How to Protect Your Business Data from Ransomware: A 2026 Guide for Indian SMEs
56% of ransomware attacks now reach encryption, and businesses with 100-250 staff are the least likely to stop one in time. What an attack really costs an Indian SME, what CERT-In and the DPDP Rules require of you within hours, and a 30-60-90 day plan.
Category: Cybersecurity · Published: August 22, 2026 · 13 min read · Author: ZM Technologies Team
If ransomware locked your servers tonight, how much of your data would you get back — and how quickly? For most Indian SMEs the honest answer is we are not sure. That uncertainty is the entire business model of ransomware.
This guide is written for owners, finance heads and IT managers at Indian businesses with roughly 20 to 500 employees — services firms, manufacturers, healthcare providers, logistics operators, retailers, distributors and professional practices. It is not a threat-intelligence essay. It covers what an attack actually costs you, what Indian law now requires you to do within hours of discovering one, the controls that genuinely stop encryption, and a 90-day plan you can start on Monday without a security team.
Book a free security audit → or WhatsApp us on +91 7066028888.
What Actually Changed in 2026
Two data points reframe the problem for Indian SMEs this year.
First, attackers are succeeding more often. Sophos' State of Ransomware 2026 found that 56% of attacks reached the encryption stage, up from 50% the year before. More importantly for you: only 34% of organisations with 100-250 employees stopped an attack before encryption or extortion — the weakest of every size band, against a high of 46% among firms of 3,001-5,000 employees. The mid-market is where attacks are landing.
Second, the way in has shifted from software to identity. Sophos reports that 79% of ransomware attacks began with an identity-based approach. The leading root causes were malicious email (26%), phishing (24%), compromised credentials (23%) and exploited vulnerabilities (18%). Where attackers got their foothold matters just as much: exposed applications and systems (38%), user devices (30%), firewalls (21%), VPNs (8%).
Read that firewall and VPN number again. Your perimeter device is not only your defence — it is one of the doors. An unpatched firewall or a VPN account without MFA is now a leading entry route.
On the cost side, IBM's 2026 Cost of a Data Breach report for India put the average Indian breach at ₹25.5 crore, up 15.9% year on year, with phishing the top attack vector at 19%. That average is pulled upward by large enterprises and financial services, so do not read it as your bill — but the direction of travel is unambiguous. The same report found 26% of malicious breaches were AI-generated, and that shadow AI usage added ₹1.79 crore to breach costs where it was present.
One more number worth understanding. The global median ransom demand fell 65% over two years to $698,000, while 48% of encrypted victims still paid, at a median payment of $769,000. (Those two medians come from different groups of respondents, which is why the payment figure sits above the demand figure.) Falling demands are not good news — they signal a shift from a handful of large targets to a high volume of smaller ones. Smaller demands are calibrated to what a mid-sized business will actually pay.
What a Ransomware Attack Really Costs an Indian SME
Ignore the headline averages for a moment. Here is the cost structure we see when we are called into a 75-150 seat Indian business that has been encrypted. These are our own figures from incident work, not a vendor survey.
Operational downtime: 5 to 12 working days. Even a well-run recovery rarely restores everything at once. ERP and finance come back first; email archives, file shares, design data and reporting trail behind by days.
Recovery labour: ₹4 lakh to ₹20 lakh. Forensics, rebuild, restore validation, and the specialist help you will need at short notice and premium rates.
Revenue and contract loss: ₹20 lakh to ₹2 crore. Missed deliveries, SLA penalties, quotations you could not send, customers who moved an order and did not move it back.
Permanent data loss. Whatever sat outside a working backup: years of email, in-progress work, drawings, quality records, the shared drive nobody owned.
Regulatory and legal exposure. CERT-In reporting, DPDP obligations, customer breach notifications, legal review. See the next section.
Customer and audit fallout. Enterprise customers will send you a security questionnaire afterwards. Some will send an auditor. A few will send neither and simply stop issuing POs.
Insurance repricing. Renewal premiums rise, and cover narrows.
Add it up honestly and a serious ransomware event at an Indian SME rarely lands below ₹50 lakh all-in, and frequently crosses ₹2 crore. A proportionate protection stack for the same business costs a small fraction of that per year — the arithmetic is not close.
The Compliance Clock: What Indian Law Requires Within Hours
This is the part most SMEs discover during an incident rather than before one. Two separate clocks start the moment you notice something is wrong.
CERT-In: six hours
The CERT-In Cyber Security Directions of April 2022 require covered entities — including body corporates, service providers and intermediaries — to report a cyber incident to CERT-In within six hours of noticing it or being made aware of it. The directions also require you to:
Retain ICT system logs for 180 days, stored within India, and produce them when asked.
Synchronise all system clocks to the NIC or NPL time servers, so logs from different systems can actually be correlated.
Designate a point of contact for CERT-In communication.
Non-compliance is punishable under Section 70B(7) of the IT Act with imprisonment of up to one year and/or a fine — a ceiling raised to ₹1 crore by the Jan Vishwas (Amendment of Provisions) Act, 2023. In practice, the six-hour window is where unprepared businesses fail — not because they refuse to report, but because at hour six they are still trying to work out what happened, and nobody has been named to file.
DPDP Rules: without delay, then 72 hours
The Digital Personal Data Protection Rules were notified on 14 November 2025, with the eighteen-month transition ending — and full adjudicatory enforcement beginning — on 14 May 2027. If personal data is involved — and in a ransomware event it usually is — Rule 7 requires a Data Fiduciary to:
Inform each affected Data Principal without delay, in clear plain language, covering the nature, extent and timing of the breach, the likely consequences for them, what you are doing about it, what they should do to protect themselves, and who at your organisation they can contact.
Inform the Data Protection Board without delay with a description of the breach, its nature, extent, timing, location and likely impact.
Follow up to the Board within 72 hours with the facts and circumstances, mitigation measures, findings on who caused it, remedial steps to prevent recurrence, and a report on the intimations you sent to affected individuals.
Penalties under the DPDP framework run to ₹250 crore for failing to take reasonable security safeguards, with a separate penalty of up to ₹200 crore for failing to notify a breach. For an SME the realistic risk is not the maximum penalty — it is being unable to evidence that you notified anyone, because you had no log, no owner and no template.
The practical takeaway: you cannot meet a six-hour clock reactively. Before anything happens you need three things on one page — who files, what the filing says, and where the logs are. That page costs nothing and takes an afternoon.
The Ten Controls That Actually Stop Ransomware
There is no single product that prevents ransomware. What works is a small number of layered controls, deployed in the order that matches how attacks actually begin. We have ordered these deliberately.
1. Multi-factor authentication on everything — especially the things you forgot
With 79% of attacks starting from identity, MFA is the single highest-return control you can deploy. Most Indian SMEs already have it on Microsoft 365. Far fewer have it on the VPN, the firewall admin console, the remote-access tool, the ERP, or the legacy line-of-business app the accounts team uses. Those gaps are exactly where attackers go. Start with MFA and SSO coverage across every remote-access path, not just email.
2. EDR, not antivirus
Consumer or bundled antivirus does not stop modern ransomware — it looks for known files, and ransomware operators change files constantly. You need endpoint detection and response with behavioural blocking and anti-ransomware rollback: Sophos Intercept X, Microsoft Defender for Endpoint, SentinelOne or ESET PROTECT. If you are comparing options, our endpoint security comparison and business antivirus price guide cover the Indian pricing realistically.
3. Immutable backups, following 3-2-1-1-0
This is the control that decides whether an attack is a bad week or an extinction event. Three copies of your data, on two different media, one offsite, one immutable copy that cannot be altered or deleted even with admin credentials, and zero errors on the daily verification report. Sophos found 66% of organisations whose data was encrypted recovered from backup in 2026 — up from 54% — and backup recovery is consistently cheaper and faster than paying. We deploy this with Veeam; see our backup and disaster recovery service.
4. Back up Microsoft 365 and Google Workspace separately
Microsoft and Google guarantee the availability of their platform, not the recoverability of your data. Under the shared responsibility model, ransomware that encrypts synced OneDrive or SharePoint content, or a malicious deletion, is your problem. Most SMEs assume otherwise until they need a restore. We cover why in detail in Microsoft 365 Backup Storage, and offer it as a managed service.
5. Patch the edge before you patch anything else
Firewalls, VPN appliances and internet-exposed applications accounted for the majority of initial footholds. Your patch programme should start at the perimeter and work inward, not the other way around. If your firewall is out of support or running firmware from two years ago, that is your most urgent item on this list.
6. Get off a flat network
In most SMEs we audit, everything sits in one broadcast domain: accounts, design, servers, CCTV, the guest Wi-Fi, and in manufacturing the shop floor too. One infected laptop then reaches everything. Segment by function, block inter-VLAN traffic by default, and put anything legacy or unpatchable behind strict access control.
7. Harden email and enforce DMARC
With malicious email and phishing together accounting for half of root causes, filtering is not optional. Layer advanced filtering with attachment sandboxing and impersonation protection on top of your tenant, and enforce SPF, DKIM and DMARC properly — most Indian SME domains we check have DMARC set to p=none, which means it is reporting and blocking nothing.
8. Remove standing admin rights
Nobody should do daily work from an account that can install software everywhere. Separate admin accounts, no shared credentials, no service accounts with domain admin, and an offboarding process that actually disables accounts on the last working day. This costs nothing but discipline.
9. Monitor around the clock
Attacks are timed for when nobody is watching — late nights, Saturdays, the week of Diwali. Detection at 9 AM Monday is not detection. Managed detection and response gives you someone who isolates the affected machine at 2 AM instead of reading about it in the morning. This is core to our managed IT and cybersecurity services.
10. Train people in a language they think in
Quarterly phishing simulations plus short micro-training, delivered in English, Hindi or Marathi as appropriate for your team. The goal is not a perfect score — it is that the person who clicks tells someone within five minutes instead of hiding it for a day.
A 30-60-90 Day Plan for an SME With No Security Team
You do not need to do all ten at once. This is the sequence we use, arranged so the free and fast items come first.
Days 1-30 — mostly free, no budget approval needed
List every internet-facing system you own: firewall, VPN, remote desktop, web apps, cameras, anything with a public IP.
Turn off RDP exposed directly to the internet. Today. It is still one of the most common ways in.
Enable MFA on every remote-access path, not just email.
Disable accounts belonging to people who have left. Check the list — there will be more than you expect.
Patch the firewall and VPN firmware, and confirm the device is still under support.
Actually restore a file from your backup. Not check the green tick — restore something and open it.
Name one person as incident owner, and write the one-page CERT-In and DPDP notification template.
Days 31-60 — the core spend
Roll out EDR across every endpoint and server, with anti-ransomware protection enabled and tuned.
Add an immutable backup copy — cloud object lock or hardened repository — and set up daily verification.
Turn on Microsoft 365 or Google Workspace backup.
Harden email filtering and move DMARC from p=none to quarantine, then reject.
Design the network segmentation plan and start with the highest-risk zone.
Configure 180-day log retention with Indian storage, and NTP sync to NPL or NIC.
Days 61-90 — make it stick
Add 24x7 monitoring or MDR.
Run a tabletop exercise: walk your management team through hour one of an attack, on paper.
Run a timed full restore drill and record the actual recovery time. That number is your real RTO — not the one in the proposal.
Complete a cyber insurance readiness review.
Document your controls, so the next enterprise customer questionnaire takes an hour instead of a fortnight.
What Protection Costs, by Company Size
Indicative all-in monthly OPEX for a managed stack covering EDR, backup with immutability, firewall management, email security, patching and monitoring. GST extra; actual pricing depends on the mix of vendors and how much of the estate is already in place.
25 seats: ₹25,000 - ₹50,000 per month
50 seats: ₹45,000 - ₹90,000 per month
100 seats: ₹80,000 - ₹1.6 lakh per month
200 seats: ₹1.5 lakh - ₹3 lakh per month
250 seats: ₹1.8 lakh - ₹3.6 lakh per month
At 100 seats, a full year of protection at the upper end costs roughly ₹19 lakh. A single incident at the same business starts around ₹50 lakh. That is the whole argument.
Cyber Insurance: What Insurers Now Expect
Cyber cover has become significantly harder to obtain in India without evidence of specific controls. Underwriters commonly ask for MFA on remote access and privileged accounts, EDR deployment, offline or immutable backups with tested restores, a defined patching cadence, email filtering, security awareness training, and a written incident response plan.
Two things to watch. Answering the proposal form optimistically can void a claim later — insurers do verify after an incident. And cover is not a substitute for controls: policies increasingly carry sub-limits and exclusions on business interruption and ransom payment. Treat insurance as the last layer, never the first.
We are not insurance advisors. Discuss cover, sub-limits and exclusions with a licensed broker before you rely on a policy.
If You Are Being Attacked Right Now: The First 60 Minutes
Print this. Keep a copy off the network.
Isolate, do not shut down. Pull network cables and disable Wi-Fi on affected machines. Powering off destroys memory evidence and can corrupt partially encrypted files.
Do not wipe or rebuild anything yet. You will need the evidence for forensics, insurance and the CERT-In filing.
Note the exact time of discovery. Your six-hour CERT-In clock starts here, and you will be asked for this timestamp repeatedly.
Call your IT partner and your insurer's incident hotline. Most policies require notification before you engage third-party responders.
Protect the backups first. Check them from a known-clean machine. Never mount backup storage to a machine on the infected network — that is how organisations lose their last good copy.
Assume data was stolen, not just encrypted. Double extortion is standard now. If personal data was in scope, your DPDP Rule 7 obligations to affected individuals and to the Board are live.
Appoint one spokesperson. Staff, customers and vendors will all ask at once. Mixed messages during hour one cause damage that outlasts the outage.
Do not pay yet, and do not negotiate alone. Payment does not guarantee a working decryptor, does not undo exfiltration, and has legal implications. Take advice first.
Five Beliefs That Get Indian SMEs Encrypted
We are too small to be a target. Ransomware is automated and indiscriminate. The 34% figure earlier says the opposite of what most owners assume: smaller organisations are the least likely to stop an attack in time, which makes them more attractive, not less.
We have antivirus. Free or bundled antivirus is designed for known threats. Modern ransomware is not a known threat when it reaches you.
Our data is on the cloud, so it is backed up. Cloud platforms replicate for availability. They do not protect you from encryption, corruption or malicious deletion of your own data. That is your responsibility under the shared responsibility model.
If it happens, we will just pay. 48% of encrypted victims paid in 2026, at a median of $769,000. Payment buys a decryptor that may be slow or incomplete, and does nothing about stolen data. Indian authorities advise against paying.
Our backup runs every night. A backup you have never restored from is a hypothesis, not a backup. And a backup reachable with the same admin credentials as your servers gets encrypted with them.
Frequently Asked Questions
How quickly must an Indian business report a ransomware attack? Under the CERT-In Directions of 2022, within six hours of noticing the incident. Separately, if personal data is affected, the DPDP Rules require you to inform affected individuals and the Data Protection Board without delay, with fuller details to the Board within 72 hours.
Does the DPDP Act apply to a small business? The obligations attach to anyone determining the purpose and means of processing digital personal data — there is no blanket small-business exemption from breach notification. Significant Data Fiduciary obligations such as audits and DPIAs apply only to entities so designated.
What is the single most important control if I can only do one thing this month? MFA on every remote-access path. It is free or near-free on most platforms and addresses the identity-based approach behind the majority of attacks.
What does immutable backup actually mean? Backup data written in a form that cannot be modified or deleted for a defined retention period, even by an administrator with valid credentials. It is what stops ransomware from encrypting your backups along with your servers.
How long does it take to deploy a full protection stack? For a typical 50-150 seat business, two to four weeks from kickoff to fully live, with no planned downtime. The 30-day items in the plan above can be done in the first week.
Should we ever pay the ransom? Indian authorities advise against it, and there is no guarantee of a working decryptor or of stolen data being deleted. The decision has legal and insurance implications — take advice before considering it. The better answer is to make payment unnecessary through tested immutable backups.
We are a manufacturer — is there anything specific to us? Yes. OT and shop-floor systems change the picture significantly. See our dedicated guide on ransomware attacks on Pune and PCMC manufacturing units.
Get a Free Ransomware Readiness Check
We will review your backup posture, endpoint protection, firewall and identity coverage, and give you a written gap report with prioritised fixes and honest costs. No obligation, and no sales pitch dressed up as an audit.
Request Your Free Security Audit →
Or reach us directly:
WhatsApp / Call: +91 7066028888
Email: sales@zmtechnologies.com
Office: 1304, Nyati Enthral, Kharadi, Pune 411014 — serving businesses across India.
The businesses that recover well are not the ones that were never targeted. They are the ones that had a tested restore and a named owner before the phone rang.