Indian Businesses Increase Cybersecurity Spending to Counter Rising Online Threats
Indian small and medium-sized enterprises are increasing investments in cybersecurity measures as the frequency of cyber incidents rises, despite persistent challenges in monitoring, internal expertise, and employee awareness that leave many organizations vulnerable.
Rising Cyber Threats in the Asia-Pacific
A significant portion of SMEs report experiencing cyberattacks within the past two years, with surveys indicating that 87% of Indian SMEs faced at least one security incident in the previous year. The Asia-Pacific region has seen similar trends, with phishing, exploitation of software vulnerabilities, and widespread malware attacks emerging as the most prevalent threats.
Challenges Faced by SMEs
Smaller businesses encounter many of the same risks as larger corporations but often lack the resources and specialized security knowledge to address them effectively. The survey, which included IT security professionals from 15 countries, revealed that organizations in the region experienced an average of three distinct security incidents annually.
Software vulnerability exploitation accounted for 20% of reported incidents, followed by phishing at 19% and mass malware attacks at 18%. Zero-day exploits were identified in 6% of cases.
Increased Budget Allocations for Cybersecurity
India’s SMEs reported an 87% incident rate, with Vietnam leading the region at 97%, followed by Malaysia at 95%, Indonesia at 92%, and Thailand at 88%. The surge in cyber incidents is driving increased budget allocations for cybersecurity. Approximately 84% of Indian SMEs plan to boost their cybersecurity expenditures over the next 12 to 24 months.
Focus on Technology and Human Expertise
This shift aims to address growing exposure to online threats, expand digital infrastructure, and support employees operating across diverse environments. However, the expansion of budgets does not necessarily translate to enhanced continuous monitoring of security environments. Only 12% of SMEs maintain ongoing cybersecurity surveillance.
A majority of SMEs are directing additional funds toward cybersecurity initiatives, with 78% of Asia-Pacific businesses planning to allocate more resources this year. Nearly half (48%) intend to invest in IT and security teams, while 32% plan to adopt advanced solutions such as extended detection and response (XDR), network detection and response (NDR), and security information and event management (SIEM) systems.
Key Challenges and Vulnerabilities
A critical challenge remains the shortage of skilled cybersecurity professionals. Around 45% of Indian SMEs cite a lack of in-house expertise as their primary obstacle. This issue extends beyond specialized security teams, as 26% of surveyed SMEs note that non-IT employees lack sufficient cybersecurity awareness, increasing the risk of successful attacks.
Employee Behavior and System Risks
Additionally, 24% point to inadequate skills among IT security staff. Other vulnerabilities include outdated systems, fragmented monitoring capabilities, irregular risk assessments, and the absence of essential security solutions. Employee behavior also contributes to cybersecurity risks. Staff handling emails, documents, passwords, and company systems can inadvertently introduce threats if proper protocols are not followed.
The Role of Artificial Intelligence
Businesses are advised to implement clear cybersecurity policies, including restrictions on software installations and guidelines for password management. The findings underscore that improving security requires more than purchasing tools; it demands robust monitoring, regular assessments, trained personnel, and adequate expertise to detect and mitigate threats.
Artificial intelligence is emerging as both a defensive tool and a potential risk. While 35% of Indian SMEs view AI as a means to enhance cybersecurity, 34% anticipate AI-driven threats impacting their operations. This dual role presents a complex challenge, as the same technology that strengthens defenses can also be weaponized by attackers to escalate the scale or sophistication of cyberattacks.
Conclusion
Despite increased spending, gaps in cybersecurity remain. Continuous monitoring, skilled personnel, employee awareness, and comprehensive visibility into digital systems are essential for improving preparedness. As AI-powered threats evolve alongside traditional attacks like phishing and malware, organizations must balance technological advancements with human-centric security strategies.
