84% of Indian SMEs plan to increase cybersecurity investments, finds Tata Teleservices study
- 84% of Indian SMEs plan to increase cybersecurity investments over the next 12–24 months
- Only 28% implemented structural security improvements after experiencing a cyber incident
- 45% cite lack of expertise as the biggest barrier to effective cybersecurity implementation
- 35% recognize AI as a cybersecurity enabler, while 34% fear AI-powered threats
- 46% allocate less than 5% of their IT budgets towards cybersecurity

*this image is generated using AI for illustrative purposes only.
A joint study by Tata Teleservices (Maharashtra) Limited and CyberMedia Research reveals that 84% of Indian small and medium enterprises plan to increase cybersecurity investments over the next 12–24 months. The findings highlight a growing recognition of security as a strategic priority, despite significant gaps in current preparedness.
The SME Digital Insights 2026: Cybersecurity study surveyed 800 IT heads and decision-makers across eight major Indian cities. It covers 150 micro, 350 small, and 300 medium enterprises. The data indicates a shift from reactive measures toward proactive investment, although execution remains uneven.
Investment Intent vs. Preparedness
While investment intent is strong, operational maturity lags. 40% of SMEs reported facing a cyber incident in the last 24 months. However, only 28% implemented structural cybersecurity improvements following these incidents. The majority, 60%, responded with tactical tool upgrades rather than strengthening their overall security posture.
Budget allocation reflects this cautious approach. 46% of SMEs allocate less than 5% of their IT budgets to cybersecurity. Medium-sized enterprises show higher intent, with 89% planning to increase investments compared to the overall average.
What the Numbers Show
A significant divergence exists between incident response and long-term strategy. While 40% of firms experienced breaches, only 12% continuously monitor their cybersecurity environments. This suggests that most organizations rely on periodic reviews or reactive remediation rather than continuous visibility.
Furthermore, 35% operate multiple cybersecurity tools with limited risk visibility. This fragmentation indicates that increased spending may not automatically translate to improved resilience without integrated management solutions.
Key Barriers and AI Adoption
Lack of expertise is the primary hurdle. 45% of SMEs cite a shortage of skilled professionals as the biggest barrier to effective implementation. When evaluating partners, 48% prioritize ease of integration and customer support, while 46% value trust and long-term relationships.
AI is emerging as both an enabler and a threat. 35% of SMEs recognize AI’s potential for threat detection and automated monitoring. Conversely, 34% expect AI-powered cyber threats to materially impact their business within the next two years.
Key Findings Summary
| Metric | Percentage |
|---|---|
| Plan to increase cyber investment | 84% |
| Faced cyber incident (last 24 months) | 40% |
| Made structural changes post-incident | 28% |
| Continuously monitor security | 12% |
| Cite lack of expertise as barrier | 45% |
| Allocate <5% IT budget to security | 46% |
Vishal Rally, Chief Revenue Officer at Tata Teleservices, noted that businesses must integrate cybersecurity into their broader digital transformation journey rather than treating it as a standalone initiative. Prabhu Ram, Vice President at CyberMedia Research, emphasized that the gap between intent and preparedness is the defining challenge for Indian SMEs today.
Historical Stock Returns for Tata Teleservices Maharashtra
| 1 Day | 5 Days | 1 Month | 6 Months | 1 Year | 5 Years |
|---|---|---|---|---|---|
| -2.85% | -3.75% | -8.99% | -8.16% | -39.18% | -5.72% |
How will the 45% talent shortage among Indian SMEs impact the growth trajectory of cybersecurity staffing and training firms over the next two years?
Will the high intent to invest (84%) combined with low budget allocation (<5%) lead to a consolidation in the cybersecurity vendor market as SMEs seek integrated solutions?
What regulatory changes might Indian policymakers introduce to bridge the gap between SME cybersecurity intent and actual structural preparedness?


































