AI-FIRST CYBERSECURITY · Always Wise. Always Ahead. +91-95851-60363 info@semperwise.com DOVER, DE, USA

MSME cyber security · India

Small-business security that starts where the money leaks.

Most Indian MSMEs do not lose money to someone breaking through a firewall. They lose it to a changed bank account in a real-looking email, a swapped QR code on the counter, or an accounts PC locked the week GST is due. This is the honest version: what the law actually asks of a small firm, where the losses really happen, and what to fix first.

Reviewed 23 September 2026 · 17 sources cited

The short answer

For an Indian MSME, cyber security starts with protecting payments and email. Two duties are already law for companies of every size: report listed incidents to CERT-In within six hours, and keep logs for 180 days in India. DPDP Act safeguards and breach reporting follow from about 13 May 2027. CERT-In’s 15 MSME controls are recommended, not mandatory — but they make a good checklist. Start with multi-factor login, a call-back rule for bank-detail changes and a tested offline backup.

Why small firms

Small firms are not attacked less. They are attacked more cheaply.

The picture most owners carry is a hacker breaking into a big company’s servers. The data says something else. Verizon’s 2026 Data Breach Investigations Report found that, where the victim’s size was known, about 96% of ransomware victims were small and mid-sized organisations — by Verizon’s definition, fewer than 1,000 staff. The ways in were ordinary: stolen passwords in 38% of those cases, and unpatched firewalls and VPNs in 29%.

In India, the money mostly leaves through payments. The Ministry of Home Affairs told the Lok Sabha that Indians lost ₹22,845.7 crore to cyber fraud in 2024. Two of the clearest business cases since then were email frauds, not break-ins. Dr Reddy’s Laboratories paid ₹2.16 crore meant for a vendor into a mule account after an email from a lookalike of that vendor’s address. An Indore drilling company paid US$415,017 — about ₹3.72 crore — to fraudsters who had inserted themselves into its correspondence with a US supplier. Both were recovered, and in both the difference was speed: the Bengaluru account was frozen within an hour, and the Indore company caught on by phoning its vendor directly.

Small firms are also the way into bigger ones. That is why large customers now send supplier security questionnaires, and why CERT-In’s own MSME baseline tells firms to hold every third party to the same standard as themselves. A small exporter that cannot answer those questions is no longer just carrying a risk — it is losing orders.

None of this needs an enterprise budget. It needs about a dozen things done properly, in the right order, and an honest answer about which of them the law actually requires. That is what the rest of this page is for.

Mandatory or not

What the law actually asks of a small firm

Sorted honestly: what is law today, what arrives with the DPDP Act, and what is recommended or expected by customers. General information, not legal advice — where a line matters to a decision, take it to counsel.

ObligationStatusWho it coversWhat it means in practice
Report listed cyber incidents to CERT-In within 6 hours Law — CERT-In Directions, April 2022 Every “body corporate”; the IT Act defines that to include firms and sole proprietorships (confirm the scope with counsel) Twenty incident types, including phishing, website defacement, malicious code such as ransomware, data leaks and unauthorised access to a business social-media account. Decide now who reports, and how.
Keep ICT logs for a rolling 180 days, stored in India Law — CERT-In Directions As above Email, firewall, server and cloud logs. Most small firms find they keep a week, if anything.
Sync clocks and name a point of contact for CERT-In Law — CERT-In Directions As above Minutes of work that is almost never done.
Security safeguards and breach notice under the DPDP Act Law from about 13 May 2027 — DPDP Rules, 2025 Anyone holding digital personal data; there is no size threshold Patient records, client files and customer lists all count. After a breach: tell the Data Protection Board and the people affected without delay, then file a detailed report within 72 hours.
Two-factor login on the GST e-invoice and e-way bill portals Mandatory for all taxpayers since 1 April 2025 Every GST taxpayer using those portals The OTP goes to the registered mobile. An accountant who needs you to forward OTPs is a process risk, not a convenience.
CERT-In’s 15 Elemental Cyber Defense Controls (45 recommendations) Recommended — MSMEs “may” self-assess MSMEs as classified under the MSME Act The best free checklist there is. The self-check further down is built on it.
Annual baseline audit by a CERT-In-empanelled auditor Recommended, unless a regulator, a government buyer or a contract requires it MSMEs Once a customer’s contract demands an empanelled audit, it is a contractual obligation — read your contracts.
Supplier security questionnaires from large customers Expected by customers Anyone selling to large firms, banks or EU buyers Increasingly built on the same baseline. CERT-In’s own control TPRM.2 tells buyers to hold suppliers to it.

Penalty for ignoring a CERT-In direction: section 70B(7) of the IT Act — imprisonment of up to one year, a fine of up to ₹1 lakh, or both. DPDP penalties run up to ₹250 crore, but the Act requires the Board to weigh the likely impact of a penalty on the business that pays it.

Five real patterns

Five ways a small business actually loses money

Each is drawn from a reported Indian case or from CERT-In’s own ransomware report. None needed the attacker to break anything clever.

01

The changed bank account

  1. Way inA lookalike of a supplier’s email address — one character different — joins a real payment conversation, or the supplier’s own mailbox is taken over.
  2. Then“Our bank details have changed” arrives with the right invoice number and the right tone. The payment goes to a mule account, sometimes abroad.
  3. CostCrores in a single transfer: ₹2.16 crore in the Dr Reddy’s case, about ₹3.72 crore in the Indore case. Both were recovered only because they were reported within hours.

What we test: Your domain’s SPF, DKIM and DMARC, lookalike-domain exposure, who is able to change payee details — and whether a call-back rule exists and is actually followed.

02

The swapped QR code

  1. Way inA genuine merchant QR code is edited to carry a different account, and the copy is placed at the counter or sent to the customer.
  2. ThenThe customer pays, sees “success”, and the money lands in someone else’s account.
  3. CostLost takings and angry customers. In December 2025 Delhi Police arrested a man whose phones held more than 100 edited and original merchant QR codes; one garment store lost ₹1.4 lakh in two payments.

What we test: Not a penetration test — a habit. Our awareness sessions cover the two-minute opening check that catches it.

03

The accounts PC, locked before a filing date

  1. Way inRemote desktop or a remote-support tool left reachable from the internet, or a database server with a guessable password.
  2. ThenRansomware encrypts the accounting PC and the network drive where the backups also live.
  3. CostMissed GST filings, a ransom demand and leaked customer data. CERT-In’s 2024 ransomware report names exposed remote desktop and brute-forced database servers among the real entry points in India.

What we test: Which of your systems answer from the internet, how they are protected, and whether your backups would survive an attack on the office network.

04

The website that quietly turns on customers

  1. Way inAn outdated WordPress or WooCommerce plugin on a site a freelancer built years ago.
  2. ThenDefacement, a card skimmer on the checkout page, or hidden spam pages that get the domain blacklisted.
  3. CostLost search ranking and stolen customer data. Website defacement is on CERT-In’s six-hour reporting list.

What we test: The site, its plugins and its hosting — see WordPress security for what that covers.

05

The one mailbox that holds everyone’s keys

  1. Way inA phishing “GST notice”, “e-challan” or “tax refund” email, or a fake software installer.
  2. ThenThe mailbox is taken over. At a CA firm or a clinic it holds clients’ portal logins, signature tokens or patient files.
  3. CostFraud across many clients at once, compensation claims under section 43A of the IT Act today, and DPDP breach duties from May 2027.

What we test: Mailbox and account security, where multi-factor login is missing, and where client credentials actually live.

Evidence

The numbers behind the risk

Each figure is linked to its primary source below. Where a study defines “small” differently from the MSME Act, we say so.

₹22,845.7 cr Lost by Indians to cyber fraud in 2024, per the Home Ministry’s reply in the Lok Sabha [5]
29.44 lakh Cyber incidents handled by CERT-In in 2025 [13]
≈96% Of ransomware victims were small or mid-sized organisations — under 1,000 staff, in Verizon’s definition [4]
7.83 crore Enterprises registered on the Udyam portals by February 2026 [14]
₹25.5 cr Average cost of a data breach in India in 2026, across the organisations IBM studied [15]
₹2.47 cr Average saving from offensive security testing — the largest cost-reducing factor in IBM’s 2026 India data [15]

IBM’s study covers organisations of every size, so ₹25.5 crore is not an MSME average; read it as how bad a breach can get, not the expected bill for a small firm. What carries over is the direction: testing was the factor that cut the cost most.

16-question self-check

CERT-In’s fifteen controls, plus the one that saves the most money

Tick only what you could show someone today, not what you intend to do. Questions 2 to 16 each map to one of CERT-In’s 15 Elemental Cyber Defense Controls, with its reference in brackets. Question 1 is not on CERT-In’s list — it is the control that would have stopped both large email frauds above.

Next step

Thirty minutes, and you will know what applies to you.

No charge, no obligation and no fear-selling. Bring your self-check result, or nothing at all.

  • Which obligations on this page are law for your business, and which are only recommended
  • The three fixes that remove the most risk, in order
  • If testing is worth doing, a written scope and a fixed price — with a retest included
  • If it is not worth doing yet, we will tell you so
Book the call We reply within 24 business hours.

A plan you can run

The first ninety days, in the order that protects most

Written for a firm with no security team and an ordinary budget. Most of the first month is settings and habits, not purchases.

  1. Week 1

    Protect the money

    • Write down the call-back rule for bank-detail changes, and tell every supplier you follow it
    • Turn on multi-factor login for email, banking, GST and cloud accounts
    • Stop sharing OTPs — the GST portals already send them to the registered mobile
    • Pin up the first-hour card: 1930, cybercrime.gov.in, your bank’s fraud line, and the FBI’s IC3 portal if the money went to a US account
  2. Weeks 2–4

    Close the obvious doors

    • Take remote desktop and remote-support tools off the open internet, or put them behind a VPN with multi-factor login
    • Change default passwords on routers, CCTV recorders and printers
    • Set up one offline backup and restore a file from it
    • Update Windows, the accounting software, the website and every plugin
  3. Month 2

    Meet the legal basics

    • Name the person who reports to CERT-In within six hours, and register your point of contact
    • Keep email, firewall and server logs for 180 days
    • Write a two-page security policy that says who owns what
    • Run phishing and payment-fraud awareness training for everyone, owners included
  4. Month 3

    Prove it

    • Have your website and internet-facing systems independently assessed
    • List every outsider who can log in, and remove the ones who should not
    • Map where personal data sits, ahead of the DPDP Act’s May 2027 duties
    • Keep the evidence — it answers the next customer questionnaire

Where SemperWise fits

Help sized for a small firm

We are a registered MSME ourselves, so we scope for a budget that has to be spent precisely. Every engagement starts with a 30-minute call and ends with a fixed, written price.

“Is our website or remote access an open door?”

Service

A tightly scoped vulnerability assessment and penetration test of your website and whatever faces the internet. Every finding is confirmed by a person, and a retest is included.

VAPT for a small scope

“Our site runs on WordPress or WooCommerce.”

Service

Plugin, theme and hosting review, hardened against the flaws that actually get small shops defaced or skimmed.

WordPress security

“We have no security person.”

Service

A named senior practitioner for a few days a month — policy, the CERT-In basics, supplier questionnaires and help on the bad day — as a subscription.

Virtual CISO

“Staff keep clicking.”

Service

Short, practical sessions built around the frauds on this page — changed bank details, swapped QR codes, fake GST notices — twice a year, as CERT-In recommends.

Security training

“A big customer sent us a security questionnaire.”

SemperWise One™

Answer it once with evidence, keep those answers in a library that retires them when the evidence expires, and reuse them for the next customer.

Questionnaire automation

“The customer wants proof we were tested.”

SemperWise One™

An assessment certificate at a live link that states the scope and where remediation stands, updated as fixes land — not a PDF that goes stale.

Assessment certificates

“What does the DPDP Act mean for a firm our size?”

Service

A fixed-scope readiness assessment: what personal data you hold, what the Act and the 2025 Rules require of you, and a plan dated to May 2027.

DPDP readiness

“We cannot keep track of what faces the internet.”

SemperWise One™

Continuous discovery of your domains, services and exposed logins in SemperWise One, so a newly exposed remote-desktop port is noticed the day it appears.

Attack surface management

Plain words

The terms you will be asked about

Udyam registration
The government portal that classifies a business as micro, small or medium under the MSME Act.
CERT-In
The Indian Computer Emergency Response Team — the national agency for cyber incidents, under the Ministry of Electronics and IT.
Elemental Cyber Defense Controls
CERT-In’s September 2025 baseline for MSMEs: 15 controls and 45 recommendations. Recommended, not mandatory.
CERT-In-empanelled auditor
A firm CERT-In has approved to carry out security audits. Required only where a regulator, government buyer or contract says so.
The six-hour rule
The duty under the April 2022 CERT-In Directions to report listed incidents within six hours of noticing them.
Business email compromise (BEC)
Fraud that uses a hijacked or lookalike email address to redirect a legitimate payment.
SPF, DKIM and DMARC
Email records that tell receiving servers which mail genuinely comes from your domain. DMARC is the one that lets you refuse the rest.
QR swap
Replacing or editing a merchant’s UPI QR code so that payments reach a fraudster’s account.
1930 and NCRP
The national cyber-fraud helpline, and the National Cyber Crime Reporting Portal at cybercrime.gov.in.
Cyber Swachhta Kendra
CERT-In’s botnet cleaning and malware analysis centre, which issues free alerts and tools.
Data Fiduciary
Under the DPDP Act, whoever decides why and how personal data is processed — including a clinic, a CA firm or a trader.
Multi-factor login
Signing in with something you know plus something you have, such as an OTP or an app prompt, so a stolen password alone is not enough.

Questions

MSMEs security — answered.

What buyers in this sector ask us before they commit to anything.

Is a cyber security audit mandatory for MSMEs in India?

Not in general. CERT-In’s 15 Elemental Cyber Defense Controls, published on 1 September 2025, say MSMEs “may” assess themselves and “may” have a CERT-In-empanelled auditor carry out a baseline audit once a year — a recommendation, not a requirement. An audit becomes mandatory for you when a regulator, a government buyer or a customer contract demands one. What is already law for every company is the April 2022 CERT-In Directions: six-hour incident reporting, 180-day logs and a named point of contact. SemperWise is not CERT-In empanelled; where a contract requires an empanelled auditor, we prepare you for that audit and say so up front.

What are CERT-In’s 15 Elemental Cyber Defense Controls?

They are CERT-In’s minimum baseline for MSMEs: effective asset management; network and email security; endpoint and mobile security; secure configuration; patch management; incident management; logging and monitoring; awareness and training; third-party risk management; data protection, backup and recovery; governance and compliance; a “Robust Password Policy”; access control and identity management; physical security; and vulnerability audits and assessments. Together they carry 45 numbered recommendations, from asset inventories to an annual independent vulnerability assessment. The self-check on this page asks one plain question per control.

Does the DPDP Act apply to small businesses?

Yes. The Digital Personal Data Protection Act has no turnover or size threshold, so a clinic’s patient records, a CA firm’s client files and a trader’s customer list are all in scope if they are held digitally. Section 17(3) lets the government exempt notified classes of business, startups included, from some duties — but none has been notified, and the exemption cannot remove the duty to keep reasonable security safeguards or to report a breach. The main obligations apply from about 13 May 2027. Penalties reach ₹250 crore, though the Board must weigh a penalty’s likely impact on the business. A DPDP readiness assessment sizes the work for a firm like yours.

What should I do in the first hour after a payment goes to a fraudster?

Call 1930, the national cyber-fraud helpline, or file on cybercrime.gov.in straight away, then call your bank’s fraud line and ask for the transfer to be recalled or the receiving account frozen. If the money went to a US account, also file with the FBI’s IC3 portal — that is how the Indore company got its ₹3.72 crore back. Keep every email and header; do not delete anything. If the fraud involved unauthorised access to your email or systems, assess whether it is on CERT-In’s list of reportable incidents, because that clock is six hours. Speed is what separates a recovery from a loss.

How can shopkeepers avoid UPI QR code fraud?

Check the QR code at the counter every morning: scan it with your own phone and confirm the name that appears is your business. Keep QR standees where staff can see them, and replace any that look re-stuck or reprinted. Never send a customer a QR image over WhatsApp as a payment request without confirming it is your own, and never accept a customer’s screenshot as proof — confirm on your soundbox, bank app or settlement statement. The Delhi case that came to light in December 2025 involved edited QR codes that looked identical to the originals, so the name check is what matters, not how the code looks.

Is there a government scheme or subsidy for MSME cyber security?

We could not find a central one. The Ministry of MSME’s 2025–26 scheme booklet does not mention cyber security at all, and lists its Digital MSME scheme as yet to be launched. What does exist is free: CERT-In’s Cyber Swachhta Kendra alerts and tools, government awareness sessions, and the 1930 helpline and cybercrime.gov.in for reporting fraud. Some state governments run their own programmes, so check with your state’s MSME or IT department before you spend. Be wary of anyone selling a “government-mandated” package; the MSME controls themselves are voluntary.

How much does a cyber security assessment cost for a small business?

It depends almost entirely on scope — one website, or a website plus remote access, an office network and a cloud account — which is why we do not publish a price list: any single number would be wrong for most readers. We scope in a 30-minute call at no charge, then send a written scope and a fixed price, with a retest of fixes included. For most small firms the right first purchase is small: an assessment of the website and whatever else faces the internet. If we think you do not need testing yet, we will tell you what to do instead.

Must a small business report a cyber attack to CERT-In within six hours?

The April 2022 CERT-In Directions apply to every “body corporate”, and the IT Act’s definition of that term includes firms and sole proprietorships engaged in commercial or professional activity — confirm the reach for your own structure with counsel. The Directions list twenty reportable incident types, including targeted scanning, phishing, website defacement, malicious code such as ransomware, data breaches and leaks, and unauthorised access to social-media accounts, and the report is due within six hours of noticing the incident. Decide in advance who files it and keep CERT-In’s reporting details somewhere everyone can find them; a six-hour clock is not the moment to look them up.

Our CA or IT vendor handles all of this. Isn’t that enough?

It helps, but it concentrates risk. The person who handles your GST, bank and e-way bill logins holds the keys to the accounts fraudsters want most, and a single compromised mailbox at a CA firm exposes every client at once. Give outside advisers their own logins rather than yours, turn on multi-factor login everywhere it exists, and review who has access every quarter, as CERT-In’s baseline recommends. Ask your IT vendor to show you — not tell you — that backups restore and that remote access is protected. Their good intentions are not evidence.

Sources

Checked by our research desk on 23 September 2026. Regulations and figures move; where a number here matters to a decision, follow it to the source.

  1. 15 Elemental Cyber Defense Controls for Micro, Small, and Medium Enterprises (MSMEs), v1.0 — CERT-In, 1 September 2025
  2. Directions under sub-section (6) of section 70B of the IT Act, 2000 — CERT-In, 28 April 2022
  3. Information Technology Act, 2000 (section 70B) — Ministry of Electronics and IT
  4. 2026 Data Breach Investigations Report (SMB analysis, p. 97) — Verizon, 2026
  5. Indians lost ₹22,845 crore to cyber fraud in 2024, a 206% rise — Scroll, reporting a Home Ministry reply in the Lok Sabha, July 2025
  6. Dr Reddy’s foils email spoofing scam, ₹2.16 crore recovered by Bengaluru police — Medical Dialogues, January 2026
  7. Cyber Cell recovers ₹3.72 crore lost by city company in international cyber fraud — Free Press Journal, December 2025
  8. Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) — MeitY, 13 November 2025
  9. Digital Personal Data Protection Act, 2023 — MeitY
  10. Multi-factor authentication on e-invoice and e-way bill portals mandatory for all taxpayers from 1 April 2025 — Taxmann, reporting a GSTN advisory
  11. QR code scam: 19-year-old arrested for diverting UPI payments — News Karnataka, December 2025
  12. India Ransomware Report 2024 — CERT-In, March 2025
  13. CERT-In backgrounder: incidents handled in 2025 — Press Information Bureau, 2026
  14. Udyam registrations up to February 2026 — Press Information Bureau / Ministry of MSME, 2026
  15. India records its highest average cost of a data breach — Cost of a Data Breach Report 2026 — IBM, 3 August 2026
  16. MSME scheme booklet 2025–26 — Office of the Development Commissioner (MSME)
  17. National Cyber Crime Reporting Portal — Indian Cyber Crime Coordination Centre, Ministry of Home Affairs

All 17 industries we serve

Next step

Find out what applies to you, in one call.

Thirty minutes and no charge. You leave knowing which obligations are law for your business, which are only recommended, and the three things worth fixing first. If testing makes sense, you get a written scope and a fixed price.