Skip to main content

      Cyber security has become a strategic business imperative as organisations navigate an increasingly complex landscape shaped by AI-driven attacks, expanding digital ecosystems and growing regulatory expectations. As enterprises accelerate digital transformation, cyber security is evolving beyond traditional defence mechanisms to focus on resilience, trust and proactive risk management. The convergence of cloud, data, AI and interconnected third-party ecosystems is creating new opportunities, while simultaneously increasing the need for stronger governance, visibility and protection.

      This transformation is being accelerated by the rise of AI-enabled cyber threats, increasing data protection requirements and evolving national security considerations. Organisations are leveraging AI to strengthen detection, response and recovery capabilities, while enhancing security across data, infrastructure and digital operations. At the same time, regulators are placing greater emphasis on customer data protection, cyber resilience and third-party risk management, requiring organisations to build security into the core of business and technology strategies.

      business

      Cyber resilience and digital trust

      Strengthening organisational resilience against evolving cyber threats

      security

      AI-powered cyber defence

      Leveraging AI to enhance threat detection, response and security operations

      phonelink_lock

      Data protection and governance

      Building trust through stronger data security, privacy and regulatory compliance

      At the same time, cyber security is increasingly being shaped by broader technology, ecosystem and national security considerations.

      • AI-accelerated threat management

        Improving detection, monitoring and incident response capabilities 

      • Customer data protection and governance

        Strengthening security, privacy and trust frameworks 

      • Cyber resilience for critical infrastructure

        Protecting data centres and digital ecosystems against emerging risks 

      • Third-party risk management

        Enhancing oversight across interconnected business and technology networks 

      • Technology-enabled fraud and investigation capabilities

        Supporting intelligence-led cyber and forensic responses 

      • Identity and access risk management

        Strengthening controls around privileged and invisible access pathways 

      • Sovereign AI and national security considerations

        Addressing strategic risks associated with emerging technologies 

      • Data-driven security strategies

        Improving visibility, governance and decision-making across the enterprise

      Latest insights

      A study of how Cyber GCCs help global organisations ‘secure in India’ and evolve into strategic hubs for cybersecurity leadership, and resilience

      Key insights into RBI's cybersecurity, technology: Risk, resilience and assurance framework and digital payment security controls directions

      Evolving regulatory landscape around dark patterns signals a shift towards greater accountability for how consumer choices are designed and presented

      Artificial intelligence (AI) as the intelligence layer of India's financial ecosystem

      Inspired by Aristotle’s ethics, Leonardo da Vinci’s systems thinking, and modern AI risk science

      Digital Personal Data Protection (DPDP) Insights

      Evolving DPDP landscape and its impact

       

      Digital Personal Data Protection (DPDP)

      Driving growth with Cyber Security trends

      Srinivas Potharaju

      Partner, Head of Cyber Security and Technology

      KPMG in India

      In an environment marked by technological disruption, evolving cyber threats and rapid AI adoption, cyber GCCs in India have evolved into trusted partners for cybersecurity and digital risk management. They are increasingly leading innovation, strengthening resilience and enabling global organisations to navigate complexity with confidence. As their role continues to expand, cyber GCCs are poised to play a defining role in shaping the future of secure and resilient global organisations.

      Srinivas Potharaju

      Partner, Head of Cyber Security and Technology

      KPMG in India

      • The CEA's Cyber Security Regulations 2026 signal a clear shift from compliance-led security to resilience-driven operations, with greater emphasis on OT security, supply chain oversight, incident readiness, and data sovereignty.

      • Cyber security can no longer be viewed as a standalone technology function. With operational continuity, grid reliability, and national infrastructure increasingly dependent on secure digital systems, the CEA Cyber Security Regulations 2026 places resilience at the centre of the sector's transformation journey.

      Sony Anthony

      Partner and Head of Department – Cyber Defence and Incident Response

      KPMG in India

      Operational resilience and cyber resilience are now inseparable. As industrial environments become increasingly connected, organisations must move beyond traditional security approaches and embed cyber resilience into the design, operation, and lifecycle of critical systems. Effective OT security is fundamental to ensuring safe, reliable, and sustainable operations in an increasingly digital world.

      Anish Mitra

      Partner, Cyber Defense & IR
      KPMG in India        

      The future of grid resilience is inseparable from cyber resilience with increasing interconnectivity across and digital operations. Organisations that proactively strengthen OT governance, secure their supply chains, and modernise cyber defenses will be better positioned to protect critical services and build stakeholder confidence in an increasingly connected ecosystem.

      Atul Gupta

      Partner and Head - Digital Trust and Cyber

      KPMG in India

      Fintech has played a significant role in the Indian economy and wider societal inclusion. Digital fraud has also grown along with the ease of payments and need is to have measures deployed to enhance trust on a sustained basis.

      Sameer Saini

      Partner, Cyber Transformation CTFR
      KPMG in India    

      While data sovereignty is critical, digital sovereignty is a much broader challenge encompassing technology, infrastructure, resilience, innovation, and trust. As cyber threats continue to evolve across borders, meaningful progress will depend on stronger international cooperation, shared cyber intelligence, and trusted partnerships.

      India is uniquely positioned to lead this dialogue, demonstrating through its digital transformation journey how secure, inclusive, and scalable digital ecosystems can also serve as a model for the Global South.

      Vaibhav Pachori

      Partner, Cyber Strategy & Governance
      KPMG in India        

      As AI becomes embedded in credit decisions, fraud detection, payments, customer engagement, and financial inclusion, the conversation highlighted a few powerful themes:

      • AI is rapidly becoming part of the financial system's critical infrastructure, making resilience and security a national priority.
      • Cybersecurity must evolve beyond protecting data to protecting algorithms, models, and AI-driven decisions.
      • Deepfakes, synthetic identities, and adversarial AI are redefining the threat landscape, requiring stronger digital identity and trust frameworks.
      • Innovation and regulation must move together. Governance, transparency, and accountability can no longer be afterthoughts.
      • Trust remains the ultimate currency. Citizens do not need to understand every algorithm, but they must have confidence that AI-driven decisions are fair, secure, and accountable.

      India has a unique opportunity to demonstrate that innovation, cybersecurity, privacy, and public trust are not competing priorities, but mutually reinforcing foundations of a resilient digital economy.

      As we build the AI economy, one message stood out above all: Trust should be our greatest asset, not our biggest vulnerability.

      Kunal Pande

      National Leader - Cyber, Risk and Compliance Services

      KPMG in India

      As smaller businesses accelerate their digital journey, trust concerns often stem from:
      • gaps in access controls,
      • oversharing of sensitive data, and
      • misconfigured security systems.

      The conversation should move beyond investing in security solutions. Lasting trust is built when organisations exercise sound judgement over their data and ensure security controls are configured and managed effectively

      Akhilesh Tuteja

      Partner & National Leader - Clients and Markets and Technology, Media & Telecommunications (TMT)

      KPMG in India

      • The Proportionality of Risk: The likelihood of a cyber attack is directly proportional to the value of the enterprise. The greater the value you create, the larger the target on your back. High-value targets require high-caliber defense.
      • The Reality of Exposure: In a hyper-connected ecosystem, hyper-exposure is the default. Traditional boundaries are gone, and assuming you are safe because you are "hidden" is a dangerous fallacy.
      • The Widening 'Cyber Poverty Line': We are seeing a deeply concerning trend where more organisations are falling below the Cyber Poverty Line. The gap between those who understand cyber risks & can defend themselves effectively, and those who cannot is widening, creating massive systemic vulnerabilities.
      • Response Over Just Prevention: While prevention is undeniably important, an obsession with perfect prevention is a trap. Preparedness to respond and recover is equally, if not more critical. True resilience isn’t just about stopping the hit; it’s about how fast you get back up.

      Manish Tembhurkar

      Partner, Cyber Defense & IR
      KPMG in India

      Digitalisation is no longer optional for power plants because it drives efficiency, reliability, predictive maintenance, and renewable integration. However, every digital connection introduces cyber risk. The challenge is not whether to digitalise, but how to digitalise securely.
      Kunal Pande

      National Leader - Cyber, Risk and Compliance Services

      KPMG in India

      In an era where every click, nudge, and interface decision can influence customer behavior, transparency and fairness must be engineered into the user journey itself. India Dark Patterns Guidelines mark a pivotal shift requiring such capabilities to be embedded into the digital journeys ensuring that digital experiences empower users, not exploit them.

      Rohan Padhi

      Partner, National Co-Lead, Digital Risk and Cloud Security

      KPMG in India

      Given the proliferation of digital channels in driving modern day commerce, the Dark Pattern guidelines are important guardrails for protecting the consumer’s interest. With these guidelines in place, India joins a select group of nations which have enforced this.

      Sony Anthony

      Partner and Head of Department – Cyber Defence and Incident Response

      KPMG in India

      As the DPDP Act begins to take effect, organisations are starting to look beyond compliance and focus more deeply on accountability, governance, and trust in how data is managed.

      The line between vulnerability discovery and weaponisation has collapsed exponentially. If the security posture still relies on manual triage and weekly patch cycles, you're treating an AI-speed problem with a human-speed solution.

      The metric for success is no longer how fast we find exposure, it's how rapidly we translate that intelligence into actionable, risk-based resilience

      Rupak Nagarajan

      Partner, Cyber Strategy & Govn
      KPMG in India

      The DPDP Act marks a fundamental shift in how organisations think about handling personal data. The conversation is moving beyond compliance towards building trust, strengthening governance and responsible innovation.

      For businesses navigating an increasingly digital ecosystem, privacy is becoming a strategic differentiator that provides competitive advantage.

      Kunal Pande

      National Leader - Cyber, Risk and Compliance Services

      KPMG in India

      Businesses are experiencing meaningful value from AI, most are concerned about data security, privacy and AI induced risks.

      Recent RBI advisories rightly focuses on the two important aspects:

      • Having strong governance for responsible and safe use of AI and
      • Strengthening capabilities against AI accelerated cyberattacks.
      Rohan Padhi

      Partner, National Co-Lead, Digital Risk and Cloud Security

      KPMG in India

      The rapid advancement of AI technologies has proved to be a double-edged sword for organisations. While there are significant business benefits to be accrued, organisations need also to double down on their preparedness in terms of robust governance and sound cyber security practices for managing AI-led cyber threats.

      Romharsh Razdan

      Partner, Digital Trust

      KPMG in India

      One reality is becoming impossible to ignore: AI-enabled threats are moving faster than traditional control environments. 

      For India’s financial services sector, where expectations from financial services regulators continue to evolve, resilience now requires dynamic, intelligence-led controls across the technology lifecycle - supported by stronger alignment across business, risk, compliance and engineering teams.

      AI risk can no longer be managed as a point-in-time compliance checkpoint. It must be treated as an enterprise resilience priority - one that strengthens trust, reduces exposure and enables responsible innovation.

      The question for leaders is simple: are our AI risk controls keeping pace with the speed of AI adoption?

      Kunal Pande

      National Leader - Cyber, Risk and Compliance Services

      KPMG in India

      As organisations accelerate adoption of AI, cloud, and emerging technologies, the conversation today is no longer just about transformation - it is about enabling trusted and responsible transformation at scale.

      Organisations need to implement secure-by-design practices, continuous monitoring, automation for rapid response action as well as technology-enablement of governance for machine speed decisioning to confidently innovate with greater speed, resilience, and trust. In a cloud environment, one additionally requires a clear understanding of shared responsibility model, deploying right security controls and crucially maintaining unified view of the entire environment.

      Akhilesh Tuteja

      Partner & National Leader - Clients and Markets and Technology, Media & Telecommunications (TMT)

      KPMG in India

      Cybersecurity budgets are often built on legacy structures, not real risk. The result is a disconnect between where organisations invest and where their true exposure lies.

      A risk based approach shifts this conversation. It starts by aligning every investment to a clearly defined and quantified risk, ensuring that spending directly contributes to reducing exposure. It also calls for adaptability, where budgets evolve alongside changing threats, and transparency, where every stakeholder can see the link between spend and outcomes.

      This is not just a financial exercise. It is a fundamental shift in how organisations think about cybersecurity. Moving from static line items to risk led priorities enables smarter allocation, stronger resilience, and clearer communication with leadership.

      When budgets are tied to measurable risk reduction, cybersecurity stops being a cost discussion and becomes a value conversation.

      Kunal Pande

      National Leader - Cyber, Risk and Compliance Services

      KPMG in India

      • In our 'always-on' world, digital trust is earned when a service is not just convenient, but consistently available and inherently secure. Beyond the code, trust is psychological - a user’s confidence that a system will act in their best interest without cause for harm. Building digital trust today requires a convergence of reliability, resilience, and an infrastructure agile enough to pivot with business needs while responding instantly to security events. Ultimately, this trust is solidified through robust communication, ensuring the user is not only protected but remains consciously aware and confident in the system’s integrity.
      • Digital trust is the intersection of technical security and resilience, and psychological safety. It is built when 'fit-for-purpose' services are consistently secure and available, backed by an infrastructure that can adapt to user needs and security threats at lightning speed. To trust a system is to believe it will act in our interest, every single time.
      Akhilesh Tuteja

      Partner & National Leader - Clients and Markets and Technology, Media & Telecommunications (TMT)

      KPMG in India

      Human intelligence has driven modern economies; the next phase of growth will depend on how well we harness intelligent data. As this report suggests, data risk is market risk. Treating data as core market infrastructure is critical for India to sustain market leadership and investor confidence.

      Rachit Chhokera

      Partner, DT-Cyber Strategy and Govn
      KPMG in India

      Cross-border data governance is where GCCs face real complexiity. Some of the key friction points that need deeper attention.

      • Global vs local rules:Aligning HQ‑led data policies with country‑specific privacy, retention, and localisation laws
      • Data visibility: Achieving accurate data discovery and lineage across systems to prove compliance end-to-end
      • Third-party risk: Governing vendors and processors operating across borders, with inconsistent controls and oversight.
      Atul Gupta

      Partner and Head - Digital Trust and Cyber

      KPMG in India

      • Ambiguity is the new operating environment for CEOs. Navigating fluid global dynamics has become a core leadership capability.
      • Resilience is now a strategic differentiator. Organisations that can anticipate, absorb and adapt to shocks will define the next decade.
      • Trust is emerging as an economic currency. In a world of rapid digitalisation, trust-driven ecosystems will outperform those built purely on scale or efficiency.
      • Innovation must move from the periphery to the core. It can no longer be experimental—it has to be embedded, continuous and enterprise-wide.
      • Talent strategies need a reset. Leaders must enable teams to thrive amid constant change, not just manage it.
      • Business disruption cycles are compressing. With new and unfamiliar risks emerging, risk intelligence and forward visibility are critical.
      • AI represents a generational shift. Its true potential will be realised only when it becomes more human-centric, ethical and responsible.
      • Digital and data sovereignty are gaining prominence. Yet, India is uniquely positioned to leverage this moment and accelerate its journey toward Viksit Bharat.

      Hear from the experts

      For MSMEs, trust is built on getting the fundamentals right. As smaller businesses accelerate their digital journey, trust concerns often stem from gaps in control, oversharing of sensitive data and misconfigured security systems

      Indian enterprises are shifting cybersecurity strategies from defense to building confidence, focusing on preparedness, transparent responses, and addressing human and procedural vulnerabilities.

      Digital trust has become a crucial business imperative for GCCs navigating the complexities of cross-border data governance, requiring alignment with global and local regulations, enhanced data visibility, and management of third-party risks.

      Akhilesh Tuteja shares his insights on cybersecurity skills in an AI-first world.

      Insights from the new 2026 KPMG global TPRM study

      While the large corporations in India may be ready for the new DPDP rules, the ecosystem of partners, vendors, suppliers may not be ready, this is one of the significant holes in the entire readiness for our country.

      Akhilesh Tuteja in conversation with Business Standard on the new DPDP Rules.

      Akhilesh Tuteja shares his insights on the new DPDP rules 2025 with The Core.

      Watch the webinar to understand how to run compliance into advantage and build a credible privacy foundation

      Cybersecurity is no longer what it used to be. Attackers use AI for deepfakes, blurring truth and fiction. AI systems change by design, complicating protection. Risks come from outside organisations, by targeting small companies to attack big systems.

      Akhilesh Tuteja shares his insights on the Data Protection Act in India.

      Threat intelligence hub

      Real-time access to research-based visibility into cyber threats

      Real-time access to research-based visibility into cyber threats

      Explore our Cyber Security insights

      Something went wrong

      Oops!! Something went wrong, please try again

      Global insights

      IDC recognizes KPMG member firms for their lifecycle OT security services, combining deep operational expertise, structured delivery, and advanced innovation

      Fresh ideas for enterprise security in an era of AI and growing risk

      KPMG’s AI Governance Principles for Boards provide a practical, principles-led framework to support board directors as they navigate this evolving landscape.

      A new imperative for a changing risk landscape

      In a volatile global economy, progressive companies do more than survive the impact. They’re transforming operations to thrive in it. One way is by boldly grabbing onto AI, from generative to agentic.

      Connect with us

      Contact our specialists for more information

      connect with us