Skip to main content
A Rigorous Business Assessment & Advisory Platform for High-Growth Markets

Cybersecurity Guide for SMEs

Cybersecurity Assessment India —
DPDP Act, CERT-In and SME Security Gaps

The DPDP Act 2023 (₹250Cr penalties), CERT-In 6-hour breach reporting, and supply chain security requirements are making cybersecurity non-optional for Indian SMEs. This guide covers the 6 security domains, the most common Indian SME vulnerabilities, and what a structured assessment involves.

₹250Cr

Max DPDP Act penalty for data breach

6 hours

CERT-In breach reporting window

6

Security domains assessed

Need Expert Help?

Talk to an IBEAN specialist about applying these insights to your business — personalised advisory, not just information.

WhatsApp Us

Direct line to our advisory team

Fixed-fee diagnostic first. No commitment required.

6 Assessment Domains

What an SME Cybersecurity Assessment Covers

Access Control & Identity

Password policies, MFA enforcement, privileged access management, employee offboarding procedures

Risk: Compromised credentials are the #1 entry point for breaches — 80% of breaches involve weak or stolen passwords

Benchmark: MFA on all cloud accounts. Zero shared passwords. Offboarding checklist completed within 24 hours.

Endpoint Security

Antivirus/EDR coverage, patch management, BYOD policy, remote work device security

Risk: Unpatched endpoints and personal devices accessing business systems are the most common SME vulnerability

Benchmark: All devices enrolled in MDM. Patches applied within 7 days of release. BYOD policy with company data containerisation.

Cloud & SaaS Security

Cloud configuration audit (AWS/Azure/GCP), SaaS app inventory, data sharing permissions, shadow IT

Risk: Misconfigured S3 buckets and overpermissioned SaaS apps leak sensitive data without any attacker action required

Benchmark: Cloud security posture management (CSPM) tool in place. SaaS app inventory with owner assigned.

Data Protection & Backup

Data classification, encryption at rest and in transit, backup frequency, recovery time objective (RTO)

Risk: Ransomware encrypts business data; without verified backups, recovery requires paying the ransom

Benchmark: 3-2-1 backup rule (3 copies, 2 media types, 1 offsite). Monthly backup recovery test. RTO < 4 hours for critical systems.

DPDP Act 2023 Compliance

Personal data inventory, consent mechanisms, data principal rights process, data processor agreements

Risk: India's Digital Personal Data Protection Act 2023 — penalties up to ₹250 crore for data breaches involving personal data

Benchmark: Data inventory complete. Privacy policy updated for DPDP. Consent mechanism implemented for data collection.

Incident Response Readiness

Incident response plan, CERT-In 6-hour breach reporting compliance, contact list, tabletop exercise history

Risk: CERT-In mandates breach reporting within 6 hours — most Indian SMEs have no incident response plan and would miss this deadline

Benchmark: Documented IRP. CERT-In reporting process tested. Annual tabletop exercise conducted.

Most Common Gaps

6 Cybersecurity Vulnerabilities Most Common in Indian SMEs

VulnerabilityPrevalenceConsequence
No MFA on Microsoft 365 / Google Workspace68% of Indian SMEsSingle compromised password = full email access, potential BEC (Business Email Compromise) fraud
Employees using personal Gmail/WhatsApp for business data74% of Indian SMEsUncontrolled data leakage; company data persists on personal devices after employment ends
No regular patch management process61% of Indian SMEsUnpatched vulnerabilities exploited by automated attack tools; ransomware entry point
Cloud storage publicly accessible (misconfigured)43% of SMEs using cloudCustomer PII, contracts, financial data exposed to anyone on the internet — DPDP Act liability
No documented incident response plan81% of Indian SMEsCERT-In non-compliance (6-hour reporting obligation); chaotic breach response that amplifies damage
Shared admin passwords for critical systems55% of Indian SMEsNo audit trail; impossible to detect insider threat or attribute breach to specific access

Frequently Asked Questions

Cybersecurity Assessment — Common Questions

Frequently Asked Questions

Cybersecurity Assessment — Common Questions

7 Questions
help_outline

Additional questions? Contact the advisory team

Know Your Cybersecurity Gaps Before a Regulator or Attacker Does

IBEAN's Cybersecurity Assessment identifies your critical vulnerabilities, DPDP Act compliance gaps, and CERT-In readiness — with a 90-day remediation roadmap.