The Soaring Price of a Silent Intruder
The financial fallout from a data breach in India has reached an unprecedented new high. According to the latest 2026 'Cost of a Data Breach Report' by IBM, the average breach now costs an Indian organization a staggering ₹25.5 crore, a sharp 15.9% increase
from the previous year. But buried beneath this headline figure is a more alarming statistic: the time it takes to even notice an intruder. For Indian companies that have not invested in AI and security automation, it takes an average of 236 days just to identify that a breach has occurred. That’s nearly eight months during which attackers can operate undetected, exfiltrating data, mapping networks, and escalating their privileges, all before the company even knows they are there. This long dwell time is the single biggest factor driving costs up. The longer an attacker remains, the more damage they can do, and the more expensive the cleanup becomes.
The Paradoxical Cost of Detection
If detection is so critical, why the delay? The answer lies in a counterintuitive financial calculation many firms seem to be making. Proactive cybersecurity is expensive. The costs are not just about purchasing advanced software. They include hiring scarce and expensive cybersecurity talent, engaging consultants for penetration testing, and the potential business disruption an in-depth investigation can cause. Fearing these immediate, tangible costs, some organizations delay the very actions that would lead to faster detection. They operate on a principle of 'what we don't know can't hurt us,' failing to recognise that the cost of a full-blown, months-long breach is exponentially higher. For instance, firms without AI and automation face average breach costs of ₹31.6 crore, compared to ₹21.3 crore for those with extensive deployment. The decision to save money on detection tools and talent is proving to be a profoundly expensive mistake.
A Critical Shortage of Cyber Guardians
Even for companies willing to spend, a formidable obstacle remains: India's acute cybersecurity skills gap. By some estimates, India will have hundreds of thousands of unfulfilled cybersecurity positions in 2026. It’s not just a numbers game; there's a deficit in high-level expertise required to manage modern security platforms. Many organizations report that it can take up to six months to fill a single cybersecurity role. This means that expensive Security Information and Event Management (SIEM) and Extended Detection and Response (XDR) tools are often underutilised or misconfigured, creating a false sense of security. The dashboard may be green, but attackers are moving freely through the network. This talent chasm means companies simply don't have the people to hunt for threats, interpret alerts, and respond effectively, stretching detection times from minutes to months.
Regulation as a Double-Edged Sword
India's regulatory landscape has tightened significantly. Directives from CERT-In mandate reporting certain incidents within a strict six-hour window, while the Digital Personal Data Protection Act (DPDPA) imposes heavy penalties for non-compliance, up to ₹250 crore. While intended to improve security, these regulations can inadvertently contribute to detection delays. The fear of triggering a regulatory investigation and facing massive fines can create a culture of hesitancy. Instead of launching a swift, transparent internal investigation at the first sign of trouble, some may delay in the hope that the issue is minor or will resolve itself. This ‘head-in-the-sand’ approach is dangerous. The longer a breach goes unconfirmed and unreported, the greater the legal and financial exposure when it inevitably comes to light, with regulatory non-compliance being a top factor that increases breach costs.














