India Recorded 29.44 Lakh Cyber Security Incidents in 2025: Enterprise Risk and Board-Reporting Guide
By Ravi Sisodia · Reviewed by CA Divyanshu Sengar · Updated 5 October 2026
India-first finance, audit and risk workflow with primary-source anchors.
2-minute summary
- The rise from 15,92,917 tracked incidents in 2023 to 20,41,360 in 2024 and 29,44,248 in 2025 is a risk-capacity signal, not a prediction that any individual company will be attacked. Boards should use the trend to test whether security staffing, logging, vulnerability management and incident-response capacity scale with digital dependence.
- A board pack should separate attempted / tracked incidents from material enterprise losses. CERT-In’s national count is not a company loss-rate statistic, so it should not be converted into a simplistic “probability of breach.”
- The practical response is measurable control coverage: internet-facing asset inventory, patch latency, endpoint coverage, privileged-access review, backup recoverability, vendor risk and tested incident escalation.
Current position
Control and decision map
| # | Control / decision step |
|---|---|
| 1 | Present national incident trend with source and definitions, avoiding company-specific probability claims. |
| 2 | Map critical business services and internet-facing assets to control owners. |
| 3 | Track patch / vulnerability ageing and endpoint / logging coverage as board metrics. |
| 4 | Measure third-party exposure and incident-notification readiness. |
| 5 | Test backups and recovery objectives through exercises, not policy statements alone. |
| 6 | Record material cyber incidents, near misses and remediation closure for the audit / risk committee. |
Evidence pack
- Board cyber-risk dashboard
- Asset / service inventory
- Vulnerability and patch metrics
- Incident / near-miss register
- Recovery-test evidence
Worked example
A company board sees the national incident count rise sharply and asks to double cyber spend. The CISO instead maps spend to measurable gaps: 18% of servers lack central logging, critical patches average 24 days, and two key vendors have no tested breach-notification workflow. The budget is then tied to those weaknesses rather than the headline count alone.
Common mistakes
- Treating national incident counts as a direct probability for one company.
- Reporting tool purchases instead of control effectiveness.
- Ignoring third-party and recovery readiness.
- Using only annual penetration-test results as the cyber dashboard.
Frequently asked questions
What does 29.44 lakh represent?
The Government says these were cyber-security incidents reported to / tracked by CERT-In in 2025.
Does the number equal successful breaches?
No. Do not equate a national incident count with successful company breaches or losses.
What should a board monitor?
Control coverage, vulnerabilities, incidents, vendors, recovery and remediation closure.
Official sources
- Press Information Bureau / MeitY - Government Strengthens Cyber Security Preparedness of Central Government Digital Platforms and Citizen Services (PIB PRID 2299339; 14 Aug 2026)
- Indian Computer Emergency Response Team (CERT-In) - 15 Elemental Cyber Defense Controls (Version 1.0; 1 Sep 2025)
- Indian Computer Emergency Response Team (CERT-In) - Directions under section 70B on cyber security practices and incident reporting (No. 20(3)/2022-CERT-In; 28 Apr 2022; current)
Disclaimer
Educational and professional reference only; confirm the current law, rates and the facts of your case before relying on this page.