Cybersecurity 2026

INDIA Trends and Developments Contributed by: Amit Jaju and Amol Pitale, Ankura Consulting Group, LLC

Leading organisations are pre-retaining forensic experts and deploying logging and evidence-preser - vation capabilities within their networks during peace - time. Black-box recording of network traffic, endpoint activity and cloud access logs ensures that when an incident occurs – and the operational assumption is that it will – the “who, what, when and where” can be established in hours rather than weeks. This forensic readiness is crucial not just for remediation, but for meeting the strict reporting obligations mandated by CERT-In and the DPDP Act. As articulated in Ankura’s recent research on foren - sic investigations, AI is now embedded within this readiness framework, not as a replacement for human judgement but as a component within structured, auditable and defensible workflows. Machine learn - ing models process terabytes of log data to surface anomalies in network behaviour, access patterns and transaction histories that would escape manual review. Natural language processing extracts intent and contextual meaning from emails and chat logs, revealing collusion and co-ordinated malicious behav - iour. However, the investigative process remains fun - damentally human: AI surfaces relationships and time - lines warranting validation; investigators corroborate findings against multiple evidence sources and build narratives that satisfy both regulatory and evidentiary standards. The regulatory architecture supporting forensic readi - ness has also hardened. CERT-In, India’s nation - al cyber-incident response agency, handled over INR29.44 lakh cyber-incidents in 2025 alone, issuing 1,530 alerts, 390 vulnerability notes and 65 advisories. The establishment of sector-specific and state-level Computer Security Incident Response Teams (CSIRTs) has created a networked response capability. The Cyber Swachhta Kendra (Botnet Cleaning and Mal - ware Analysis Centre) provides free tools and forensic support to organisations and citizens. The Cyber Cri - sis Management Plan (CCMP) for government entities provides structured guidance during major attacks affecting essential services. This institutional deepen - ing of forensic capability at the national level creates accountability: organisations that demonstrate foren - sic readiness through proper logging and evidence preservation benefit from faster regulatory resolution,

while those lacking readiness face extended investi - gation timelines and compounded penalties. Trend seven – insider threats in India’s outsourcing environment An often-overlooked cybersecurity risk in India is the insider threat posed by the nation’s IT and business process outsourcing ecosystem. India hosts some of the world’s largest BPO and IT services companies, employing millions of professionals with access to sensitive client data. While outsourcing has delivered enormous economic value, it has also created an envi - ronment where insider threats – from deliberate data theft to negligent exposure – carry substantial cost and regulatory risk. The global Cost of Insider Threats Report (Ponemon Institute, 2025) reveals that insider incidents now cost organisations an average of USD17.4 million annually, a 7.4% increase year-on-year. In India’s outsourcing context, the risk factors are particularly acute: • high employee turnover and competitive talent poaching create opportunities for disgruntled insid - ers to exfiltrate data before departure; • subcontracting arrangements create obscured access control chains, making it difficult to track who actually has access to sensitive systems; • moonlighting – where employees simultaneously serve competitors – creates undeclared conflicts of interest and IP leakage; and • third-party vendor misuse, where overseas support contractors leverage authorised access for person - al gain or crime, has resulted in multi-crore losses in recent cases The Coinbase breach (April 2025) exemplified this risk: insider misuse at third-party support vendors enabled targeted impersonation scams, exposing customer names, addresses, government-issued IDs and banking metadata. Coinbase’s response – ter - minating involved insiders, shutting down overseas support contracts, centralising operations in the US – reflected a broader industry realisation that out - sourcing without forensic-grade access governance introduces unacceptable risk. The cost of that breach included operational disruption, legal scrutiny, market impact and regulatory exposure.

210 CHAMBERS.COM

Powered by