) is the single highest-return security move you can make.
  • Multi-factor authentication (MFA) on email, banking, and accounting software blocks the vast majority of account takeovers, and it's free.
  • A solid baseline security setup for a 20-person firm costs roughly ₹1,500–₹3,000 per user per year, less than what most companies waste on unused software.
  • Ransomware is survivable if you have offline or immutable backups. It's a business-ending event if you don't.
  • Train your accounts team specifically on invoice fraud and "change of bank details" emails. That one hour prevents the most expensive losses.
  • The DPDP Act 2023 now makes protecting customer data a legal obligation, not just good practice.

What cyber threats actually hit Indian SMBs (not the scary Netflix version)

Forget the hoodie-in-a-dark-room image. The threats that drain money from a Pune manufacturing unit or a Bengaluru services firm are mundane and repeatable. Here are the four that account for almost everything I see.

1. Business Email Compromise (BEC) and invoice fraud

An attacker either spoofs a vendor's email or breaks into a real mailbox, then waits. When a genuine invoice discussion is happening, they slip in with "our bank account has changed, please update." Your accounts person, trying to be efficient, pays. This is the Surat story, and it's the most expensive category for SMBs precisely because it targets people, not machines.

2. Ransomware

Someone opens an attachment or clicks a link, malware encrypts every file on the network, and a demand appears. For a small firm, the loss isn't just the ransom. It's the three weeks of GST filings, Tally data, and customer records that vanish. Attackers now specifically hunt small businesses because they're soft targets who often pay quietly.

3. Phishing and OTP theft

Fake login pages for your bank, your GST portal, or your email. In India, WhatsApp-based OTP theft is rampant, "sir, I sent money by mistake, please share the OTP to reverse it." Your staff need to know that no legitimate entity ever asks for an OTP.

4. Weak or reused passwords

The owner uses the same password for email, banking, and the accounting software. It leaks in a breach of some unrelated website. Now the attacker has everything. This is depressingly common and completely preventable.

Why is email your biggest risk, and how do you lock it down?

If you do nothing else from this article, do this section. Email is the front door, the back door, and most of the windows. Locking it down properly closes off the majority of real-world attacks against Indian SMBs.

There are two layers to fix: your identity records (so nobody can impersonate your domain) and your accounts (so nobody can log in as you).

Set up SPF, DKIM, and DMARC on your domain

These three DNS records tell the world which servers are allowed to send email as your domain. Without them, anyone can forge messages that appear to come from [email protected]. With them properly configured, spoofed mail gets rejected or junked before it reaches anyone.

  1. SPF lists your authorised sending servers. If you use Google Workspace, it's a single TXT record you add to your domain's DNS.
  2. DKIM cryptographically signs your outgoing mail so recipients can verify it wasn't tampered with. Both Google and Microsoft generate this key for you.
  3. DMARC is the policy that ties them together and tells receiving servers what to do with mail that fails. Start with p=none to monitor, then move to p=quarantine and finally p=reject.

This costs nothing beyond an hour of a competent person's time. We cover the full mechanics in our guide to email security for Microsoft 365 and Google Workspace, and if you'd rather someone just do it correctly the first time, our IT consulting team sets these up regularly.

Common Mistake: Owners jump straight to p=reject on DMARC without monitoring first. If you have a billing system, a CRM, or a marketing tool that sends email on your behalf, you'll silently block your own legitimate mail. Run p=none for two to four weeks, read the reports, authorise every legitimate sender, then tighten the policy.

Turn on multi-factor authentication everywhere

MFA means a stolen password alone isn't enough to log in. It's free, it takes minutes per account, and it stops the overwhelming majority of account takeovers. Enable it on:

  • Every email account (mandatory for the owner and accounts team, ideally everyone)
  • Net banking and payment gateways
  • Tally, Zoho Books, or whatever accounting software you use
  • Your domain registrar and DNS provider (an attacker who controls your DNS controls everything)
  • WhatsApp Business and any social accounts

Use an authenticator app like Google Authenticator or Microsoft Authenticator rather than SMS OTP where possible, since SIM-swap fraud is real in India.

How much does baseline cybersecurity for Indian SMBs actually cost?

Owners assume security means a huge bill. It doesn't. A defensible baseline for a small firm is remarkably cheap, and much of it is configuration rather than product. Here's a realistic worked example.

The setup: A 20-person interior design firm in Gurugram. They run on a mix of personal Gmail accounts, a shared laptop for accounts, no backups, and free antivirus. Total security spend before: effectively ₹0, and total risk: enormous.

Here's what a sensible upgrade looked like, and what it cost per year:

Item What it does Annual cost (20 users)
Google Workspace Business Starter Professional email, MFA, admin controls, SPF/DKIM/DMARC support ~₹1,90,000 (₹136/user/month)
Password manager (Bitwarden Teams) Unique strong passwords for every account, secure sharing ~₹58,000
Endpoint protection (business-grade) Real antivirus + ransomware protection on laptops ~₹40,000
Cloud backup (Tally + documents) Automated, versioned backups you can restore after ransomware ~₹30,000
Staff awareness training (one session + refreshers) Teaches the team to spot phishing and invoice fraud ~₹25,000
Total ~₹3,43,000/year (~₹1,430/user/month)

That's the full package. If budget is tight, the top three rows (email, password manager, backups) deliver about 80% of the protection for under ₹1,500 per user per month. Compare that to a single ₹6.8 lakh wire fraud and the maths makes itself.

If you're choosing between platforms, our comparison of email hosting for Indian SMBs: Google Workspace vs Zoho breaks down the trade-offs, and we handle Google Workspace licensing and Microsoft 365 licensing directly, usually at better rates than buying retail.

What's the simplest way to survive ransomware?

Backups. That's the whole answer, but the details matter, because most SMBs that "have backups" don't actually have recoverable ones.

The rule I give every client is 3-2-1: three copies of your data, on two different types of media, with one copy offline or off-site. Ransomware today deliberately encrypts connected backup drives, so a USB disk plugged into the same machine is worthless the moment you get hit.

A practical backup plan for a small firm

  1. Identify what actually matters. Tally data, GST records, contracts, customer database, design files. You don't need to back up the whole Windows install, just the irreplaceable stuff.
  2. Automate a daily cloud backup. Google Drive, OneDrive, or a dedicated service. Automated, because "we'll remember to copy it" always fails.
  3. Keep versions. If ransomware encrypts a file and your backup only stores the latest version, you've backed up the encrypted junk. Versioned backups let you roll back to yesterday.
  4. Keep one copy offline. A weekly export to an external drive that you disconnect and store in a drawer. Cheap and effective.
  5. Test a restore. Once a quarter, actually restore a file and open it. An untested backup is just a hope.
Pro Tip: For firms running Tally on a local server, set up an automatic daily backup export to a cloud folder, then enable version history on that folder. I've watched a Nashik trading firm recover from full ransomware in under four hours because they had exactly this. Their competitor down the road paid the ransom and still lost two weeks.

If your data lives on ageing on-prem servers, moving the right workloads to managed cloud infrastructure removes a huge chunk of this headache. Our cloud migration and managed services team handles this for SMBs, and if you want to understand the landscape first, read the data centre boom in India and what it means for SMB cloud.

How do you stop invoice fraud and payment scams?

This is the category that costs the most and the one technology alone won't fully solve, because it targets human trust. You need process, not just software.

The rules that stop wire fraud

  • Verify every change of bank details by phone. Not by replying to the email (the attacker controls that inbox). Call a number you already have on file, not one in the email.
  • Require dual authorisation for payments above a threshold, say ₹50,000. Two people must approve. One compromised account can't move money alone.
  • Slow down on urgency. "Pay immediately or we lose the deal" is the oldest trick. Make it policy that urgent payment requests get extra verification, not less.
  • Watch the domain carefully. vendor-company.in vs vendorcompany.in. Train accounts staff to hover over the sender address every single time.

An hour spent drilling your accounts team on these four rules is genuinely the highest-return training you can buy. It would have saved my Surat friend ₹6.8 lakh.

What are your legal obligations under the DPDP Act?

Security stopped being optional in India the moment the Digital Personal Data Protection Act, 2023 came into force. If you hold personal data of customers, employees, or leads, and you do, you're now a "Data Fiduciary" with real obligations: collect only what you need, secure it with "reasonable security safeguards," and report breaches.

The penalties are serious, running up to ₹250 crore for major failures. Nobody expects a 20-person firm to face that, but the direction of travel is clear. Regulators and enterprise customers will increasingly ask what safeguards you have. For MSMEs bidding on larger contracts or GeM tenders, being able to say "we run MFA, encrypted email, backups, and staff training" is fast becoming a qualifier.

The practical read: the baseline setup in this article isn't just protection, it's your evidence of "reasonable safeguards." Document what you've done. If you need a structured review of where you stand, our IT consulting service runs affordable security assessments scaled for SMBs.

Your 30-day cybersecurity action plan

Don't try to do everything at once. Here's the order I'd run it in for a firm starting from zero.

  1. Week 1: Move everyone off personal email to a professional platform. Turn on MFA for the owner and accounts team first, then everyone. Change any reused passwords immediately.
  2. Week 2: Configure SPF, DKIM, and DMARC (start at p=none). Deploy a password manager and get staff to migrate their logins into it.
  3. Week 3: Set up automated, versioned cloud backups plus one offline copy. Install business-grade endpoint protection on all laptops. Test a restore.
  4. Week 4: Run a one-hour staff awareness session focused on phishing and invoice fraud. Write down your payment verification rules and make them policy. Tighten DMARC toward quarantine.

Four weeks, a few thousand rupees per person, and you've gone from soft target to a business that most opportunistic attackers will skip in favour of someone easier.

Frequently asked questions

What is the cheapest way to improve cybersecurity for a small business in India?

Turn on multi-factor authentication everywhere and use unique passwords via a password manager. Both are free or nearly free and block the majority of account takeovers. Add automated backups and you've covered the biggest risks for well under ₹1,500 per user per month.

Do small businesses in India really get targeted by hackers?

Yes, and more than large firms in raw numbers, because SMBs are softer targets. Most attacks aren't personal, they're automated or opportunistic, hitting anyone with weak email security or no backups. Invoice fraud in particular specifically hunts small trading and services firms.

Is antivirus enough to protect my company?

No. Antivirus is one layer, but it does nothing against phishing, email spoofing, or invoice fraud, which cause most SMB losses. You need email authentication, MFA, backups, and staff awareness alongside endpoint protection.

What should I do immediately if we get hit by ransomware?

Disconnect affected machines from the network right away to stop the spread, but don't wipe them. Don't pay the ransom before exploring restoration from clean backups. Contact your IT provider and report the incident to CERT-In. If you had versioned, offline backups, you can usually recover within hours.

Does the DPDP Act apply to small businesses?

Yes. If you process personal data of individuals, you have obligations regardless of company size, though certain provisions may be lighter for smaller entities once rules are fully notified. At minimum, implement reasonable security safeguards and be prepared to report breaches.

How do I stop scammers from spoofing my company's email?

Configure SPF, DKIM, and DMARC records on your domain. These tell receiving mail servers which sources are authorised to send as your domain and instruct them to reject forgeries. It's a one-time setup, costs nothing, and dramatically cuts impersonation.

Should I hire a full-time IT security person?

For most firms under 50 people, no. A well-configured baseline plus a managed service or consultant on call is far more cost-effective than a full-time hire. Revisit this once you're handling large volumes of sensitive data or have compliance obligations from enterprise clients.

Where to start

Good cybersecurity for Indian SMBs isn't about spending big or buying the scariest-sounding product. It's about closing the obvious doors: professional email with MFA, domain records that stop impersonation, versioned backups that survive ransomware, and an accounts team that knows not to trust a "changed bank details" email. Do those four things and you've eliminated most of the risk that actually bankrupts small businesses.

If you'd like help setting any of this up, from email and licensing to secure cloud migration and a proper security review, take a look at our full services overview or get in touch with the eDarpan team. We work with SMBs across India and price everything for real-world budgets, not enterprise ones. And if you're also thinking about the physical side of setting up or expanding, we handle virtual office addresses for GST and company registration too.

Start this week. Pick the first item on the 30-day plan and do it today. The Surat firm wishes they had.

Image credit: Innovate Maryland Emerging Technology Center by MDGovpics via flickr (BY 2.0), sourced through Openverse.

A

Written by

Amit Verma

Cloud architect specializing in AWS, Azure, and GCP infrastructure. Amit has designed multi-region deployments for Indian enterprises and writes about cloud migration, cost optimization, and DevOps best practices.

Looking for a technology partner?

From IT consulting to virtual office to custom software — eDarpan can help.