India Faces the Highest Weekly Attack Volume of Any Country on Earth. Most Organisations Have No Security Operations Capability to Match It

The IBM Cost of a Data Breach Report 2026 contains a data point that deserves far more attention in Indian boardrooms than it has received. India faces 3,195 average weekly cyberattacks per organisation. That is the highest figure of any country included in the global research. The next highest is Brazil at 2,780. The United Kingdom sits at 1,560. The United States at 1,920.

The contrast with breach cost is instructive. The average cost of a data breach in India is 2.51 million US dollars per incident. In the United States the equivalent figure is 10.22 million dollars. In Australia it is 4.65 million. The 2.51 million dollar figure for India is not evidence that Indian organisations manage breaches more effectively. It reflects a regulatory and legal environment where the financial consequences of a breach have historically been far lower than in comparable economies. The DPDP Act is in the process of changing that, but active enforcement only began in late 2025 and the full penalty structure will not be operationally tested until a major enforcement action concludes.

India in the Global Attack Volume Context

The chart below places India’s weekly attack volume in international context alongside average breach costs. The pattern it reveals is one of the most important data points in Indian cybersecurity in 2026: the country with the highest attack frequency has among the lowest financial consequences per breach, creating a structural environment where investment in prevention has historically been difficult to justify on purely financial grounds.

Chart 1: Average weekly attacks per organisation versus average breach cost by country, 2026 (Source: IBM Cost of Data Breach Report 2026; Checkpoint Research)

What the Attack Composition Looks Like

The dominant attack vector against Indian organisations in 2025 and 2026 is AI-assisted social engineering. Attackers are using large language models to generate convincing phishing content in multiple Indian languages simultaneously, personalised to the recipient using data harvested from social media profiles, data breaches and digital tracking footprints. The volume and linguistic quality of these messages has increased to the point where they are genuinely difficult to distinguish from legitimate communications even for employees who have received awareness training.

Cloud misconfiguration is the second most significant attack vector. As Indian organisations across all sectors have accelerated migration to cloud infrastructure, exposed storage buckets, weak identity controls and improperly configured access management systems have created a consistent and easily exploitable attack surface. Research published in 2026 suggests that up to 75 percent of cloud security breaches globally are caused by inadequate identity, access or privilege management rather than by novel attack techniques. India’s rapid cloud adoption without a commensurate investment in cloud security architecture has made this a particularly acute vulnerability.

Supply chain attacks present the third major threat category and the one with the greatest potential for cascading damage. India’s IT and ITeS sector serves as a digital supplier to thousands of organisations globally. A successful supply chain compromise targeting a major Indian IT services provider does not affect only that provider. It affects every client organisation that depends on the software, infrastructure or services it delivers.

Sector-Level Threat Profile

SectorPrimary ThreatSpecific Risk Factor in IndiaRisk Level 2026
Banking and FinanceUPI fraud and account takeoverScale of UPI transaction volumes creates enormous fraud surfaceCritical
HealthcarePatient data breach and ransomwareLarge unpatched systems and high data value to criminal marketsCritical
IT and ITeSSupply chain compromiseGlobal client base amplifies impact of any successful breachVery High
Government Digital PlatformsMass data exfiltrationAadhaar and DigiLocker hold data on over a billion individualsVery High
EducationData breach and ransomwareSeverely underfunded security with large student databasesHigh
Energy and UtilitiesOT and infrastructure probingIncreasing state-linked targeting of power grid infrastructureHigh and rising

Table 1: Sector-level threat profile for India in 2026 with specific risk factors and current risk assessment

The Detection Gap Is as Dangerous as the Attack Volume

The most operationally significant problem in Indian cybersecurity in 2026 is not the volume of attacks. It is the detection gap. A large proportion of Indian organisations across the mid-market and SME segments operate without a security operations centre, without 24-hour monitoring capability and without the log management infrastructure required to detect an intrusion in real time.

CERT-In’s 6-hour incident reporting requirement is a meaningful obligation for organisations that can detect an incident within that window. For an organisation without monitoring capability an intrusion may persist for weeks or months before it is detected by an external party, a affected customer or an opportunistic threat actor advertising the access for sale on a criminal forum. By the time the organisation is aware a breach has occurred the 6-hour reporting clock is largely academic.

The investment required to close the detection gap is not primarily in expensive technology. It is in establishing basic log collection and alerting capabilities that most mid-sized organisations in the UK, US and EU have treated as a standard requirement for over a decade. The CERT-In 180 day log retention mandate creates the legal obligation. The enforcement of that obligation is what will drive the infrastructure investment.

Leave a Reply

Your email address will not be published.