In-depth research and expert guidance from the Shridhar InfoSec Solutions R&D Wing.
The Digital Personal Data Protection Act, 2023 applies in full to India's MSMEs, yet most small manufacturers, retailers and service businesses were never built with a legal or privacy function capable of meeting that obligation. Research finds this gap to be structural: one survey found only 2.5% of MSMEs understand the Act, while compliance costs can range from ₹5–25 lakh to over ₹50 lakh for data-heavy operations, against penalties of up to ₹250 crore for non-compliance.
Operational technology (OT) and industrial control system (ICS) environments carry a distinct cyber-physical risk profile that ordinary IT security guidance does not fully address. This research finds that MSMEs operating OT/ICS infrastructure face many of the same threats as large critical-infrastructure operators, yet authoritative frameworks such as NIST SP 800-82, ISA/IEC 62443 and CISA guidance are operationalized for MSME-scale implementation in only a limited number of areas, chiefly network segmentation.
Organisations with shared IT responsibility and no dedicated 24x7 security operations centre now face two detection problems on the same desk. The first is familiar: endpoints, mail, identity and cloud. The second is newer: unofficial AI tools, model and data provenance, and agents that can write records, send mail or initiate payments. Major frameworks describe both problems, but none specifies a first sequence that a thinly staffed Indian organisation can run without adding a second console nobody opens.