Skip to content
    An ageing desktop computer still running a working counter
    Industry Signals

    3,195 Attacks Per Week. And Most Indian Companies Are Still Running Antivirus From 2019.

    June 8, 2026 · Article · 6 min read

    SRF Capital Studio

    The threat has industrialised. The defence has not. This is the gap that is costing Indian businesses thousands of crores every year.

    Summary

    • Attacks on Indian organisations have grown 70% in two years as ransomware-as-a-service turned cybercrime into a franchise industry needing no technical knowledge.
    • Signature-based antivirus cannot stop zero-day exploits, living-off-the-land attacks, AI-generated phishing or supply chain attacks, the main vectors behind major Indian breaches.
    • A minimum defence of EDR, MFA, tested offline backups, email filtering and patching costs far less than an incident, and DPDPA penalties now raise the stakes.
    The threat has industrialised. The defence has not. This is the gap that is costing Indian businesses thousands of crores every year.

    Indian organisations faced an average of 3,195 cyberattacks per week in 2025. That is from Check Point's annual report, published in February 2026. It represents a 70% increase since 2023. It is significantly higher than the global average of 1,968 attacks per week.

    Read that again: 3,195 attacks. Per organisation. Per week.

    Now consider what most Indian organisations are defending against those 3,195 attacks with. A signature-based antivirus subscription last renewed in 2021. A firewall installed during the office WiFi setup and never configured beyond the defaults. An IT team of one or two people who also handle printer problems, laptop procurement, and the CEO's password resets. A cybersecurity budget set three years ago when the threat environment was materially different.

    This is not a description of a negligent organisation. It is a description of most Indian businesses with fewer than 500 employees. And it represents approximately 63 million companies.

    What Changed. And When.

    Cyberattacks were always a risk. What changed between 2019 and 2025 is that cybercrime became an industry. Specifically, it became a franchise industry.

    Ransomware-as-a-Service (RaaS) platforms like LockBit, ALPHV/BlackCat, and Clop operate exactly like commercial software businesses. They build the attack tools. They recruit affiliates. They provide technical support. They negotiate ransoms. They handle payments. They take a revenue share. The affiliate provides nothing except access to a target. No technical knowledge required.

    The barrier to becoming a cybercriminal has been reduced to approximately zero.

    The result is an attack volume that has grown 70% in two years and shows no sign of moderating. Check Point recorded a 53% year-on-year increase in extorted ransomware victims in 2024-25 and a 50% rise in new RaaS groups. There are more attackers, better equipped, targeting more organisations, with less discrimination than at any previous point in the history of cybercrime.

    A 17-year-old with a laptop can now deploy the same attack that required a nation-state in 2015. The tools cost nothing. The targets are everywhere. The potential reward is substantial.

    Why India Is Particularly Exposed

    The digital payment surface:

    UPI processed 185 billion transactions in FY2025, handling Rs. 246 lakh crore in transaction value. India's National Cyber Crime Reporting Portal recorded Rs. 36,450 crore in financial cyber fraud losses by February 2025, driven primarily by UPI-linked phishing, AI-assisted social engineering, and SIM swap attacks. The same digital infrastructure that makes India's payments system the most ambitious in the world makes it the most concentrated fraud target.

    The digitisation-without-security pattern:

    The AIIMS Delhi ransomware attack of 2022 compromised records of approximately 40 million patients. The BSNL data breach of 2024 exposed sensitive subscriber data. The CoWin data breach exposed health and identification data of millions of citizens. These incidents did not happen because India's engineers are incompetent. They happened because the organisations that built these systems prioritised deployment speed over security architecture. Each new digitisation initiative creates proportional new security demand that organisations are not investing to meet.

    The SME security vacuum:

    India's 63 million registered SMEs are the largest undefended attack surface in Indian cybersecurity.

    Most operate with basic antivirus and a general-purpose IT provider with no specific security expertise. They process customer data, supplier data, and financial data, often without understanding that they are data fiduciaries under DPDPA. They are targeted not because they are high-value individually but because they are low-defence entry points into supply chains that reach larger enterprises.

    What the Antivirus From 2019 Cannot Stop

    Signature-based antivirus works by matching files and network traffic against a database of known threats. It is excellent at stopping threats that were identified and catalogued before the scan. It is essentially useless against:

    • Vulnerabilities not yet publicly disclosed cannot be in any signature database. Zero-day exploits: • Attackers use legitimate tools already present on a system (PowerShell, WMI, PsExec), leaving no malicious files for signature scanning to detect. Living-off-the-land attacks: • Modern phishing emails generated by AI are grammatically perfect, contextually personalised, and visually indistinguishable from legitimate communications. AI-generated phishing: • The attacker compromises a trusted third party to gain access to the real target. The malicious activity appears to come from a trusted source. Supply chain attacks:

    These are not exotic, rarely-seen attack techniques. They are the primary attack vectors documented in the major Indian breaches of the past three years. They are what the 3,195 weekly attacks include. And antivirus from 2019 stops none of them.

    The Minimum Viable Defence for an Indian Business in 2025

    This is not a recommendation to spend crores on enterprise security platforms. For most Indian organisations, the minimum viable defence that would stop the vast majority of attacks they will actually face consists of:

    • Modern EDR tools use behavioural analysis to detect threats never seen before. The cost difference between EDR and antivirus for a 200-person company is approximately Rs. 3-6 lakh annually. The cost of a ransomware incident for the same company averages Rs. 50-200 lakh. Endpoint Detection and Response (EDR) over legacy antivirus:

    • The single most effective control against credential-based attacks. Most organisations that have experienced a serious breach were not running MFA on the system where the attacker gained initial access. Multi-Factor Authentication (MFA) on every external-facing system: • Ransomware works by encrypting your data and demanding payment for the decryption key. Offline backups eliminate the leverage entirely. Backup without testing is not backup; it is hope. Regular, tested, offline backups:

    • Blocks the primary delivery mechanism for the majority of attacks. Cost: Rs. 1,500-3,000 per user per year. Email filtering with AI-powered phishing detection: • 96% of exploits in 2024 leveraged vulnerabilities disclosed before the year they were used. Organisations that apply security patches promptly eliminate the vast majority of the attack surface that commodity attackers exploit. Patch management:

    None of these require a CISO. None require a dedicated security team. All of them together cost significantly less than the average cybersecurity incident they would prevent. The barrier is not budget. It is awareness and priority.

    The DPDPA Accelerant

    The Digital Personal Data Protection Rules, notified on November 13, 2025, impose legally defined security obligations on every entity that processes digital personal data of Indian citizens. Full compliance obligations come into force on May 13, 2027. The penalties for non-compliance are material: up to Rs. 250 crore for failure to maintain reasonable security safeguards.

    For Indian businesses, this changes the calculus of cybersecurity investment fundamentally. It is no longer purely an insurance decision, where the expected cost of an incident is weighed against the cost of prevention. It is now also a compliance decision, where the regulatory consequence of inadequate security includes penalties that dwarf the cost of the security investment itself. The 3,195 attacks per week are not slowing down. The defences most Indian businesses are running cannot stop them. And from May 2027, there is a regulator with the authority to hold businesses accountable for the consequences.

    How useful was this article?

    One tap. It tells us what to write more of.

    Not usefulVery useful

    About the author

    SRF Capital Studio

    The next one

    Get what we publish next, by email.

    Working notes on raising, borrowing, protecting, growing and structuring capital in India. One email a week at most, and you can leave any time.

    We use your address only to send this. See our privacy policy.

    We store your address to send you these emails and nothing else. See our privacy policy.

    Related reading