India Inc.’s cybersecurity paradox: More tools, same old breaches

A new ESET Enterprise Cybersecurity Report 2026 (India), conducted in partnership with Blackbox Research, paints a sobering picture of enterprise security in India: more spending on tools is not stopping more frequent breaches. Despite record investment in technology, Indian organizations are being breached more often than ever, and the reasons are surprisingly human.

AI: A double-edged sword

The report finds that 99% of Indian businesses are now using or piloting AI in some form, from customer service chatbots to fraud detection. But this rapid adoption has a cost: 85% of organizations experienced an AI-related cyber threat in the past year. The most common issues include AI-generated phishing and impersonation (48%), data leakage through AI platforms (48%), and deepfake or voice-cloning attacks (47%). As a result, concern is greatest in sectors such as technology and financial services, where AI-driven threats are seen as an increasing operational risk rather than a distant possibility.

Breaches are the norm, not the exception

Perhaps the most striking figure is this: 80% of Indian businesses suffered a major security incident in the last 12 months. Nearly half of those affected 44% were hit three or more times. These incidents most often involved data exfiltration, cloud breaches, business email compromise and ransomware, with attackers frequently chaining multiple techniques together rather than relying on a single method.

The fallout isn’t confined to IT departments. One in six affected businesses reported significant financial losses, and a similar share faced legal or regulatory penalties — a reminder that cybersecurity failures increasingly carry boardroom-level consequences.

The real problem isn’t technology

According to the report, the biggest obstacles to better defense aren’t a lack of tools; they’re capability gaps. Delayed detection (55%), limited internal resources (54%), and poor visibility across IT environments (53%) were the top challenges organizations faced when trying to contain an incident. In practice, only 19% of businesses could detect and respond to a threat within the critical first hour; most took 24 hours or more.

Employees remain the weakest link

Human error continues to open the door for attackers. Nearly a third of incidents were linked to user actions, most commonly employees clicking phishing links, reusing weak passwords or mishandling sensitive data. While 97% of organizations now run cybersecurity awareness training, the report’s experts stress that frequency alone isn’t enough; training needs to be timely and relevant to the threats employees are actually likely to face, such as festival-season scams or AI-generated deepfake calls.

Looking ahead: MDR and smarter insurance

Looking to close these gaps, 84% of Indian organizations are now using or planning to adopt Managed Detection and Response (MDR) services, driven by the need for round-the-clock monitoring and faster response times. Meanwhile, cyber insurance is becoming harder to secure; 97% of businesses reported challenges including rising premiums, stricter insurer requirements, and difficulty demonstrating their security maturity.

The takeaway for Indian enterprises is clear: more security software isn’t solving the core problem. Faster detection, sharper employee awareness, and stronger operational resilience will determine who survives the next attack and who becomes another statistic in next year’s report.

Author