When IBM publishes research showing that India faces the highest average weekly attack volume of any country in its global study and that the average cost of a breach in India is among the lowest of any major economy, there is a predictable temptation to read the low cost figure as a sign of resilience. If attacks are high and costs are low, perhaps Indian organisations are dealing with threats effectively while spending efficiently. This reading is wrong and acting on it will produce poor security outcomes.
The low average breach cost in India reflects three structural factors that have nothing to do with the quality of Indian security programmes. First, regulatory penalties in India have historically been far lower than in the United States or Europe. A breach that would trigger a multi-million dollar GDPR fine in the European Union or a significant SEC disclosure penalty in the US has typically resulted in far smaller regulatory consequences in India. The DPDP Act is changing this but the first major enforcement actions have not yet concluded. Second, class action litigation for data breaches is far less developed in India than in common law jurisdictions with mature consumer protection regimes. Third, detection rates in India are lower than in comparable economies, which means that many breaches are not detected, reported or costed at all.
The Attack Volume and Breach Cost Paradox
The chart below illustrates the paradox directly. India’s weekly attack volume per organisation is almost double that of the United States and more than double that of the United Kingdom. Its average breach cost is less than a quarter of the US figure. This is not a normal distribution. It is the signature of a regulatory and enforcement gap.

Chart 1: India weekly attack volume versus breach cost compared to selected countries, 2026 (Source: IBM Cost of Data Breach Report 2026)
What the DPDP Act Changes and What It Does Not
The DPDP Act’s penalty structure of up to $29 million (₹250 crore) per violation for data breach failures is genuinely transformative for Indian data protection regulation. It creates, for the first time, a financial consequence for poor security that is large enough to appear as a material risk in an Indian enterprise’s financial planning. Organisations that have treated data security as an IT housekeeping matter rather than a business risk will need to recalibrate.
What the DPDP Act does not change is the detection problem. A penalty of $29 million (₹250 crore) is a powerful incentive to invest in security. It is not an incentive that operates automatically. It requires that breaches are detected, that they are reported correctly and that the Data Protection Board has the enforcement capacity and political will to pursue violations at scale. All three of those conditions are still being tested in 2026. The Board became operational in late 2025 and its enforcement approach in the first major cases will define how seriously the penalty structure is taken by corporate India.
The CERT-In 6-hour reporting requirement creates a parallel incentive for detection investment. An organisation that cannot detect a breach within 6 hours cannot comply with the reporting mandate. The mandate therefore creates a direct regulatory driver for investment in monitoring and detection capability that was absent before the Directions came into force in 2022. Four years into the mandate the compliance rates and the quality of incident detection across the Indian enterprise landscape remain variable.
The Investment Gap That the Numbers Reveal
| Security Investment Area | Current Indian Market Status | What Comparable Economies Spend | Gap Assessment |
| Security operations and monitoring | Low to medium in most organisations | High; SOC considered standard for mid-market | Significant gap |
| Cloud security architecture | Low; cloud adoption outpaces security investment | High; cloud security now a board priority | Critical gap |
| Identity and access management | Variable; strong in large enterprises, weak in SMEs | High; MFA and PAM considered baseline | Variable |
| Incident response capability | Low; most organisations lack a tested IR plan | Medium to high; regular tabletop testing expected | Significant gap |
| Supply chain security | Low; third-party risk management immature | Medium; formal supplier assessment growing | Significant gap |
| Regulatory compliance capability | Growing rapidly under DPDP and CERT-In pressure | High; compliance teams well established | Closing |
Table 1: Security investment gap analysis for India compared to comparable economies, 2026 assessment
Why the Narrative Needs to Change
The dominant narrative in Indian cybersecurity investment discussions is that India is a high-threat, low-cost environment that requires a calibrated response proportionate to the penalty exposure. That narrative made a certain kind of sense when the penalty exposure was low. It does not make sense in an environment where the DPDP Act creates penalties of $29 million (₹250 crore) per violation and the CERT-In reporting mandate creates criminal liability for non-compliance.
The more accurate narrative is that India faces the highest attack volume in the world, a detection gap that means a large proportion of those attacks succeed without being noticed and a regulatory transition that is in the process of creating European-scale financial consequences for the breaches that are eventually discovered. The combination of high volume, low detection and increasing penalties is not a comfortable place to be for any organisation that is not investing in security at a level that matches the threat.
The IBM figure of 3,195 weekly attacks per organisation is not a measure of how many attacks Indian organisations are successfully defending against. It is a measure of how many attempts are being made. The number of attempts that succeed and go undetected is unknowable from the data. Given the detection capability of the average Indian mid-market organisation it is reasonable to assume that the success rate is meaningfully higher than the breach cost data suggests. The low cost per breach does not mean breaches are cheap. It means many of them are not being counted.

Leave a Reply