Cybersecurity Guide for SMEs
Cybersecurity Assessment India —
DPDP Act, CERT-In and SME Security Gaps
The DPDP Act 2023 (₹250Cr penalties), CERT-In 6-hour breach reporting, and supply chain security requirements are making cybersecurity non-optional for Indian SMEs. This guide covers the 6 security domains, the most common Indian SME vulnerabilities, and what a structured assessment involves.
₹250Cr
Max DPDP Act penalty for data breach
6 hours
CERT-In breach reporting window
6
Security domains assessed
Talk to an IBEAN specialist about applying these insights to your business — personalised advisory, not just information.
WhatsApp Us
Direct line to our advisory team
Fixed-fee diagnostic first. No commitment required.
6 Assessment Domains
What an SME Cybersecurity Assessment Covers
Access Control & Identity
Password policies, MFA enforcement, privileged access management, employee offboarding procedures
Risk: Compromised credentials are the #1 entry point for breaches — 80% of breaches involve weak or stolen passwords
Benchmark: MFA on all cloud accounts. Zero shared passwords. Offboarding checklist completed within 24 hours.
Endpoint Security
Antivirus/EDR coverage, patch management, BYOD policy, remote work device security
Risk: Unpatched endpoints and personal devices accessing business systems are the most common SME vulnerability
Benchmark: All devices enrolled in MDM. Patches applied within 7 days of release. BYOD policy with company data containerisation.
Cloud & SaaS Security
Cloud configuration audit (AWS/Azure/GCP), SaaS app inventory, data sharing permissions, shadow IT
Risk: Misconfigured S3 buckets and overpermissioned SaaS apps leak sensitive data without any attacker action required
Benchmark: Cloud security posture management (CSPM) tool in place. SaaS app inventory with owner assigned.
Data Protection & Backup
Data classification, encryption at rest and in transit, backup frequency, recovery time objective (RTO)
Risk: Ransomware encrypts business data; without verified backups, recovery requires paying the ransom
Benchmark: 3-2-1 backup rule (3 copies, 2 media types, 1 offsite). Monthly backup recovery test. RTO < 4 hours for critical systems.
DPDP Act 2023 Compliance
Personal data inventory, consent mechanisms, data principal rights process, data processor agreements
Risk: India's Digital Personal Data Protection Act 2023 — penalties up to ₹250 crore for data breaches involving personal data
Benchmark: Data inventory complete. Privacy policy updated for DPDP. Consent mechanism implemented for data collection.
Incident Response Readiness
Incident response plan, CERT-In 6-hour breach reporting compliance, contact list, tabletop exercise history
Risk: CERT-In mandates breach reporting within 6 hours — most Indian SMEs have no incident response plan and would miss this deadline
Benchmark: Documented IRP. CERT-In reporting process tested. Annual tabletop exercise conducted.
Most Common Gaps
6 Cybersecurity Vulnerabilities Most Common in Indian SMEs
| Vulnerability | Prevalence | Consequence |
|---|---|---|
| No MFA on Microsoft 365 / Google Workspace | 68% of Indian SMEs | Single compromised password = full email access, potential BEC (Business Email Compromise) fraud |
| Employees using personal Gmail/WhatsApp for business data | 74% of Indian SMEs | Uncontrolled data leakage; company data persists on personal devices after employment ends |
| No regular patch management process | 61% of Indian SMEs | Unpatched vulnerabilities exploited by automated attack tools; ransomware entry point |
| Cloud storage publicly accessible (misconfigured) | 43% of SMEs using cloud | Customer PII, contracts, financial data exposed to anyone on the internet — DPDP Act liability |
| No documented incident response plan | 81% of Indian SMEs | CERT-In non-compliance (6-hour reporting obligation); chaotic breach response that amplifies damage |
| Shared admin passwords for critical systems | 55% of Indian SMEs | No audit trail; impossible to detect insider threat or attribute breach to specific access |
Frequently Asked Questions
Cybersecurity Assessment — Common Questions
Cybersecurity Assessment — Common Questions
Additional questions? Contact the advisory team
Know Your Cybersecurity Gaps Before a Regulator or Attacker Does
IBEAN's Cybersecurity Assessment identifies your critical vulnerabilities, DPDP Act compliance gaps, and CERT-In readiness — with a 90-day remediation roadmap.