Indian SMBs are the most common cyber crime victims and the least prepared. A 30-person manufacturing company in Hisar is just as much a target as a Bengaluru SaaS unicorn — and usually loses more, relative to revenue, when it gets hit. This guide is for the practical owner or IT lead who wants to lock down their business in 2026 without burning ₹50 lakh on enterprise tools.
The 80/20 — Five Things That Stop 80% of Attacks
- MFA on every account — email, banking, ERP, CRM, payroll. No exceptions.
- Backups, tested — 3 copies, 2 different media, 1 offsite. Test restore every quarter.
- Email anti-phishing — use Google Workspace / Microsoft 365 (don't run your own mail server)
- Endpoint security on every laptop — basic EDR like CrowdStrike Falcon Go or SentinelOne
- Patch monthly — Windows, Office, browsers, the web CMS, the ERP
Most of these cost under ₹500 / employee / month. Do these and you eliminate the vast majority of script-kiddie attacks targeting Indian SMBs.
Realistic Annual Cyber Security Budget for SMBs in India
| Business Size | Annual Budget | Includes |
|---|---|---|
| 10 employees | ₹40,000 – ₹1,20,000 | M365 / Google Workspace + basic EDR + annual VAPT |
| 30 employees | ₹2,00,000 – ₹4,00,000 | Add SOC alerting, awareness training |
| 100 employees | ₹8,00,000 – ₹15,00,000 | Add MSSP, GRC consultant |
What Indian SMBs Get Wrong
- Buying a firewall and calling it "secure" — firewalls are necessary, far from sufficient
- Pirated Windows / Office — comes with built-in malware in many cases
- Shared admin passwords on a whiteboard — yes, still happens in 2026
- "We are too small to be a target" — automation makes everyone a target
- No backups, or backups on the same network as production — ransomware encrypts both
30 / 60 / 90 Day Action Plan
First 30 Days — Quick Wins
- Enable MFA on email + UPI/banking + ERP
- Change all default passwords on the firewall and Wi-Fi routers
- Inventory every device that connects to the company network
- Buy & install endpoint security on every laptop/desktop
- Run a phishing simulation to set baseline awareness
30–60 Days — Foundations
- Move email to Google Workspace or Microsoft 365 (managed = patched + scanned)
- Set up automated backups with offsite storage
- Document your data flow — what data goes where (DPDP requirement)
- Write a one-page incident response plan
- Train all staff on phishing in 1 short session
60–90 Days — Mature
- External penetration test of your website / app — see VAPT services in Haryana
- Network segmentation — separate guest Wi-Fi, IoT, production
- Patch management process — monthly check, not "when something breaks"
- Vendor risk review for SaaS tools you use
- Consider cyber insurance for ransomware loss coverage
Real Hisar Example
A 25-person trading company in Hisar lost ₹8 lakh to invoice fraud in 2024 — an attacker impersonated their supplier over email after compromising the supplier's mailbox. After they engaged us, the fix took 11 weeks: MFA on email, vendor verification process, supplier email policies, basic awareness training, and a ₹35,000 / year MSP retainer. They've had zero incidents since. The lesson: the controls are inexpensive; the consistency is what's hard.
Where to Get Help in Haryana
- Cyber Defence (Hisar) — local VAPT, training, ongoing managed support — our services
- CERT-In (national) — free guidelines and incident reporting
- Haryana Cyber Cell — for active incident reporting
- Local CA — for cyber insurance options
Train at Cyber Defence Academy, Hisar
Hands-on labs, real-world projects, government-of-India trusted institute. Online + offline batches across Haryana. Placement support, lifetime access to materials.
FAQs
Do I really need MFA?
Yes. MFA alone stops >99% of automated account takeover attempts.
What is the single highest-ROI thing I can do today?
Turn on MFA for email. Costs nothing. Stops most attacks.
Should an SMB hire a full-time security person?
Below ~50 employees: usually no — engage an MSSP / consulting firm. Above 100: yes.
