
India Processes One-Third of the World's Security Alerts. Why Does It Still Import Its Security Thinking?
India runs a large share of the world's security operations, yet imports the intelligence and frameworks behind them. Why operational scale has not become intelligence ownership, and what that leaves open for Indian companies to build.
Summary
- Indian IT services firms run 24/7 security operations for global clients, yet the threat intelligence, platforms and frameworks their analysts use are largely imported.
- The telemetry these operations generate could power India-first threat intelligence, but client contracts and a billable-hours model discourage retaining and productising it.
- Relying on intelligence built for other threat environments leaves Indian institutions under-defended against local attacks such as UPI phishing and Aadhaar-related fraud.
India runs the world's cybersecurity operations. But the intelligence that drives them comes from somewhere else entirely.
Every night, in delivery centres across Bengaluru, Hyderabad, Chennai, and Pune, tens of thousands of Indian security analysts monitor the digital infrastructure of American hospitals, British banks, Australian retailers, and German manufacturers. They triage alerts, investigate anomalies, write incident reports, and escalate threats. They are, by any reasonable measure, the operational backbone of global cybersecurity.
India's IT services companies collectively employ more security professionals than most countries have in total. TCS, Infosys, Wipro, HCLTech, and Tech Mahindra run 24/7 security operations centres that process millions of security events daily for clients across North America, Europe, and Asia-Pacific. India is the world's largest exporter of cybersecurity services by headcount and delivery volume.
And yet.
The threat intelligence those analysts use comes from Recorded Future, a US company. The detection platform comes from CrowdStrike or Palo Alto Networks, both American. The frameworks come from MITRE ATT&CK, built in Virginia. The playbooks are adapted from NIST guidelines, written in Maryland. The AI models that triage the alerts were trained on threat data collected primarily from North American and European enterprise networks.
India processes the alerts. Someone else decides what they mean.
The Data Paradox
Here is what makes this paradox especially striking. The raw material for world-class threat intelligence is not capital or technology. It is data. Specifically, it is incident data: what attacks look like in practice, how they propagate, what they target, and how they evolve. And India, by virtue of processing security events for hundreds of global clients across thousands of enterprise networks, sits on one of the largest repositories of real-world threat telemetry on the planet.
Every phishing email that a TCS security analyst triages. Every ransomware alert that a Wipro SOC analyst investigates. Every anomalous login pattern that an Infosys threat hunter examines. Each of these is a data point. Aggregated across millions of events, across thousands of clients, across years of operations, this telemetry is the foundation of the most accurate possible picture of how attackers actually behave.
Indian IT services companies are generating the data that could power world-class threat intelligence. They are not systematically converting it into a product. The data is being processed and discarded rather than retained, enriched, and monetised.
The reasons are partly contractual: client data belongs to the client, and most MSSP agreements include provisions that prevent vendors from using client security data for any purpose other than delivering the contracted service. But the structural barrier is not just legal. It is strategic. The dominant business model of Indian IT services is billable hours and FTE contracts. Investing in proprietary intelligence platforms requires R&D spend that reduces short-term margin without an immediate billable return. The incentive structure of the industry actively discourages the investment that would allow India to convert its operational scale into intellectual capital.
What India-Specific Threat Intelligence Would Actually Look Like
India's threat landscape has characteristics that global platforms built primarily on North American and European data systematically under-serve. Consider the attack vectors that are most prevalent in India:
• UPI-linked phishing and social engineering that exploits the specific interface conventions of BHIM, GPay, PhonePe, and Paytm in ways that no Western threat intelligence feed captures with precision. • Aadhaar-related identity fraud that exploits the specific architecture of India's digital identity infrastructure, including OTP interception, biometric bypass, and demographic data exploitation. • APT campaigns targeting Indian defence supply chains, using Hindi-language spearphishing and using the specific procurement workflows of DRDO and defence ministry contractors. • State-sponsored intrusion attempts targeting Indian critical infrastructure: power grid SCADA systems, railway management platforms, and telecom backbone providers, each with India-specific attack surface characteristics.
A threat intelligence platform trained specifically on Indian threat data would detect these attack patterns faster, with higher accuracy, and with lower false positive rates than any global platform can achieve. It would know that a particular phishing template targets Indian BFSI clients, not generic banking customers. It would recognise the specific payload signatures associated with threat actors who target Indian government systems.
This platform does not exist at scale. SAFE Security has built a risk quantification layer. Innefu Labs has built government-facing intelligence tools. Seqrite has built endpoint detection models that perform well on locally prevalent malware families. These are early signals of what Indian threat intelligence could become. None has yet built the comprehensive, telemetry-driven, India-first threat intelligence platform that the country's operational scale could support.
Why This Matters Beyond Market Size
The import of security thinking is not just a commercial opportunity missed. It is a strategic vulnerability.
When India's critical infrastructure operators, BFSI institutions, and government agencies make cybersecurity decisions based on threat intelligence frameworks built for a different threat environment, they systematically under-invest in the defences that matter most for their actual exposure.
The AIIMS Delhi ransomware attack of 2022 compromised approximately 40 million patient records and disrupted services for nearly two weeks. The attack vector was not novel. The specific combination of vulnerabilities exploited, the propagation method, and the ransomware variant used were all known to global threat intelligence platforms. But the specific configuration of AIIMS's network, the third-party access pathways, and the social engineering approach used were tailored to the Indian healthcare context in ways that global intelligence had not pre-mapped. A domestic threat intelligence capability would have. Not because Indian analysts are smarter. Because they would be working with data from the right environment.
The Strategic Inflection Point
India is at an inflection point in cybersecurity that it has been at before in adjacent industries. The country built a world-class pharmaceutical generics manufacturing base by combining scale, cost efficiency, and regulatory capability. It built a world-class IT services industry by combining English-language capability, technical education, and time-zone advantage. In both cases, India started as a low-cost executor of other people's intellectual frameworks and progressively built enough proprietary capability to compete on the value of what it knew, not just the cost of what it did.
Cybersecurity is the next iteration of this pattern. The operational scale is already there. The talent is already there. The threat data is being generated at scale every night. What is missing is the strategic decision to treat that data as an asset rather than a by-product of service delivery.
The company that builds a genuinely India-first threat intelligence platform, trained on Indian threat telemetry, sold to Indian enterprises and exported to global markets with India-specific differentiation, will find that the moat it has built cannot be replicated by any foreign vendor regardless of their technology or capital.
India runs the world's cybersecurity operations. The moment it starts thinking for them too, the industry's value architecture changes permanently.
How useful was this article?
One tap. It tells us what to write more of.
About the author
SRF Capital Studio
The next one
Get what we publish next, by email.
Working notes on raising, borrowing, protecting, growing and structuring capital in India. One email a week at most, and you can leave any time.
We use your address only to send this. See our privacy policy.
We store your address to send you these emails and nothing else. See our privacy policy.
Related reading
Why the Cheapest Cybersecurity Decision an Indian SME Can Make Is Also the Most Expensive6 min read
3,195 Attacks Per Week. And Most Indian Companies Are Still Running Antivirus From 2019.6 min read
Your SOC Has 10 Analysts. AI Is About to Make 7 of Them Redundant. Here Is What the Other 3 Need to Become.7 min read
