Cybersecurity 2026

INDIA Trends and Developments Contributed by: Amit Jaju and Amol Pitale, Ankura Consulting Group, LLC

viduals of breaches, or violations related to children’s data, can attract penalties up to INR200 crore. Even general compliance failures carry penalties of INR50 crore. The Board’s enforcement focus has been clear: demonstrable compliance means organisations must prove the technical efficacy of their data gov - ernance infrastructure. This has triggered a surge in data discovery and classification exercises across Indian enterprises, as boards and CISOs recognise they cannot protect data they cannot see, classify or account for. The requirement for explicit, verifiable, free and informed consent for data processing has forced e-commerce platforms, financial institutions and digital service providers to redesign their data handling architectures entirely. A critical upcoming milestone is November 2026, when enhanced obligations for consent managers become operational. Organisations that have not already established robust consent infrastructure are now facing accelerated timelines to demonstrate com - pliance. The investment required in privacy-enhancing technologies, consent management platforms, and breach notification systems has made data protection a material financial planning consideration for Indian corporates. Trend three – critical infrastructure under threat – geopolitical dimensions While deepfake fraud targets individuals and enter - prises, a parallel threat landscape is forming around India’s critical infrastructure. According to Kaspersky’s Global Research & Analysis Team, India is likely to see a significant increase in cyberattacks targeting criti - cal infrastructure and government systems in 2026, driven by geopolitical tensions, cross-border conflicts and the continued digitisation of operational technol - ogy (OT) environments. The threat profile has shifted from traditional cyber - espionage to disruption-oriented attacks. State-spon - sored actors and non-state groups are leveraging cyber operations as an extension of geopolitical con - flict, with a growing focus on defacement campaigns, data leaks with political messaging, co-ordinated DDoS attacks and cyber activity linked to diplomatic

flashpoints. India’s expanding digital public infrastruc - ture – including digitisation of government services, smart city initiatives and public health systems – has dramatically expanded the national attack surface. Recent incidents illustrate the vulnerability. AIIMS Del - hi was targeted twice in seven months during 2022– 2023, disrupting hospital operations. The SPARSH portal breach in January 2024 exposed defence per - sonnel data through a misconfigured cloud storage bucket – not a sophisticated exploit, but a simple oversight. While India’s power sector blocked 99.99% of attempted cyberattacks in 2024, 150 successful breaches still penetrated these defences. As Union Power Minister Manohar Lal Khattar noted, tracing attack origins to specific nations is nearly impossible, making attribution and response co-ordination excep - tionally difficult. The convergence of IT and OT systems has created new vulnerabilities. Legacy security frameworks that protected isolated operational technology environ - ments were not designed for the interconnected, cloud-dependent systems now driving India’s digital transformation. Sectors such as power generation and distribution, water systems, transportation net - works, telecommunications and public administration face mounting risk from Advanced Persistent Threat (APT) actors leveraging spear-phishing as an initial access vector combined with zero-day exploits and lateral movement techniques. Trend four – India’s AI Governance Framework – a soft-law paradigm In November 2025, the Ministry of Electronics and Information Technology released India’s comprehen - sive AI Governance Guidelines, establishing a unique approach distinct from the prescriptive regulatory models adopted globally. Rather than imposing strict licensing requirements or outright bans, India has adopted a “soft-law” framework grounded in princi - ples and techno-legal integration. The Seven Sutras form the philosophical core: Trust, People First, Innovation Over Restraint, Fairness and Equity, Accountability, Transparency, and Sustain - ability. These principles are operationalised through a practical governance model that emphasises compli -

208 CHAMBERS.COM

Powered by