
Indian small and medium-sized businesses are significantly increasing their cybersecurity investments as cyberattacks become more prevalent. According to the Tata Tele Business Services-CyberMedia Research, 84% of SMEs plan to increase cybersecurity spending over the next 12-24 months. This investment surge follows direct experience with cyber incidents, with 40% of SMEs reporting an incident in the past two years. Another comprehensive report from Kaspersky confirms this trend, showing that 87% of Indian SMBs surveyed reported a cyber incident in the past year. As per Tata Teleservices Chief Revenue Officer Vishal Rally, "It is encouraging to see that 84% of SMEs plan to increase their cybersecurity investments over the next two years. As cyber threats continue to evolve, businesses need to make cybersecurity an integral part of their broader digital transformation journey."
Despite increased spending intentions, Indian SMEs face a critical gap between investment plans and operational capabilities. The latest TTBS-CMR SME Digital Insights on Cybersecurity Study 2026 reveals that 61% of SMEs still rely on intermittent security oversight, with 35% conducting cybersecurity reviews quarterly or half-yearly and 26% relying on ad-hoc practices. Only 12% have implemented continuous 24/7 monitoring, while 18% conduct regular reviews supported by structured reporting mechanisms. The study found that 40% of SMEs rely on periodic or manual checks for cyber-risk monitoring, compared with just 28% using continuous monitoring and automated alerts. 73% said they were dissatisfied with their current cybersecurity setup, highlighting the urgent need for improved detection capabilities. The study also found that 35% of SMEs operate multiple cybersecurity tools but have limited visibility into risks, indicating that while businesses are adopting different security solutions, fragmented tools and limited monitoring capabilities can make it difficult for organisations to get a clear view of their overall cybersecurity environment.
According to the Kaspersky survey covering IT security specialists across SMBs and enterprises in 18 countries, organisations in the APAC region experienced three different types of security incidents over the past year. For SMBs specifically, the most frequently encountered incidents were software vulnerability exploitation (20%), phishing (19%), and mass malware attacks (18%). Even zero-day exploits, which ranked lowest among listed incident types, were encountered by 6% of organisations. India recorded an incident rate of 87% among SMBs surveyed, with Vietnam reporting the highest regional rate at 97%, followed by Malaysia at 95% and Indonesia at 92%. The TTBS-CMR study found that 40% of SMEs have experienced a cyber-incident over the last two years, yet only 28% implemented structural cybersecurity improvements after the incident, highlighting the persistent challenge of translating awareness into actionable security improvements.
The impact of cyber incidents is already significant among SMEs, with 19% of organisations experiencing cybersecurity incidents reporting business disruption or operational downtime, 17% experiencing data leakage or loss, and 15% reporting unauthorised access to systems or information. The TTBS-CMR study identifies 45% of Indian SMEs as identifying lack of in-house cybersecurity expertise as their biggest challenge, followed by 43% citing integration complexity and 23% facing budget constraints. While 65% of SMEs reported in-house network security capabilities, only 33% reported having incident-response capabilities, and 53% reported internal cloud-security expertise. The study recommends that SMEs move towards always-on security monitoring, greater use of specialist cybersecurity expertise, and measurement based on outcomes such as mean time to detect and contain incidents. Spending on cybersecurity also remains limited for a significant number of SMEs, with 46% of SMEs allocating less than 5% of their IT budgets to cybersecurity, suggesting considerable scope for increased investment as businesses strengthen their digital infrastructure.
Artificial intelligence is emerging as both a security tool and additional risk factor for SMEs. The TTBS-CMR study found that 65% of SMEs view AI-driven attacks as a threat they cannot fully visualise or defend against, while 34% expect AI-driven cyber threats to materially affect their businesses over the next 12-24 months. This creates a complex security environment where the same technology can help security teams detect threats while being used by attackers to increase attack scale and complexity. However, 35% of SMEs recognise AI as a cybersecurity enabler, particularly for faster threat detection, automated monitoring and improved incident response. As per CyberMedia Research Vice President Prabhu Ram, "Our study findings highlight a clear inflection point in the cybersecurity journey of Indian SMEs. While investment intent is rising sharply, cyber maturity remains uneven, with just 12% of SMEs continuously monitoring their cybersecurity environments. At CyberMedia Research (CMR), our analysis suggests that SME cyber resilience will increasingly depend on integrated, continuously managed approaches - a shift already visible among the more mature enterprises in our sample."