Skip to content

Free, independent software advice for Indian businesses

App Advisor logoApp Advisor

Cybersecurity for Indian SMEs 2026: CERT-In Guide

SME cybersecurity in India: CERT-In 6-hour reporting and 180-day logs, endpoint and email security, Microsoft Defender INR prices and a phased roadmap.

Updated 14 September 2026 13 min read 2,580 words 8 sourcesBy App Advisor Research

Rack-mounted network switches and patch panels with neatly routed Ethernet cables
Rack-mounted network switches and patch panels with neatly routed Ethernet cables. Photo: Dsimic · CC BY-SA 4.0 · Wikimedia Commons

Software covered in this blog

An Indian SME can reach a strong, compliant security baseline for a modest per-user monthly cost. That baseline has five parts: endpoint protection on every device, hardened business email with MFA, tested backups, centralised logs kept for 180 days in India, and a written plan to report cyber incidents to CERT-In within 6 hours. Microsoft's India page lists Defender for Business at ₹250 per user per month and Microsoft 365 Business Premium, which bundles email, device management and Defender, at ₹1,830 per user per month, both paid yearly. Indian vendors such as Quick Heal and Seqrite, and global vendors such as Sophos, ESET, Bitdefender and CrowdStrike, are the other common shortlists. This guide explains what the law requires, what to buy first, and what it costs.

Executive summary

  • CERT-In's Directions apply to ordinary companies. The April 2022 Directions cover "body corporate". They require incident reporting within 6 hours, ICT logs kept for 180 days within India, and clock sync with NIC/NPL NTP servers.
  • Email and identity come first. Most SME incidents start with a phished password or a spoofed invoice. Enforced MFA, SPF/DKIM/DMARC and admin audit logs are the cheapest controls with the highest impact.
  • Endpoint protection has moved from antivirus to EDR. Microsoft Defender for Business is listed at ₹250/user/month (paid yearly). Many vendors do not publish SME business prices on the pages we accessed, so you need quotes.
  • Bundles often beat point tools on cost. If you need Microsoft 365 anyway, Business Premium (₹1,830/user/month, paid yearly) combines productivity, Intune device management and Defender.
  • The DPDP Act raises the stakes. Data fiduciaries must protect personal data with reasonable security safeguards. The DPDP Rules, 2025 roll out over an 18-month phased timeline.

Market context

What the CERT-In Directions require

The CERT-In Directions of 28 April 2022, issued under Section 70B(6) of the IT Act, 2000, require:

  1. Clock synchronisation: "All service providers, intermediaries, data centres, body corporate and Government organisations shall connect to the Network Time Protocol (NTP) Server of National Informatics Centre (NIC) or National Physical Laboratory (NPL) or with NTP servers traceable to these NTP servers."
  2. 6-hour reporting: these entities "shall mandatorily report cyber incidents as mentioned in Annexure I to CERT-In within 6 hours of noticing such incidents or being brought to notice about such incidents". Reports can go to incident@cert-in.org.in, among other channels listed.
  3. Log retention: logs of all ICT systems must be maintained securely "for a rolling period of 180 days" and "within the Indian jurisdiction".
  4. Provider KYC: data centres, VPS providers, cloud service providers and VPN providers must keep validated subscriber information for 5 years or longer.

Annexure I lists incident types, including targeted scanning, compromise of critical systems, unauthorised access to IT systems or data, website defacement, malicious code attacks including ransomware, identity theft and spoofing, and data breaches. CERT-In also published FAQs on the Directions. Its Directions page also links a notice extending enforcement timelines for MSMEs, and CERT-In publishes elemental cyber defence controls for MSMEs there.

DPDP Act, 2023

The Digital Personal Data Protection Act requires data fiduciaries to take reasonable security safeguards to prevent personal data breaches. The DPDP Rules, 2025 set out breach notification and other procedures, with an 18-month phased compliance timeline, according to the Government's press release. For SMEs, customer databases, HR records and email are the main personal data stores to protect.

We have not relied on any private survey for statistics on attack frequency or cost in India. We explain risks qualitatively.

Evaluation framework

App Advisor's methodology for SME cybersecurity stacks:

CriterionWeightWhat we look for
Coverage of top SME attack paths25%Phishing, credential theft, ransomware, unpatched devices, misconfigured cloud sharing
Compliance support20%Log retention/export for 180 days in India, incident timelines, audit reports
Manageability for small IT teams20%Single console, automated response, sensible defaults, managed service availability
Cost transparency15%Published INR prices, per-user vs per-device, bundle value
Detection and response depth10%EDR, isolation, rollback, threat hunting options
Local support10%India support hours, partner network, language

Vendor comparison

The minimum control stack

LayerControlExample products on App Advisor
IdentityMFA for all, SSO, admin separationMicrosoft Entra ID, JumpCloud, Zoho Vault (passwords)
EmailPhishing and malware filtering, SPF/DKIM/DMARC, audit logsMicrosoft 365, Google Workspace, Zoho Mail. See business email guide
EndpointEDR/antivirus, disk encryption, patchingMicrosoft Defender for Business, Seqrite, Quick Heal, Sophos, ESET, Bitdefender, CrowdStrike Falcon
Device managementEnrol, enforce policies, remote wipeMicrosoft Intune, ManageEngine Endpoint Central
LoggingCentralised logs, 180-day retention in IndiaManageEngine Log360
BackupOffline/immutable copies, restore testsSee backup and disaster recovery guide

Official prices we could verify

ProductOfficial priceNotesSource
Microsoft Defender for Business₹250.00 user/month, paid yearly (annual subscription, auto-renews)Standalone device protectionMicrosoft India
Microsoft 365 Business Premium₹1,830.00 user/month, paid yearlyProductivity + security bundleMicrosoft India
Microsoft 365 Business Premium (no Teams)₹1,565.00 user/month, paid yearlySame bundle without TeamsMicrosoft India
Quick Heal Total Security (consumer)₹1,591.00 for 1 user, 1 year (shown against ₹1,909.00)Consumer product, for context onlyQuick Heal
Seqrite Endpoint Protection (business)Not published on the page we could accessQuote via partnersSeqrite
Sophos, ESET, Bitdefender, CrowdStrike business plansNot verified for this articleRequest quotes in INRVendor sites

Explore more tools in the cybersecurity category, the IT management category and the password manager category.

Mapping CERT-In incident types to SME controls

Annexure I of the Directions lists the incident types that must be reported. The table below links the ones SMEs most commonly face to the control that prevents or detects them.

Annexure I incident type (as listed)Typical SME scenarioPrimary preventive controlDetection source
Unauthorised access of IT systems/dataEx-employee still logs into accounting softwareOffboarding checklist, MFA, password managerApplication and identity logs
Identity theft, spoofing and phishing attacksFake supplier email changes bank detailsDMARC, email filtering, payment call-back ruleEmail security reports, user reports
Malicious code attacks (including ransomware)Staff opens an infected attachmentEDR, patching, no local admin rightsEDR alerts
Attack on servers such as database, mail and DNSExposed database or RDP port attackedFirewall rules, VPN, patchingServer and firewall logs
Defacement of website or intrusion into a websiteOutdated CMS plugin exploitedPlugin updates, web application firewallUptime and integrity monitoring
Data breach / data leakPublic link to a customer spreadsheetSharing restrictions, data classificationCloud storage audit logs
Unauthorised access to social media accountsBrand Instagram or Facebook page hijackedMFA, shared credentials in a vaultPlatform security notifications
Attacks or malicious/suspicious activities affecting cloud computing systemsCompromised cloud admin keyLeast-privilege IAM, MFA, key rotationCloud audit logs

Annexure I also lists other categories, including denial-of-service attacks, attacks on IoT devices, attacks affecting digital payment systems, and malicious or fake mobile apps. Read the full list in the Directions.

What a 6-hour report needs

Six hours is short. Prepare a one-page template in advance with:

  • Organisation name, point of contact, phone and email.
  • Time the incident was noticed, and how it was noticed.
  • Incident type, using the Annexure I category.
  • Affected systems, locations and approximate number of users or records.
  • Immediate actions taken (isolation, password resets, blocking).
  • Whether personal data may be involved. This also triggers your DPDP breach-handling process.

Initial reports can be updated as the investigation proceeds. The priority is to report within the window with the facts known at the time.

Security for the owner and the accounts team

In small companies, the owner and the accounts team are the most targeted people, because they can move money. Three rules prevent a large share of real-world losses:

  1. Call back before changing bank details. Any request to change a supplier's or employee's bank account is verified by phone, using a number already on file.
  2. Two-person approval for payments above a threshold in net banking.
  3. Separate devices or browser profiles for banking and general browsing, with MFA on every financial portal.

Buying through a partner

Many SMEs buy endpoint and email security through a managed service provider. Ask the partner to commit in writing to: alert monitoring hours, response time for critical alerts, help with preparing CERT-In reports, monthly reports on patch and EDR coverage, and where log data is stored.

Total cost of ownership

Illustrative model — assumptions stated. A 50-person professional services firm with 50 laptops and existing Google Workspace email. Assumptions:

  • Option A adds Microsoft Defender for Business to all 50 laptops at the listed ₹250/user/month.
  • Option B moves the firm to Microsoft 365 Business Premium at ₹1,830/user/month and drops Google Workspace Business Starter (₹270/user/month from Google's India page).
  • Log management and backup tools: an assumed ₹15,000/month in both options (our assumption; get quotes).
  • Managed security service or IT partner time: an assumed 10 hours/month at ₹1,500/hour in A, and 7 hours in B because of the single console (our assumption).
  • Prices exclude GST.
Year-1 cost lineOption A: Keep Google + add DefenderOption B: Move to M365 Business Premium
Email/productivity50 × ₹270 × 12 = ₹1,62,000Included
Endpoint security50 × ₹250 × 12 = ₹1,50,00050 × ₹1,830 × 12 = ₹10,98,000
Logging + backup (assumed)₹1,80,000₹1,80,000
Partner time (assumed)₹1,80,000₹1,26,000
Migration (assumed one-time)₹0₹1,00,000
Year-1 total (excl. GST)₹6,72,000₹15,04,000

What this shows:

  1. For a firm happy on Google Workspace, adding endpoint protection is far cheaper than switching suites.
  2. Business Premium makes financial sense when you would buy Microsoft 365 anyway and would otherwise pay separately for device management and endpoint security.
  3. People and process costs (partner time, log review) are about a quarter of Option A's total. Do not budget only for licences.

Endpoint security buying checklist

When comparing endpoint products, ask each vendor or partner to demonstrate:

  • Detection and response: isolating an infected device from the console with one action.
  • Ransomware protection: behaviour-based blocking and, where offered, rollback of encrypted files.
  • Device control: blocking or allowing USB storage by policy.
  • Patch visibility: reports on missing operating system and third-party application updates.
  • Coverage: Windows, macOS, Linux servers and mobile devices, as your estate requires.
  • Log export: sending endpoint events to your central log store for 180-day retention in India.
  • Licensing clarity: whether pricing is per user or per device, and what happens when staff use several devices.

Implementation roadmap

Weeks 1–2: Baseline and governance

  • Appoint an incident owner and a deputy. Document the CERT-In reporting route and the 6-hour clock.
  • Inventory devices, accounts, SaaS apps, domains and internet-facing services.
  • Configure NTP on servers, firewalls and network devices to NIC/NPL-traceable sources.

Weeks 3–4: Identity and email

  • Enforce MFA for all users; separate admin accounts.
  • Publish SPF, DKIM and DMARC and monitor DMARC reports.
  • Turn on email and admin audit logging.

Weeks 5–7: Endpoints

  • Deploy EDR to 100% of laptops and servers; enable disk encryption.
  • Enrol devices in management; enforce screen lock and OS updates.
  • Remove local admin rights from standard users.

Weeks 8–10: Logging, backup and response

  • Centralise logs with 180-day retention stored in India.
  • Implement 3-2-1 backups with an offline or immutable copy; test restore.
  • Run a tabletop exercise: phishing leads to ransomware, and the team decides, detects, contains and reports within 6 hours.

Ongoing (monthly/quarterly)

  • Monthly patch compliance review; quarterly phishing simulation; annual policy review and DPDP readiness check.

Risks and compliance checklist

  • CERT-In 6-hour reporting: named owner, contact details and a report template ready.
  • 180-day ICT logs within Indian jurisdiction: firewall, VPN, email, endpoint, cloud and server logs.
  • NTP: all systems synced to NIC/NPL or traceable NTP servers.
  • DPDP Act: personal data inventory; access restricted; breach response procedure aligned to the DPDP Rules.
  • Data localisation: logs kept in India per CERT-In; check sector rules (for example RBI-regulated entities) for other localisation needs.
  • MFA on email, VPN, cloud admin, banking and accounting software.
  • EDR on every endpoint and server; alerts monitored, including out of hours.
  • Backups offline/immutable and tested quarterly.
  • Vendor access: third-party remote access tools controlled and logged.
  • Staff training: phishing awareness at joining and every year.

KPIs to track

KPISuggested target
MFA coverage100% of users and admin accounts
EDR coverage100% of endpoints and servers
Critical patches applied within 14 daysAbove 95% of devices
Mean time to detect / containHours, not days; always inside the 6-hour reporting window
Phishing simulation click rateFalling each quarter
Log sources feeding central store with 180-day retention100% of in-scope systems
Successful restore tests1 per quarter minimum

How to choose

  • Microsoft 365 shop? Evaluate Business Premium first; it may replace three separate tools.
  • Google Workspace shop? Keep it, and add a dedicated EDR (Defender for Business, Seqrite, Sophos, ESET, Bitdefender or CrowdStrike) plus device management.
  • No in-house IT? Buy through a managed security partner who will monitor alerts and help with CERT-In reporting.
  • Regulated data (health, finance)? Prioritise logging, access control and data residency statements. See healthcare software if relevant.

For asset and service management tooling, read our IT asset management and ITSM guide. For team credentials, see password managers for teams.

FAQs

Do CERT-In rules apply to small businesses?

The April 2022 Directions apply to "body corporate", which includes private companies. CERT-In's Directions page links a notice extending enforcement timelines for MSMEs. Take advice on your specific obligations, but plan to meet the 6-hour reporting and 180-day log requirements.

What counts as a reportable cyber incident?

Annexure I of the Directions lists types including targeted scanning, compromise of critical systems, unauthorised access to IT systems or data, website defacement, malicious code such as ransomware, identity theft and spoofing, and data breaches.

How much does Microsoft Defender for Business cost in India?

Microsoft's India page lists Defender for Business at ₹250.00 per user per month, paid yearly.

Is free antivirus enough for an SME?

Usually not. Businesses need central management, EDR-style detection and response, reporting and logs, which consumer or free tools generally do not provide.

Where should logs be stored?

The CERT-In Directions require ICT logs to be maintained securely for 180 days within Indian jurisdiction.

What should we do in the first hour of a ransomware attack?

Isolate affected devices from the network, preserve logs, inform your incident owner and IT partner, start the CERT-In reporting clock, and do not pay or wipe systems before evidence is secured.

Does the DPDP Act require encryption?

The Act requires reasonable security safeguards. Encryption, access control and logging are widely used ways to meet that duty. Check the DPDP Rules and take legal advice for specifics.

Do we need to register a point of contact with CERT-In?

The Directions include a format (Annexure II) for service providers, intermediaries, data centres, body corporate and government organisations to share point-of-contact details with CERT-In by email, and to keep them updated. Name a primary and a deputy contact, so reports and CERT-In requests reach someone quickly.

Sources

Sources cited

  1. CERT-In Directions under Section 70B(6), 28 April 2022
  2. CERT-In Directions page
  3. CERT-In FAQs on Cyber Security Directions
  4. PIB: Digital Personal Data Protection Rules, 2025
  5. Microsoft Defender for Business (India)
  6. Google Workspace pricing (India)
  7. Quick Heal
  8. Seqrite

Found this useful? Share it with your team.

Get a free cybersecurity & endpoint protection shortlist

Free for buyers · no spam. We use your details to handle this request and share them only with the vendors you ask about. Privacy policy · Your rights

Software mentioned in this blog

All cybersecurity & endpoint protection

Explore these categories

Related blogs

Get an instant demo

Let us arrange your demos, free

  • Verified vendors
  • Real feedback before purchase
  • Free trials
  • Special discounts