Identity Theft, Insider Risks, and AI Threats: The Dark Side of India's Digital Boom While large enterprises are strengthening their cybersecurity infrastructure, small and medium-sized enterprises (SMEs) remain highly vulnerable due to lower cybersecurity maturity

By Shivani Tiwari

Opinions expressed by Entrepreneur contributors are their own.

You're reading Entrepreneur India, an international franchise of Entrepreneur Media.

[L- R] Sandesh G S, CTO, Bureau; Vishal Gupta, Founder & CEO, Seclore; Ashok Hariharan Co-Founder & CEO, IDfy; Arvind, CTO, Sequretek; Somshubhro, Co-Founder and Partner, BIF Ventures (Moderator); Syed Shahrukh, CO- Founder & CTO, CloudSEK

In 2024, India ranked as the second most cyber-attacked nation after the United States. While large enterprises are strengthening their cybersecurity infrastructure, small and medium-sized enterprises (SMEs) remain highly vulnerable due to lower cybersecurity maturity.

Syed Shahrukh Ahmad, Co-founder & CTO, CloudSEK, attributed this rise to financial incentives. "Whenever revenue grows, attackers want a piece of it," he explains. Ahmad also pointed out that third-party vendors and interconnected systems have widened the attack surface, making it easier for hackers to exploit sensitive consumer and enterprise data. "If you are a bank, your risk doesn't stop at your infrastructure. You're sharing data with vendors, agencies, and partners—how do you ensure that data is secure throughout the entire supply chain?" he questioned.

The insider threat

Cyber threats aren't just external—insider risks are growing concerns. Arvind Boggarapu, CTO, Sequretek, explained that India's IT environment is more relaxed compared to the U.S., leading to a higher risk of insider-led breaches. "In the U.S., IT is very much locked down—you cannot install anything without multiple approvals. But in India, IT systems are more flexible, which increases the risk of insider-led attacks," he noted.

Identity theft

Beyond IT breaches, identity theft and financial fraud remain rampant in India. Ashok Hariharan, Founder & CEO of IDfy, revealed that his company has processed KYC for over 300 million individuals and handles 65 million authentications a month. However, data privacy remains a major issue. "You post your house for rent on Magic Bricks, and suddenly you start getting calls from builders and Bajaj Finserv. Where did they get your number? From data brokers," Hariharan pointed out, highlighting the lack of data security in India.

"All fraud problems are data problems. Fraudsters operate in rings, and we need to detect these networks rather than just flagging individual transactions," Sandesh G.S., CTO, Bureau added.

AI: the gatekeeper?

While AI is helping organisations strengthen their cybersecurity, it is also introducing new risks. Vishal Gupta, Founder & CEO, Seclore, warned about the threats posed by AI systems like Large Language Models (LLMs). "The biggest challenge enterprises face with AI is the fear of the unknown. Once an AI system gets access to your data, how do you control what it does with it?" he questioned.

Attackers are also targeting AI models with prompt injection attacks and data poisoning, making them unreliable. "Attackers are trying to poison AI models, making them ineffective or introducing biases that can be exploited," warned Boggarapu. To mitigate risks, organizations must shift to a data-centric security approach. "Instead of protecting networks, devices, or applications, enterprises need to protect the data itself," he further emphasised.

Road ahead

With cyberattacks becoming a new form of warfare, businesses must move beyond reactive security measures and invest in real-time threat detection, AI-driven fraud prevention, and third-party risk management. Regulations like the DPDP Act are pushing enterprises toward stricter data governance, but organisations must proactively enhance their security posture. "Cybersecurity is national security," Boggarapu stated, echoing a sentiment shared by India's Home Minister, Amit Shah. As AI continues to shape cybersecurity, India's ability to adapt, automate, and counter evolving threats will determine its resilience in the digital age.

Panelists shared their opinions at Entrepreneur Tech & Innovation Summit 2025.

Business Ideas

70 Small Business Ideas to Start in 2025

We put together a list of the best, most profitable small business ideas for entrepreneurs to pursue in 2025.

Business News

'The Best Advice That I Could Give Anybody': Billionaire Ray Dalio Credits One Daily Habit With All of His Success

Dalio sets aside forty minutes a day to meditate and has been doing so since 1968.

Science & Technology

This Technology Will Redefine Business by 2027 — Here's How Leaders Can Prepare

Artificial General Intelligence (AGI) is no longer a distant concept; it's poised to redefine how businesses operate by 2027. The next two years will determine who leads the AGI revolution — and who gets left behind.

Growing a Business

5 Books Every Small Business Owner Should Read

Here are five encouraging books for business owners trying to grow their companies.

News and Trends

Biotech Brilliance: Rituja Suraj Chavan, Managing Director of Valient Biotech Pvt Ltd

One of the biggest hurdles in the sugar and ethanol industries is strict government regulations on wastewater management, which require companies to invest heavily in infrastructure. Valient Biotech tackled this challenge head-on by developing biochemical solutions that help businesses reduce wastewater, improve product yield, and control losses due to microbial contamination