SMB Cybersecurity in India 2026: A No-Jargon Defense Plan
A no-jargon, practical roadmap to SMB cybersecurity in India for 2026, with real rupee costs, vendor names, and the controls that stop 90% of attacks.

Last October, a friend who runs a 40-person auto-parts distributor in Ludhiana called me on a Sunday morning. His accounts team couldn't open Tally. Every file on the shared drive had a weird extension and a text file demanding 2 Bitcoin. He'd never heard the word "ransomware" until that day. By Monday afternoon he'd lost three years of GST invoices, and the "IT guy" who managed his network on the side had stopped answering calls.
This is not a rare story anymore. India is now among the most-targeted countries for ransomware, and small and mid-size businesses are the softest targets because they run on trust, thin budgets, and the belief that "we're too small to be hacked." Attackers don't think that way. They run automated scans that don't care whether you're a bank in Mumbai or a tuition centre in Coimbatore. If your remote desktop port is open or your staff clicks a fake GST refund email, you're in the pool.
This post is a practical roadmap for SMB cybersecurity in India for 2026. No frameworks you'll never read, no fear-selling. Just the specific controls that stop 90% of real attacks, with rupee costs, vendor names, and a plan you can hand to your team or your vendor this week.
Key Takeaways
- Most SMB breaches in India start with two things: a phished email and a reused password. Fix those first and cheaply.
- Turn on multi-factor authentication (MFA) everywhere. It's free with Google Workspace and Microsoft 365, and it blocks the vast majority of account takeovers.
- A real, tested backup (3-2-1 rule) is the single control that turns a ransomware disaster into a bad afternoon.
- CERT-In rules now require you to report serious incidents within 6 hours and keep logs for 180 days. This is a legal obligation, not optional.
- A solid baseline for a 25–50 person firm costs roughly ₹1,500–₹2,500 per employee per year. Cheaper than one day of downtime.
- Write a one-page incident response plan before you need it. Panic is expensive.
Why are Indian SMBs suddenly such a big target?
Two reasons, and both come down to economics. First, large enterprises have spent the last decade hardening their systems, hiring security teams, and buying expensive tools. SMBs largely haven't. Attackers follow the path of least resistance, and that path now runs through the 63 million-plus MSMEs in India.
Second, ransomware is now a service. Criminal groups rent out ready-made attack kits. The person hitting your business may not even be technical. They buy access, deploy the tool, and split the ransom. Because the effort per target is so low, they can afford to hit hundreds of small firms hoping a few pay ₹5–15 lakh each.
The damage isn't just the ransom. It's the four days your billing stops, the customer data you have to notify people about, the GST filing you miss, and the reputation hit when a client's data leaks. For most SMBs, downtime and lost trust cost far more than the ransom demand itself.
The three attacks you'll actually face
- Phishing — fake emails pretending to be your bank, GST portal, a vendor, or your own boss asking for an urgent transfer. This is the entry point for most breaches.
- Ransomware — malware that encrypts your files and demands payment. Usually enters through phishing or an exposed remote-access port.
- Business email compromise (BEC) — an attacker gets into (or convincingly imitates) an email account and redirects a real payment to their bank. I've seen a Pune manufacturer lose ₹22 lakh this way on a single supplier invoice.
What's the cheapest security that actually stops attacks?
Here's the uncomfortable truth: the most effective controls are also the cheapest. Businesses waste money on fancy firewalls while leaving the front door open. Start with the basics, in this order.
1. Multi-factor authentication on everything
If you do one thing this month, do this. MFA means even if someone steals a password, they still can't log in without the second factor (a code on the phone). Microsoft's own data shows MFA blocks over 99% of automated account attacks.
It's already included in Google Workspace and Microsoft 365. Turn it on for email, banking, accounting software, and your cloud console. Use an authenticator app (Google Authenticator, Microsoft Authenticator) rather than SMS where you can, because SIM-swap attacks are real in India.
Common mistake: Turning on MFA for the admin account but not for the accounts team. The people who touch money and invoices are the exact ones attackers target. MFA needs to be mandatory for everyone, enforced by policy, not left as an option employees can skip.
2. Email protection and staff awareness
Email is the battlefield. Configure SPF, DKIM, and DMARC records on your domain so attackers can't easily spoof your company address. Both major platforms have built-in phishing filters; turn on the advanced ones. If you're on Microsoft, Defender for Office 365 adds a strong layer for a small per-user fee.
We've written a full guide on this in our post on email security for Microsoft 365 and Google Workspace in India, worth reading before you configure anything.
Then train your people. Not a boring annual video. Run a fake phishing test, see who clicks, and coach them privately. Repeat quarterly. Humans are your firewall and they respond to practice, not lectures.
3. Backups you have actually tested
Follow the 3-2-1 rule: three copies of your data, on two different types of media, with one copy off-site and disconnected. Ransomware often encrypts connected backups too, so an offline or immutable cloud copy is non-negotiable.
For a Tally-and-files SMB, that might be: live data on the server, a daily backup to a NAS, and an encrypted nightly copy to cloud storage with versioning turned on. Test a restore every quarter. A backup you've never restored is a hope, not a plan.
How much should an Indian SMB budget for cybersecurity?
Let me give you real numbers instead of vague ranges. Here's a comparison of three defense tiers for a typical 30-person firm, based on deployments I've done.
| Control | Basic (survival) | Standard (recommended) | Advanced (regulated/data-heavy) |
|---|---|---|---|
| Email & identity | Google Workspace Business Starter + MFA (~₹150/user/mo) | Microsoft 365 Business Premium (~₹1,800/user/mo) | M365 Business Premium + Defender add-ons |
| Endpoint protection | Built-in Defender / free AV | Managed EDR (~₹300–500/device/mo) | 24/7 managed EDR + response |
| Backup | NAS + cloud storage (~₹5,000/mo) | Immutable cloud backup with versioning | Backup + disaster recovery site |
| Firewall / network | ISP router with WPA3 | Business firewall (Sophos/Fortinet) ~₹40–80K one-time | Firewall + segmented VLANs + VPN |
| Staff training | DIY phishing awareness | Quarterly simulated phishing | Monthly training + compliance audits |
| Approx annual cost (30 staff) | ₹1.2–1.8 lakh | ₹8–12 lakh | ₹18–30 lakh |
Most SMBs should aim for the Standard column. It maps to roughly ₹1,500–₹2,500 per employee per year once you spread out the one-time costs. Compare that to a single ransomware incident, which easily runs into several lakhs in ransom, recovery, lost billing, and consultant fees. The maths is not close.
What does a real SMB security rollout look like? (A case study)
Let me walk through an actual engagement, with details changed to protect the client. A 35-person textile exporter in Surat came to us after a near-miss: an employee had entered credentials into a fake "M365 login" page, and the attacker started sending invoices to the client's buyers. They caught it because a German buyer phoned to confirm a strange bank-change request.
Here's what we did over six weeks, and roughly what it cost.
- Week 1 — Lock the doors. Forced password resets for all staff, enforced MFA across every account, and revoked the sessions the attacker had. Cost: staff time, effectively zero.
- Week 1 — Fix email trust. Configured SPF, DKIM, and DMARC (set to
quarantine, laterreject) so spoofed mail from their domain would be blocked. This directly stopped the impersonation attacks. - Week 2 — Upgrade licensing. Moved them from a basic plan to Microsoft 365 Business Premium so they got Defender, device management, and conditional access. Cost: roughly ₹1,800/user/month, about ₹63,000/month for the team.
- Week 3 — Backups. Set up immutable cloud backup with 30-day versioning for their file server and email. Tested a full restore. Cost: about ₹9,000/month.
- Week 4 — Endpoints and network. Deployed managed EDR on all laptops and a Sophos firewall, closed the exposed remote-desktop port, and put remote access behind a VPN. Firewall: ₹55,000 one-time.
- Week 5 — People. Ran a simulated phishing campaign. Nine of 35 clicked. We coached them and set a rule that any bank-detail change on an invoice must be confirmed by phone using a number already on file, never the number in the email.
- Week 6 — The plan. Wrote a one-page incident response plan with names, phone numbers, and first steps, and pinned it up.
Total: about ₹75,000 in one-time costs and roughly ₹72,000/month ongoing. The next quarter, a repeat phishing test saw only two clicks, and both reported it rather than entering credentials. That's what "working" looks like. If you want help scoping something similar, our IT consulting team does exactly this kind of assessment and rollout.
What does Indian law actually require you to do?
This is where a lot of SMBs are unknowingly exposed. Compliance isn't just for big companies anymore.
CERT-In directions
Under the 2022 CERT-In directions, all organisations, including SMBs, must:
- Report specified cyber incidents (including ransomware and data breaches) to CERT-In within 6 hours of noticing them.
- Maintain system logs for a rolling period of 180 days within India.
- Sync all system clocks to NPL or NIC time servers.
That 6-hour window is tight. You cannot meet it if you don't already know who reports, what the CERT-In contact channel is, and where your logs live. Build that into your plan now.
The DPDP Act
India's Digital Personal Data Protection Act adds obligations around how you handle customer personal data, including breach notification. If you store customer names, phone numbers, and payment details, and almost every SMB does, this applies to you. The practical takeaway: know what personal data you hold, where it sits, and who can access it.
Data localisation
If you're in fintech, lending, or payments, RBI's rules on where data is stored matter a great deal. We cover the specifics in our guide on cloud data localization in India and what RBI and CERT-In require. Choosing an India-region cloud isn't just about latency anymore. There's a strong case for keeping workloads in-country, which we explored in how West Asia cloud workloads are shifting to India.
How do I secure my cloud and remote setup without a big team?
Most SMBs now run on some mix of cloud apps, cloud storage, and remote or hybrid staff. That's good for flexibility but it widens your attack surface if configured carelessly. The good news is you can lock it down without hiring a security engineer.
Cloud configuration checklist
- Turn off any storage bucket or drive folder set to "public" or "anyone with the link" unless it truly must be public. Misconfigured cloud storage leaks are a top cause of Indian data exposure.
- Use least privilege. The intern doesn't need admin. Give people access to only what their role needs, and review it every quarter.
- Enable audit logging on your cloud console so you can see who did what. This also helps meet the CERT-In 180-day log rule.
- Set up conditional access so logins from unusual locations or unmanaged devices get blocked or challenged.
- For any server exposed to the internet, close unused ports and never leave remote desktop (RDP) open to the world. Put it behind a VPN.
If your infrastructure has grown messily over the years, a clean migration to a properly configured cloud setup is often cheaper and safer than patching the old one. Our cloud migration and managed services team handles this end to end, and we've built custom software for clients where off-the-shelf tools couldn't enforce the access controls they needed. For a broader view of what we offer, see our full services overview.
Pro tip: Set up a dedicated, boring email account for domain and cloud administration, something like [email protected], protected with a hardware security key. Don't use a personal account or the founder's day-to-day email as the master admin. When a founder leaves or their phone is lost, you don't want your entire company's cloud access tied to it.
What should I do the moment I think we've been breached?
Keep a one-page plan printed and pinned near the servers, because if your systems are encrypted, you can't open a plan stored on them. Here's the skeleton every SMB should have.
- Isolate. Disconnect affected machines from the network and Wi-Fi. Don't shut them down; that can destroy forensic evidence.
- Don't pay yet, don't panic. Paying rarely gets clean data back and marks you as a payer for future attacks.
- Call your responder. Have a security partner's number ready. Every hour of guessing makes it worse.
- Report to CERT-In within 6 hours. This is a legal requirement. Know the channel in advance.
- Preserve evidence. Screenshot ransom notes, note timestamps, keep logs.
- Restore from backup. This is why you tested those backups. Rebuild clean, then restore.
- Notify affected parties. Under DPDP obligations, you may need to inform customers whose data was exposed.
Write down real names and phone numbers next to each step. When it's 2am and billing is down, you don't want to be searching for who to call.
Frequently asked questions
How much does cybersecurity cost for a small business in India?
For a well-protected setup, budget roughly ₹1,500 to ₹2,500 per employee per year. A 30-person firm on the recommended tier typically spends ₹8–12 lakh annually including licensing, backups, endpoint protection, and a firewall. The basics like MFA and backups cost far less and stop most attacks.
Is antivirus enough to protect my company from ransomware?
No. Traditional antivirus catches known malware but misses phishing, credential theft, and new ransomware variants. You need layered defence: MFA, email filtering, tested backups, and modern endpoint detection (EDR). Antivirus alone is a 2010-era answer to a 2026 problem.
What is the CERT-In 6-hour reporting rule?
CERT-In's 2022 directions require Indian organisations to report specified cyber incidents, including ransomware and data breaches, within six hours of becoming aware of them. You must also keep logs for 180 days within India. Failure to comply can carry penalties, so build reporting into your incident plan.
Should I use Google Workspace or Microsoft 365 for better security?
Both are secure when configured properly. Google Workspace is simpler and cheaper for smaller teams, while Microsoft 365 Business Premium bundles powerful security tools like Defender and device management that suit growing or regulated firms. The right choice depends on your apps and budget, which we help clients evaluate.
How do I protect my business from fake invoice and payment fraud?
Set a firm rule that any change to a supplier's bank details must be verified by calling a phone number you already have on file, never the number in the email. Enforce MFA on all email accounts and configure DMARC to block spoofed messages from your domain. Most business email compromise losses come from skipping that one verification call.
Do small businesses really need to worry about the DPDP Act?
Yes. If you hold customer personal data such as names, phone numbers, or payment information, the DPDP Act applies regardless of your size. You should know what data you hold, limit who can access it, and have a process to notify people if it's breached.
Can I outsource cybersecurity instead of hiring in-house?
For most SMBs, yes, and it's usually more cost-effective. A managed service partner handles monitoring, patching, backups, and response for a predictable monthly fee, which is far cheaper than a full-time security hire. This is exactly the kind of managed support eDarpan provides.
Where to start this week
You don't need a big budget or a security team to be dramatically safer than you are today. Turn on MFA everywhere, test your backups, fix your email records, and write that one-page incident plan. Those four moves alone put you ahead of most Indian SMBs and stop the attacks that actually happen.
Getting SMB cybersecurity in India right is less about buying expensive gear and more about closing the obvious gaps that attackers exploit every day. If you'd like a straight assessment of where your business stands, without jargon or scare tactics, get in touch with eDarpan or read more about how we work with Indian businesses. Fix the basics first. Everything else builds on that.
Image credit: Innovate Maryland Emerging Technology Center by MDGovpics via flickr (BY 2.0), sourced through Openverse.
Written by
Amit Verma
Cloud architect specializing in AWS, Azure, and GCP infrastructure. Amit has designed multi-region deployments for Indian enterprises and writes about cloud migration, cost optimization, and DevOps best practices.
Looking for a technology partner?
From IT consulting to virtual office to custom software — eDarpan can help.
Continue reading

West Asia Cloud Workloads Shift to India: What SMBs Gain
West Asia cloud workloads are shifting to Indian regions, cutting latency and costs for SMBs. Here's what the change means for your business in 2026.

CRM for Indian SMBs: Build vs Buy vs Zoho/Salesforce 2026
Should Indian SMBs buy Zoho/Salesforce or build a custom CRM? Real rupee costs, WhatsApp integration, and a worked example to help you decide in 2026.

Data Centre Boom in India: Green Cloud Choices for SMBs
India's data centre boom meets a coal-heavy grid. Learn how SMBs can pick low-carbon cloud regions, cut costs, and meet buyer sustainability demands.