Cybersecurity 2026

INDIA Trends and Developments Contributed by: Amit Jaju and Amol Pitale, Ankura Consulting Group, LLC

ance verifiable by design rather than enforced after- the-fact. The framework creates regulatory sandbox - es, establishes AI incident databases and proposes DEPA-style (Data Empowerment and Protection Archi - tecture) consent frameworks that integrate technology with legal obligations. Critically, the Guidelines deliberately refrain from proposing a new omnibus AI law. Instead, they emphasise that India’s existing regulatory environ - ment – anchored in the DPDP Act, the Information Technology Act, sectoral statutes, and constitutional principles – provides adequate legal foundations. The missing layer, the Guidelines argue, is execution. This approach creates flexibility for rapid AI innovation while maintaining proportional governance for high- risk applications. The institutional architecture supporting these guide - lines includes three key bodies: the AI Governance Group (AIGG), which serves as a high-level co-ordi - nation body; the Technology and Policy Expert Com - mittee (TPEC), which develops technical standards; and the proposed AI Safety Institute (AISI), which will execute audits and certifications. Rather than paper- based compliance reviews, AISI would conduct direct assessments of governance architectures, enabling real-time observability of organisational compliance maturity. Trend five – the supply chain attack surface – vendors as security dependencies India’s interconnected digital ecosystem has created an unexpected vulnerability: the supply chain itself has become the primary vector for major compro - mises. Large BFSI and critical infrastructure entities have hardened their perimeters, prompting attackers to pivot toward smaller, less secure vendors and ser - vice providers embedded within supply chains. The Cyble APAC Threat Landscape Report 2025 doc - umented 456 ransomware attacks across the region, with India consistently featuring among the most attacked nations. A high-profile example: an Indian multinational payment system was compromised in January 2025, with unauthorised access to production databases, source code and infrastructure credentials being offered for sale on underground forums. During

the same month, multiple Indian companies expe - rienced data leaks due to compromised S3 bucket access, exposing more than 22 terabytes of sensitive corporate information. The pattern is consistent: attackers no longer target the fortress; they compromise the trusted vendors granted access to it. This has necessitated a funda - mental shift from static vendor questionnaires and annual security certifications to continuous third-party risk management (TPRM). Forward-looking organisa - tions are now implementing: • real-time security ratings for vendors, updated continuously based on threat intelligence; • automated access provisioning and de-provision - ing, eliminating standing access rights; • joint incident response table-top exercises with critical vendors, establishing playbooks before crisis strikes; • supplier-specific segmentation of network resourc - es, limiting lateral movement even if vendor cre - dentials are compromised; and • continuous vulnerability scanning of third-party infrastructure and configuration audits The realisation is stark: an organisation is only as secure as its weakest vendor. In India’s outsourcing- heavy environment, where large service providers rou - tinely subcontract work to smaller firms to manage labour costs, this risk multiplies exponentially. Insider threats and credential misuse in IT outsourcing envi - ronments have become a leading cause of large data exposures, costing the average organisation USD17.4 million annually. Trend six – forensic readiness – from reactive investigation to proactive detection A notable maturity shift is occurring in the Indian mar - ket: the transition from reactive forensic investigations to proactive forensic readiness. Historically, organi - sations would scramble to engage forensic experts only after a breach was confirmed, often resulting in the loss of volatile evidence critical for attribution, recovery and insurance claims. This approach is now obsolete.

209 CHAMBERS.COM

Powered by