An Indian SME can reach a strong, compliant security baseline for a modest per-user monthly cost. That baseline has five parts: endpoint protection on every device, hardened business email with MFA, tested backups, centralised logs kept for 180 days in India, and a written plan to report cyber incidents to CERT-In within 6 hours. Microsoft's India page lists Defender for Business at ₹250 per user per month and Microsoft 365 Business Premium, which bundles email, device management and Defender, at ₹1,830 per user per month, both paid yearly. Indian vendors such as Quick Heal and Seqrite, and global vendors such as Sophos, ESET, Bitdefender and CrowdStrike, are the other common shortlists. This guide explains what the law requires, what to buy first, and what it costs.
Executive summary
- CERT-In's Directions apply to ordinary companies. The April 2022 Directions cover "body corporate". They require incident reporting within 6 hours, ICT logs kept for 180 days within India, and clock sync with NIC/NPL NTP servers.
- Email and identity come first. Most SME incidents start with a phished password or a spoofed invoice. Enforced MFA, SPF/DKIM/DMARC and admin audit logs are the cheapest controls with the highest impact.
- Endpoint protection has moved from antivirus to EDR. Microsoft Defender for Business is listed at ₹250/user/month (paid yearly). Many vendors do not publish SME business prices on the pages we accessed, so you need quotes.
- Bundles often beat point tools on cost. If you need Microsoft 365 anyway, Business Premium (₹1,830/user/month, paid yearly) combines productivity, Intune device management and Defender.
- The DPDP Act raises the stakes. Data fiduciaries must protect personal data with reasonable security safeguards. The DPDP Rules, 2025 roll out over an 18-month phased timeline.
Market context
What the CERT-In Directions require
The CERT-In Directions of 28 April 2022, issued under Section 70B(6) of the IT Act, 2000, require:
- Clock synchronisation: "All service providers, intermediaries, data centres, body corporate and Government organisations shall connect to the Network Time Protocol (NTP) Server of National Informatics Centre (NIC) or National Physical Laboratory (NPL) or with NTP servers traceable to these NTP servers."
- 6-hour reporting: these entities "shall mandatorily report cyber incidents as mentioned in Annexure I to CERT-In within 6 hours of noticing such incidents or being brought to notice about such incidents". Reports can go to incident@cert-in.org.in, among other channels listed.
- Log retention: logs of all ICT systems must be maintained securely "for a rolling period of 180 days" and "within the Indian jurisdiction".
- Provider KYC: data centres, VPS providers, cloud service providers and VPN providers must keep validated subscriber information for 5 years or longer.
Annexure I lists incident types, including targeted scanning, compromise of critical systems, unauthorised access to IT systems or data, website defacement, malicious code attacks including ransomware, identity theft and spoofing, and data breaches. CERT-In also published FAQs on the Directions. Its Directions page also links a notice extending enforcement timelines for MSMEs, and CERT-In publishes elemental cyber defence controls for MSMEs there.
DPDP Act, 2023
The Digital Personal Data Protection Act requires data fiduciaries to take reasonable security safeguards to prevent personal data breaches. The DPDP Rules, 2025 set out breach notification and other procedures, with an 18-month phased compliance timeline, according to the Government's press release. For SMEs, customer databases, HR records and email are the main personal data stores to protect.
We have not relied on any private survey for statistics on attack frequency or cost in India. We explain risks qualitatively.
Evaluation framework
App Advisor's methodology for SME cybersecurity stacks:
| Criterion | Weight | What we look for |
|---|---|---|
| Coverage of top SME attack paths | 25% | Phishing, credential theft, ransomware, unpatched devices, misconfigured cloud sharing |
| Compliance support | 20% | Log retention/export for 180 days in India, incident timelines, audit reports |
| Manageability for small IT teams | 20% | Single console, automated response, sensible defaults, managed service availability |
| Cost transparency | 15% | Published INR prices, per-user vs per-device, bundle value |
| Detection and response depth | 10% | EDR, isolation, rollback, threat hunting options |
| Local support | 10% | India support hours, partner network, language |
Vendor comparison
The minimum control stack
| Layer | Control | Example products on App Advisor |
|---|---|---|
| Identity | MFA for all, SSO, admin separation | Microsoft Entra ID, JumpCloud, Zoho Vault (passwords) |
| Phishing and malware filtering, SPF/DKIM/DMARC, audit logs | Microsoft 365, Google Workspace, Zoho Mail. See business email guide | |
| Endpoint | EDR/antivirus, disk encryption, patching | Microsoft Defender for Business, Seqrite, Quick Heal, Sophos, ESET, Bitdefender, CrowdStrike Falcon |
| Device management | Enrol, enforce policies, remote wipe | Microsoft Intune, ManageEngine Endpoint Central |
| Logging | Centralised logs, 180-day retention in India | ManageEngine Log360 |
| Backup | Offline/immutable copies, restore tests | See backup and disaster recovery guide |
Official prices we could verify
| Product | Official price | Notes | Source |
|---|---|---|---|
| Microsoft Defender for Business | ₹250.00 user/month, paid yearly (annual subscription, auto-renews) | Standalone device protection | Microsoft India |
| Microsoft 365 Business Premium | ₹1,830.00 user/month, paid yearly | Productivity + security bundle | Microsoft India |
| Microsoft 365 Business Premium (no Teams) | ₹1,565.00 user/month, paid yearly | Same bundle without Teams | Microsoft India |
| Quick Heal Total Security (consumer) | ₹1,591.00 for 1 user, 1 year (shown against ₹1,909.00) | Consumer product, for context only | Quick Heal |
| Seqrite Endpoint Protection (business) | Not published on the page we could access | Quote via partners | Seqrite |
| Sophos, ESET, Bitdefender, CrowdStrike business plans | Not verified for this article | Request quotes in INR | Vendor sites |
Explore more tools in the cybersecurity category, the IT management category and the password manager category.
Mapping CERT-In incident types to SME controls
Annexure I of the Directions lists the incident types that must be reported. The table below links the ones SMEs most commonly face to the control that prevents or detects them.
| Annexure I incident type (as listed) | Typical SME scenario | Primary preventive control | Detection source |
|---|---|---|---|
| Unauthorised access of IT systems/data | Ex-employee still logs into accounting software | Offboarding checklist, MFA, password manager | Application and identity logs |
| Identity theft, spoofing and phishing attacks | Fake supplier email changes bank details | DMARC, email filtering, payment call-back rule | Email security reports, user reports |
| Malicious code attacks (including ransomware) | Staff opens an infected attachment | EDR, patching, no local admin rights | EDR alerts |
| Attack on servers such as database, mail and DNS | Exposed database or RDP port attacked | Firewall rules, VPN, patching | Server and firewall logs |
| Defacement of website or intrusion into a website | Outdated CMS plugin exploited | Plugin updates, web application firewall | Uptime and integrity monitoring |
| Data breach / data leak | Public link to a customer spreadsheet | Sharing restrictions, data classification | Cloud storage audit logs |
| Unauthorised access to social media accounts | Brand Instagram or Facebook page hijacked | MFA, shared credentials in a vault | Platform security notifications |
| Attacks or malicious/suspicious activities affecting cloud computing systems | Compromised cloud admin key | Least-privilege IAM, MFA, key rotation | Cloud audit logs |
Annexure I also lists other categories, including denial-of-service attacks, attacks on IoT devices, attacks affecting digital payment systems, and malicious or fake mobile apps. Read the full list in the Directions.
What a 6-hour report needs
Six hours is short. Prepare a one-page template in advance with:
- Organisation name, point of contact, phone and email.
- Time the incident was noticed, and how it was noticed.
- Incident type, using the Annexure I category.
- Affected systems, locations and approximate number of users or records.
- Immediate actions taken (isolation, password resets, blocking).
- Whether personal data may be involved. This also triggers your DPDP breach-handling process.
Initial reports can be updated as the investigation proceeds. The priority is to report within the window with the facts known at the time.
Security for the owner and the accounts team
In small companies, the owner and the accounts team are the most targeted people, because they can move money. Three rules prevent a large share of real-world losses:
- Call back before changing bank details. Any request to change a supplier's or employee's bank account is verified by phone, using a number already on file.
- Two-person approval for payments above a threshold in net banking.
- Separate devices or browser profiles for banking and general browsing, with MFA on every financial portal.
Buying through a partner
Many SMEs buy endpoint and email security through a managed service provider. Ask the partner to commit in writing to: alert monitoring hours, response time for critical alerts, help with preparing CERT-In reports, monthly reports on patch and EDR coverage, and where log data is stored.
Total cost of ownership
Illustrative model — assumptions stated. A 50-person professional services firm with 50 laptops and existing Google Workspace email. Assumptions:
- Option A adds Microsoft Defender for Business to all 50 laptops at the listed ₹250/user/month.
- Option B moves the firm to Microsoft 365 Business Premium at ₹1,830/user/month and drops Google Workspace Business Starter (₹270/user/month from Google's India page).
- Log management and backup tools: an assumed ₹15,000/month in both options (our assumption; get quotes).
- Managed security service or IT partner time: an assumed 10 hours/month at ₹1,500/hour in A, and 7 hours in B because of the single console (our assumption).
- Prices exclude GST.
| Year-1 cost line | Option A: Keep Google + add Defender | Option B: Move to M365 Business Premium |
|---|---|---|
| Email/productivity | 50 × ₹270 × 12 = ₹1,62,000 | Included |
| Endpoint security | 50 × ₹250 × 12 = ₹1,50,000 | 50 × ₹1,830 × 12 = ₹10,98,000 |
| Logging + backup (assumed) | ₹1,80,000 | ₹1,80,000 |
| Partner time (assumed) | ₹1,80,000 | ₹1,26,000 |
| Migration (assumed one-time) | ₹0 | ₹1,00,000 |
| Year-1 total (excl. GST) | ₹6,72,000 | ₹15,04,000 |
What this shows:
- For a firm happy on Google Workspace, adding endpoint protection is far cheaper than switching suites.
- Business Premium makes financial sense when you would buy Microsoft 365 anyway and would otherwise pay separately for device management and endpoint security.
- People and process costs (partner time, log review) are about a quarter of Option A's total. Do not budget only for licences.
Endpoint security buying checklist
When comparing endpoint products, ask each vendor or partner to demonstrate:
- Detection and response: isolating an infected device from the console with one action.
- Ransomware protection: behaviour-based blocking and, where offered, rollback of encrypted files.
- Device control: blocking or allowing USB storage by policy.
- Patch visibility: reports on missing operating system and third-party application updates.
- Coverage: Windows, macOS, Linux servers and mobile devices, as your estate requires.
- Log export: sending endpoint events to your central log store for 180-day retention in India.
- Licensing clarity: whether pricing is per user or per device, and what happens when staff use several devices.
Implementation roadmap
Weeks 1–2: Baseline and governance
- Appoint an incident owner and a deputy. Document the CERT-In reporting route and the 6-hour clock.
- Inventory devices, accounts, SaaS apps, domains and internet-facing services.
- Configure NTP on servers, firewalls and network devices to NIC/NPL-traceable sources.
Weeks 3–4: Identity and email
- Enforce MFA for all users; separate admin accounts.
- Publish SPF, DKIM and DMARC and monitor DMARC reports.
- Turn on email and admin audit logging.
Weeks 5–7: Endpoints
- Deploy EDR to 100% of laptops and servers; enable disk encryption.
- Enrol devices in management; enforce screen lock and OS updates.
- Remove local admin rights from standard users.
Weeks 8–10: Logging, backup and response
- Centralise logs with 180-day retention stored in India.
- Implement 3-2-1 backups with an offline or immutable copy; test restore.
- Run a tabletop exercise: phishing leads to ransomware, and the team decides, detects, contains and reports within 6 hours.
Ongoing (monthly/quarterly)
- Monthly patch compliance review; quarterly phishing simulation; annual policy review and DPDP readiness check.
Risks and compliance checklist
- CERT-In 6-hour reporting: named owner, contact details and a report template ready.
- 180-day ICT logs within Indian jurisdiction: firewall, VPN, email, endpoint, cloud and server logs.
- NTP: all systems synced to NIC/NPL or traceable NTP servers.
- DPDP Act: personal data inventory; access restricted; breach response procedure aligned to the DPDP Rules.
- Data localisation: logs kept in India per CERT-In; check sector rules (for example RBI-regulated entities) for other localisation needs.
- MFA on email, VPN, cloud admin, banking and accounting software.
- EDR on every endpoint and server; alerts monitored, including out of hours.
- Backups offline/immutable and tested quarterly.
- Vendor access: third-party remote access tools controlled and logged.
- Staff training: phishing awareness at joining and every year.
KPIs to track
| KPI | Suggested target |
|---|---|
| MFA coverage | 100% of users and admin accounts |
| EDR coverage | 100% of endpoints and servers |
| Critical patches applied within 14 days | Above 95% of devices |
| Mean time to detect / contain | Hours, not days; always inside the 6-hour reporting window |
| Phishing simulation click rate | Falling each quarter |
| Log sources feeding central store with 180-day retention | 100% of in-scope systems |
| Successful restore tests | 1 per quarter minimum |
How to choose
- Microsoft 365 shop? Evaluate Business Premium first; it may replace three separate tools.
- Google Workspace shop? Keep it, and add a dedicated EDR (Defender for Business, Seqrite, Sophos, ESET, Bitdefender or CrowdStrike) plus device management.
- No in-house IT? Buy through a managed security partner who will monitor alerts and help with CERT-In reporting.
- Regulated data (health, finance)? Prioritise logging, access control and data residency statements. See healthcare software if relevant.
For asset and service management tooling, read our IT asset management and ITSM guide. For team credentials, see password managers for teams.
FAQs
Do CERT-In rules apply to small businesses?
The April 2022 Directions apply to "body corporate", which includes private companies. CERT-In's Directions page links a notice extending enforcement timelines for MSMEs. Take advice on your specific obligations, but plan to meet the 6-hour reporting and 180-day log requirements.
What counts as a reportable cyber incident?
Annexure I of the Directions lists types including targeted scanning, compromise of critical systems, unauthorised access to IT systems or data, website defacement, malicious code such as ransomware, identity theft and spoofing, and data breaches.
How much does Microsoft Defender for Business cost in India?
Microsoft's India page lists Defender for Business at ₹250.00 per user per month, paid yearly.
Is free antivirus enough for an SME?
Usually not. Businesses need central management, EDR-style detection and response, reporting and logs, which consumer or free tools generally do not provide.
Where should logs be stored?
The CERT-In Directions require ICT logs to be maintained securely for 180 days within Indian jurisdiction.
What should we do in the first hour of a ransomware attack?
Isolate affected devices from the network, preserve logs, inform your incident owner and IT partner, start the CERT-In reporting clock, and do not pay or wipe systems before evidence is secured.
Does the DPDP Act require encryption?
The Act requires reasonable security safeguards. Encryption, access control and logging are widely used ways to meet that duty. Check the DPDP Rules and take legal advice for specifics.
Do we need to register a point of contact with CERT-In?
The Directions include a format (Annexure II) for service providers, intermediaries, data centres, body corporate and government organisations to share point-of-contact details with CERT-In by email, and to keep them updated. Name a primary and a deputy contact, so reports and CERT-In requests reach someone quickly.








