Indian small and medium enterprises are increasing their focus on cybersecurity, but a large share continue to rely on periodic or manual security practices, creating gaps between the growing threat environment and their ability to detect and respond to attacks.
How Many SMEs Plan to Increase Cybersecurity Spending?
The findings show that 84 per cent of Indian SMEs plan to increase cybersecurity spending over the next 12 to 24 months.
However, 61 per cent continue to operate with intermittent security oversight, highlighting a gap between investment intentions and operational capability.
The cybersecurity challenges facing SMEs include persistent ransomware, malware, phishing, supply-chain threats and emerging risks across sectors including IT and IT-enabled services, e-commerce, manufacturing, BFSI, healthcare technology, EdTech and travel technology.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
How Closely Are Cyber Threats Being Monitored?
Only 35 per cent of SMEs conduct cybersecurity reviews quarterly or half-yearly, while another 20 per cent rely on ad-hoc practices.
Just 17 per cent have implemented continuous 24×7 monitoring. Another 18 per cent conduct regular reviews supported by structured reporting mechanisms.
This creates a detection challenge because cyber incidents can develop much faster than traditional review cycles. Delays in identifying suspicious activity can allow attackers more time to remain inside systems.
How Quickly Are Cyber Incidents Detected?
The impact of slow detection is already visible among SMEs. Of organisations that experienced cybersecurity incidents, 19 per cent reported business disruption or operational downtime.
Another 17 per cent experienced data leakage or loss, while 15 per cent reported unauthorised access to systems or information.
The findings indicate that 45 per cent of SMEs take four hours or more to detect and contain a cyber incident. For businesses operating continuously, that delay can give attackers additional time to move through systems or affect operations.
Is Artificial Intelligence Changing the Threat?
Artificial intelligence is emerging as another major factor in the cybersecurity landscape.
The findings indicate that 65 per cent of SMEs view AI-driven attacks as a threat they cannot fully visualise or defend against. At the same time, 34 per cent expect AI-driven cyber threats to materially affect their businesses over the next 12 to 24 months.
Data leakage, cloud security risks, financial fraud and identity-based attacks were also identified among the leading concerns.
What Is Holding SMEs Back?
A major obstacle is the cost of cybersecurity implementation. About 65 per cent of respondents identified cost as the biggest barrier to cybersecurity implementation, followed by integration complexity at 43 per cent and budget constraints at 23 per cent.
Around 65 per cent also reported that in-house network security capabilities were insufficient, while 33 per cent reported having no incident-response capabilities.
The figures indicate that increasing cybersecurity budgets alone may not address the problem if businesses lack the expertise and operational systems required to detect and respond to attacks.
Are SMEs Relying on External Security Providers?
Many SMEs are turning to outside providers for security monitoring. About 40 per cent rely on periodic or manual checks for cyber-risk monitoring, compared with 28 per cent using continuous monitoring and automated alerts.
Meanwhile, 73 per cent said they were dissatisfied with their current cybersecurity setup.
The findings recommend that SMEs move towards always-on security monitoring, greater use of specialist cybersecurity expertise and measurement based on outcomes such as mean time to detect and mean time to contain incidents. They also highlight managed security partnerships as a way to address internal capability gaps while maintaining full-scale 24×7 security operations.
The420 View
Higher cybersecurity spending will mean little if threats are discovered hours after they enter a system. For SMEs, the sharper priority is turning security budgets into continuous monitoring, faster detection, skilled response and stronger internal capability.
The finding that 45% take four hours or longer to detect and contain an incident shows why always-on visibility is becoming increasingly important.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics