The Soaring Cost of Silence
The time between a cyberattacker’s entry and their discovery is where the most damage is done. According to IBM's 2026 'Cost of a Data Breach Report', the average cost of a breach for an Indian company has hit a record INR 25.5 crore. But a more telling
figure lies in the response time. For Indian organisations without extensive AI and security automation, it takes an average of 236 days just to identify that a breach has occurred. That's nearly eight months during which attackers can roam undetected through networks, steal data, and prepare larger attacks. This detection gap is significantly longer than for firms that use automation, which spot breaches in about 175 days. The financial penalty for this delay is stark: firms without automation face average breach costs of INR 31.6 crore, compared to INR 21.3 crore for those with extensive automation. Every extra day of silence adds to the final bill, not just in financial terms but in reputational damage and loss of customer trust.
Why Are Breaches Missed for So Long?
The prolonged detection time isn't solely a technology issue. While a lack of advanced tools like AI-driven security is a major factor, the problem is also deeply rooted in people and processes. A significant skills gap plagues the industry, with reports showing that a majority of Indian cybersecurity teams have unfilled positions. This understaffing means existing teams are overwhelmed, stuck in a reactive mode of firefighting rather than proactive threat hunting. Furthermore, a culture of fear and denial often prevents the swift escalation of potential incidents. Experts note that many companies prefer to remain silent about breaches, fearing reputational damage and regulatory scrutiny. This creates a situation where security analysts might hesitate to raise an alarm without definitive proof, or middle management might suppress bad news, hoping the problem resolves itself. This reluctance is compounded by the fact that over a quarter of Indian organisations reportedly lack a formal incident management process altogether.
The Broken Escalation Ladder
A fast and effective response hinges on a clear internal escalation path. This is the pre-defined process that ensures a potential security issue, once spotted by a junior analyst, is rapidly communicated to the right people with the authority to act. However, in many organisations, this ladder is broken. Without clear roles, responsibilities, and protocols, the alert gets stuck. Junior team members may not know who to notify or what threshold warrants escalation. There might be ambiguity over whether an issue belongs to IT, security, or a specific business unit, leading to finger-pointing and delays. A 'blame culture' is particularly corrosive; if employees fear being penalised for a false alarm or for bringing bad news, they are less likely to report suspicious activity promptly. This breakdown in communication is precisely what attackers exploit. They rely on organisational silence and indecision to extend their dwell time within a network, turning a minor intrusion into a catastrophic breach.
Regulations Demand Speed, But Detection Lags
Indian regulators have attempted to force the issue. Directives from the Indian Computer Emergency Response Team (CERT-In) mandate that cyber incidents, including data breaches, must be reported within just six hours of being noticed. The Digital Personal Data Protection Act (DPDPA) of 2023 also imposes strict, albeit less specific, timelines for notifying authorities and affected individuals. However, these regulations have a fundamental limitation: they only apply once an incident is detected. If a company takes 236 days to even notice a breach, the six-hour reporting window becomes almost irrelevant to the initial intrusion. This highlights that compliance is not a substitute for a robust internal security culture. While the threat of penalties may encourage faster reporting post-discovery, it does little to solve the core problem of delayed detection and slow internal alerts.
Building a Culture of Rapid Response
Shortening the detection-to-escalation timeline requires a cultural shift, not just a technological one. Organisations must foster a 'no-blame' environment where employees are encouraged to report anomalies without fear of reprisal. A critical step is establishing a formal Incident Response Plan with clearly defined roles, responsibilities, and communication channels for various scenarios. Regular drills and simulations are essential to test these plans, ensuring that everyone from the IT helpdesk to the CEO knows their role in a crisis. Empowering the security team with both the authority and the tools to investigate potential threats is paramount. Ultimately, faster escalation is a byproduct of a resilient organisation that views cybersecurity not as an IT cost centre, but as a core business function critical for survival in the digital age.














