
Why the Cheapest Cybersecurity Decision an Indian SME Can Make Is Also the Most Expensive
Cybersecurity is often viewed as a cost centre until the day it becomes a crisis. By then, the economics change dramatically. This article breaks down the financial reality of cyber incidents for Indian SMEs, from operational downtime and recovery expenses to regulatory exposure and customer trust, and explains why prevention remains the cheapest strategy available.
Summary
- An SME’s real cybersecurity decision is how much invisible risk it will carry, since attacks give no warning before files are encrypted.
- A serious incident can cost a mid-size SME Rs. 50-200 lakh through downtime, recovery and ransom, against Rs. 10-20 lakh a year for basic protection.
- Under the DPDPA Rules, failing to maintain security safeguards is a legal violation carrying penalties of up to Rs. 250 crore, with full obligations from May 2027.
The cost of not investing in cybersecurity is invisible until it arrives. And when it arrives, it arrives all at once.
The most common cybersecurity decision an Indian SME makes is not the one its owner thinks it is.
The owner thinks the decision is: antivirus or no antivirus, firewall or no firewall, security or no security audit. These feel like active choices with visible costs.
The actual decision being made is different. It is: how much risk am I willing to carry unknowingly, and how much of it will I be able to absorb when it materialises?
Most Indian SME owners have never framed their cybersecurity posture as a risk-carrying decision because the risk is invisible until it is not. You do not see the attack coming. You do not feel the vulnerability being exploited. You have no warning before the morning your team arrives at the office and every file on every server is encrypted with a ransom demand attached.
The Real Cost of a Cybersecurity Incident for an Indian SME
When security researchers cite the average cost of a data breach at $4.88 million (IBM, 2024), Indian SME owners reasonably conclude that this number has nothing to do with them. The SME calculation is different, but it is not more reassuring.
• A ransomware attack typically takes a business offline for 5-21 days. For a Rs. 50 crore annual revenue business, each day of downtime costs approximately Rs. 14-20 lakh in direct revenue loss, plus the cost of staff who cannot work, orders that cannot be fulfilled, and clients who find alternative suppliers during the disruption. Operational downtime:
• Incident response fees for professional data recovery and forensics run Rs. 5-25 lakh for a mid-size SME environment. System rebuild and data restoration adds Rs. 2-10 lakh. Recovery costs: • Indian SMEs are increasingly paying ransoms, typically Rs. 10-50 lakh for mid-size businesses, because the alternative (extended downtime plus recovery costs) is more expensive. Payment does not guarantee recovery; approximately 40% of businesses that pay ransoms do not fully recover their data. Ransom payment:
• From May 2027, DPDPA enforcement applies to any entity processing digital personal data of Indian citizens. Failure to maintain security safeguards carries penalties of up to Rs. 250 crore. For most SMEs, a single regulatory penalty would be existential. Regulatory consequences:
• The client who discovers their supplier was breached and their data was exposed does not typically give a second chance. A single major security incident that becomes public can end customer relationships that took years to build. Reputational damage:
Total incident cost for a mid-size Indian SME: Rs. 50-200 lakh in the short term. Potentially existential if regulatory penalties and client loss compound.
The Invisible Nature of Cybersecurity Risk
The reason SMEs systematically under-invest in cybersecurity is not primarily budget. It is the invisibility of the risk before it materialises and the visibility of the cost before it is incurred.
If you install an EDR endpoint security platform for your 150-person company, you will pay approximately Rs. 4-6 lakh per year. You will see that cost every month on your P&L. You will not see the attacks it blocked. You will not see the ransomware it detected and contained before it encrypted anything.
The security investment is visible; its benefit is invisible.
If you do not install it and you have a serious incident three years later, the Rs. 4-6 lakh annual cost that would have prevented it will seem like the most obviously rational investment in hindsight. But in hindsight is the only context where it is obvious. In the context of a growing business with competing investment priorities, it competes with a new machine, a better ERP system, an additional salesperson, or profit distribution to the promoter.
What Has Changed: The DPDPA Inflection
The DPDPA Rules 2025, notified on November 13, 2025, with full compliance obligations coming into force on May 13, 2027, change the investment calculation in two ways. First, they define what reasonable security safeguards means and make failure to implement them a legal violation regardless of whether a breach has occurred. Second, they make the regulatory consequence of a breach a certain and immediate cost rather than a probabilistic one.
Every Indian SME that processes digital personal data of its customers, employees, or suppliers (which is essentially every formal business with a digital presence) is now a data fiduciary under DPDPA. The obligations include implementing security safeguards, maintaining data processing records, and notifying the Data Protection Board within defined timelines if a breach occurs. Most Indian SMEs are not yet compliant. Most are not aware of the specific requirements. Many will discover their obligations at the worst possible moment: when an incident has already occurred and the notification clock is running.
The Actual Investment Required
For a 100-200 person SME, the annual investment in basic but effective cybersecurity looks approximately like this:
• Rs. 3-5 lakh per year Modern EDR endpoint security (replacing legacy antivirus): • Rs. 1.5-3 lakh per year Cloud-based email security with AI phishing detection: • Rs. 50,000-1 lakh (one-time setup) + Rs. 30,000-50,000 ongoing Multi-factor authentication deployment: • Rs. 1-2 lakh per year Automated, tested, offline backup system: • Rs. 1.5-3 lakh per year Annual vulnerability assessment: • Rs. 2-5 lakh (one-time, first year) DPDPA compliance gap assessment and remediation:
Total: approximately Rs. 10-20 lakh per year for a 100-200 person business. Against an average incident cost of Rs. 50-200 lakh. Against regulatory penalties that could reach Rs. 250 crore. Against the reputational consequence of a public breach in a B2B market where trust is the primary currency.
The cheapest cybersecurity decision an Indian SME can make is to do nothing. It is also the most expensive, because the eventual cost is not the monthly subscription it saved. It is the incident it did not prevent, multiplied by the regulatory penalty it did not anticipate, compounded by the clients it did not retain.
Three Questions Every Indian SME Should Ask Today
If you are an SME owner reading this, the relevant questions are not technical. They are operational and financial:
• If every file on every server in your business was encrypted tomorrow, how long would it take to resume operations, and what would that cost? • Do you know what personal data of customers, employees, or suppliers your business processes and stores, and where it is held? • When did your IT provider last conduct any security assessment of your infrastructure beyond the annual antivirus renewal?
If the answer to the first question is 'more than a week,' the second is 'not really,' and the third is 'we have never done that': you are carrying a level of cybersecurity risk that is not reflected in your insurance, your financial planning, or your operational contingency. And from May 2027, it will not be reflected in your regulatory compliance either.
The cybersecurity investment that feels expensive today is the one that prevents the incident that would cost ten times more tomorrow.
The framing is not 'can we afford cybersecurity.' The accurate framing is 'can we afford not to.'
How useful was this article?
One tap. It tells us what to write more of.
About the author
SRF Capital Studio
The next one
Get what we publish next, by email.
Working notes on raising, borrowing, protecting, growing and structuring capital in India. One email a week at most, and you can leave any time.
We use your address only to send this. See our privacy policy.
We store your address to send you these emails and nothing else. See our privacy policy.
Related reading
3,195 Attacks Per Week. And Most Indian Companies Are Still Running Antivirus From 2019.6 min read
Your SOC Has 10 Analysts. AI Is About to Make 7 of Them Redundant. Here Is What the Other 3 Need to Become.7 min read
India Processes One-Third of the World's Security Alerts. Why Does It Still Import Its Security Thinking?6 min read
