Data privacy is no longer optional paperwork. India's DPDP Act is enforceable, and the EU's GDPR has issued fines that can close a company. If you collect user data, this applies to you.
The Anatomy of a Typical Breach
Most breaches we're called in to investigate follow a depressingly predictable pattern. Someone gets a phishing email, clicks a link, enters their credentials. The attacker logs into an account that didn't have MFA, finds a file share or database, exfiltrates data, encrypts or extorts. Six to eight weeks of silent access, on average, before anyone notices.
The controls that would have stopped this at any step are not complicated. MFA on every account. Phishing training twice a year. Monitoring on sensitive systems. A backup that's actually tested. None of these are enterprise-grade investments.
If You Are Hit: The First Hours Matter
The first hours of a security incident are decisive. Disconnect affected systems from the network but don't power them off (forensics depends on memory). Take a snapshot. Notify your incident response partner if you have one, or call immediately if you don't. Reset all credentials assuming full compromise. Notify regulators within the required window, which in India can be as short as six hours for CERT-In.
Do not pay a ransom without professional advice. Ransoms fund future attacks and, more practically, often don't deliver working decryption. The legal and insurance implications of payment are also getting more complicated each year.
Why This Isn't Someone Else's Problem
The number of times we've seen businesses assume cybersecurity is for bigger companies is, frankly, embarrassing. The math doesn't work that way. Attackers scan every IPv4 address on the internet, find something exploitable, and automate their way in. Your size doesn't protect you.
What protects you is a baseline of controls that automated attacks can't easily bypass. None of those controls are expensive or exotic. They're just work that doesn't feel urgent until the day it is.
Compliance vs Actual Security
There's a quiet tension in this field between compliance and security. Compliance is what the auditor checks. Security is what actually stops attackers. They overlap meaningfully but they're not the same thing, and treating them as identical leads to the worst of both worlds.
The pattern we see at well-run security programmes: treat compliance as a baseline that gets done competently and without drama, then spend the real attention on actual risk reduction. The compliance paperwork matters because it has to happen. The substance of what's underneath matters because attackers don't care about your audit report. Related read: our post on OWASP Top 10 covers the flip side of this.
Training Isn't Optional
Technical controls are half the battle. The other half is human behaviour. Running simulated phishing campaigns quarterly, walking through real recent incidents with your team, and making it easy to report suspicious messages without punishment — those things are measurably effective.
The training has to be short, relevant, and repeated. A 45-minute annual compliance video doesn't change behaviour. A 10-minute monthly check-in with a real example does.
What Actually Works at an SMB Budget
A reasonable baseline for a small to mid-sized business: Cloudflare's free tier in front of web properties, MFA enforced everywhere via a password manager, endpoint protection from Microsoft or CrowdStrike, tested off-site backups, and a written incident response plan. Total annual cost for a 50-person business is usually under Rs 5 lakh, often well under.
That investment dramatically reduces your exposure to automated attacks, which are roughly 90% of what you'll actually face. Targeted nation-state attacks are a separate problem and usually not your problem.
The Human Element, Honestly
Technical controls solve a big chunk of the problem. The rest is people. Employees click links, reuse passwords, share credentials in Slack, leave laptops in cars, and occasionally try to help attackers who've called pretending to be the CEO. Every one of these has been the root cause of a breach we've seen.
Training helps but it has a ceiling. The most effective controls combine training with architecture: MFA makes stolen passwords less dangerous, EDR catches malicious activity regardless of how it got in, segmentation limits what a single compromised account can reach. Design the system to survive human mistakes, because the mistakes will happen.
The Threat Landscape in 2026
The threat landscape has shifted in specific ways worth naming. Ransomware has become more targeted and more patient — attackers dwelling for weeks inside networks before encrypting, specifically to maximise damage and negotiating leverage. AI-assisted phishing has raised the floor of attack quality substantially; the obviously-broken English phishing emails of five years ago are largely gone.
On the defence side, tooling has also improved. Modern EDR products genuinely catch more than they used to. Managed SOC services are accessible at price points SMBs can afford. The gap between what's achievable in security and what most businesses implement has widened, which is frustrating because the tools to close it exist.
The regulatory environment has also tightened meaningfully. DPDP enforcement in India is becoming real. The EU's NIS2 and DORA regulations are producing compliance demands that flow down to vendors. Being serious about security is increasingly a market access requirement, not just a risk reduction investment.
Misconceptions That Keep Businesses Vulnerable
One: 'we're too small to be a target'. Demonstrably false. Automated attackers don't care about your size — they scan everyone. Ignoring security because you're small is exactly the reasoning attackers count on.
Two: 'we haven't been hacked, so our current security must be working'. Possibly. Or you've been hacked and just don't know yet. The average time between breach and detection is months. Absence of evidence isn't evidence of absence in this domain.
Three: 'security is too expensive'. Compared to what it costs to recover from a serious incident, it's cheap. Basic security controls for a 50-person business cost less than a single ransomware recovery effort.
A Close Call We Witnessed
A mid-sized client in the manufacturing sector almost got hit by a ransomware incident in late 2025. The initial access was a targeted phishing email to their finance head that mimicked a genuine vendor. Credentials got harvested. The attackers spent about three weeks mapping internal systems quietly before anyone noticed.
What saved them was a thing they'd grumbled about installing six months earlier: a proper EDR solution on every endpoint, with a managed SOC watching alerts. The anomalous behaviour — unusual PowerShell execution from the finance head's machine at 2am — triggered a response within an hour. Containment happened before encryption started.
The investment that "seemed expensive" six months before paid for itself a hundred times over that one night. We talk about this story in every security audit discussion now. The controls that feel optional in peacetime are the only thing standing between you and a very bad quarter.
The Short Checklist
If you take nothing else from this post, take this checklist. It's what we'd hand to someone just starting out in this area. None of it is revolutionary. All of it is worth doing. The compound effect of consistently doing these things, even without any other clever moves, is meaningful over a year or two. We'd rather see a team do the checklist competently than chase the latest trend while skipping the fundamentals.
- Turn on MFA for every account, no exceptions. Including the CEO.
- Run phishing simulations quarterly. Don't punish failures. Coach them.
- Test your backups by actually restoring something at least twice a year.
- Keep a written incident response plan. Review it annually.
- Monitor privileged accounts more closely than regular ones.
- Know your legal notification obligations (CERT-In, DPDP, sector regulators) before you need them.
- Run tabletop exercises for incident response annually. The plan you've never rehearsed probably won't work.
- Keep an asset inventory up to date. Assets you don't know about are assets you can't protect.
- Rotate high-privilege credentials quarterly. Long-lived admin credentials are a risk.
- Audit user access quarterly. People change roles; old access rarely gets revoked automatically.
The main thing we'd say after all of this: take it seriously, but don't overthink it. Most of the big wins come from executing the basics well, not from finding the one clever trick nobody else knows. Start small, measure what happens, iterate based on what you learn. If you do that consistently for twelve months, you'll be in a materially better place than you are today. The difference between most successful and most struggling teams is rarely about intelligence or strategy — it's about whether they kept the discipline long enough for compound improvement to kick in. We've been through enough cycles of this to be confident saying it. The patient teams win.
Thanks for reading all the way to the end. If this was useful, the next most useful thing is usually to pick one concrete action from it and actually do it this week. Insight without action is just entertainment, and we suspect you've got better things to do than be entertained by a technology blog.
Frequently Asked Questions
Does DPDP apply to small businesses in India?
Yes, largely. There's no blanket size exemption. Some provisions have reduced obligations for 'small data fiduciaries' as defined by rules, but the core requirements (lawful basis, consent, data subject rights, breach notification) apply broadly. Check the current implementation rules for specific exemptions.
Do I need a Data Protection Officer?
Required if you're a 'Significant Data Fiduciary' under DPDP or a large processor under GDPR. Recommended for any business handling substantial volumes of sensitive data. For smaller organisations, a senior role with privacy responsibilities (often the CTO or COO) can perform the DPO function.
Can I store Indian user data outside India?
Generally yes under DPDP, except for specific categories that the government may notify as requiring localisation. Sector-specific rules (RBI for financial data, healthcare-specific rules) may impose stricter localisation requirements than the base DPDP. Always check your specific sector's rules.
What's the penalty for getting privacy compliance wrong?
Under DPDP, up to Rs 250 crore per instance. Under GDPR, up to 4% of global annual revenue or €20 million, whichever is higher. Beyond fines, reputational damage and business interruption during incident response often dwarf the legal penalty. The investment in compliance is usually small relative to the downside risk.
Need help with your project?
Orange Essence Technologies builds e-commerce, software, mobile apps and AI solutions for clients across India and around the world. If any of this is relevant to what you're working on, we'd love to chat.
Get in touch →