
Cyber resilience is emerging as a key boardroom metric in India, driven by AI adoption, the Digital Personal Data Protection (DPDP) Act, and growing investor and regulatory scrutiny, reports the Economic Times…
Cyber resilience is emerging as a key boardroom metric in India, driven by AI adoption, the Digital Personal Data Protection (DPDP) Act, and growing investor and regulatory scrutiny, reports the Economic Times CISO. Boards are being urged to shift focus from operational metrics like patches deployed to resilience measures such as recovery time and crisis simulation participation. The DPDP Act places data governance responsibility on boards, not just IT teams.

Simultaneously, RBI and Sebi are intensifying cyber oversight of India’s financial sector, Livemint reports. RBI governor Sanjay Malhotra recently flagged cyber risks as a top threat alongside geopolitics. Regulators are expanding simulation exercises, planning AI-related risk guidelines, and launching shared security centres for smaller entities. RBI reported 10,114 fraud cases in FY26, with the total amount involved rising 46.4% to Rs 48,021 crore.
Two narratives need checking. First, that Indian boards are suddenly awake to cyber risk, the PwC survey says only 2% of organisations have implemented resilience actions, so awareness without action is hollow. Second, that RBI and Sebi are ahead of the curve, while their measures are welcome, the Bank of Baroda breach and rising fraud amounts show enforcement gaps remain. The real test will be whether regulated entities treat these mandates as living drills or just annual compliance tick-boxes.
Sources (2): ciso.economictimes.indiatimes.com, livemint.com
This story was synthesised by AI from the 2 sources linked above.
Updated: this story now draws on 2 sources.