
Cyber resilience is moving from an operational concern to a boardroom priority in India, driven by three factors: rapid AI adoption, the Digital Personal Data Protection (DPDP) Act, and growing scrutiny from…
Cyber resilience is moving from an operational concern to a boardroom priority in India, driven by three factors: rapid AI adoption, the Digital Personal Data Protection (DPDP) Act, and growing scrutiny from investors, customers, and regulators. According to PwC's 2025 Global Digital Trust Insights, while business leaders acknowledge the importance of cyber resilience, only 2% have implemented such actions across their organisations.
The DPDP Act shifts data governance responsibility from IT teams to boards, making cybersecurity a governance issue. Metrics like mean time to detect and respond, disaster recovery success, and executive participation in crisis simulations are replacing outdated operational metrics such as the number of devices monitored. The Economic Times report notes that AI is changing the threat landscape, with attackers using it for phishing and deepfakes, while defenders use it for detection, but warns that automation alone does not create resilience.
The narrative that Indian boards now care about cybersecurity is convenient but incomplete. While the DPDP Act and rising investor scrutiny have pushed the topic onto meeting agendas, the real test is whether boards move past asking about patch counts and start measuring recovery times from a simulated ransomware attack. The gap between awareness, acknowledged even here, and actual resilience actions is a yawning 98%, per PwC's survey. That is not a shift; it is a still-unanswered question. Will the next board meeting review a tabletop exercise, or just another slide deck on threats blocked?
Source: ciso.economictimes.indiatimes.com
This story was synthesised by AI from the source linked above.