Cybersecurity Laws Push Indian Firms to Fortify Systems
DPDP Act and RBI Resilience Rules Drive Compliance
Geopolitical Risks and AI Adoption Add Complexity
By Legal Reporter
New Delhi: May 26, 2026
Indian companies are accelerating cybersecurity investments as new laws like the Digital Personal Data Protection Act (DPDP) and RBI’s resilience mandates reshape compliance requirements. The urgency stems from rising phishing attacks, geopolitical conflicts, and regulator-driven thresholds for disaster recovery.
The Supreme Court judgment in Smt. Sushila Devi vs Pandit Krishna Kumar Missir is an important ruling on succession law, testamentary disputes, and proof of wills in India. The Court examined the legal principles governing execution, attestation, and evidentiary scrutiny of testamentary documents, particularly in situations involving contested inheritance claims and suspicious circumstances. This decision is frequently referred to in probate proceedings, family property disputes, and cases concerning validity and enforceability of wills under Indian succession law.
Key Legal and Regulatory Frameworks
1. Digital Personal Data Protection Act (DPDP), 2023
- Scope: Regulates how organisations collect, store, and process personal data.
- Compliance Deadline: Full compliance required by May 2027.
- Key Provisions:
- Consent-based data collection.
- Mandatory safeguards against data leaks.
- Obligations to disclose breaches and remediate risks.
- Impact: Companies are investing in stronger data governance, monitoring AI systems, and securing SaaS/cloud environments.
2. RBI Cyber Resilience Mandates
- Introduced after the 2024 global IT outage and Suez Canal blockage.
- Requirements:
- Stronger resilience practices.
- Defined impact tolerance thresholds for banks and financial institutions.
- Impact: Banks now maintain multiple disaster recovery sites and test continuity plans regularly.
3. Sectoral Guidelines
- Banking & Telecom: High exposure to phishing attacks prompted stricter monitoring.
- Enterprise IT: Mandates for disaster recovery zones and backup facilities.
- AI Governance: Regulators warn that AI systems may inadvertently expose sensitive data if oversight is weak.
Analytical Insights
- Geopolitical Conflicts: The Iran war and India-Pakistan standoff triggered millions of phishing attempts daily, forcing companies to rethink resilience.
- Market Growth: India’s cybersecurity market is projected to grow from $6.5 billion in 2026 to $15 billion by 2031, driven largely by compliance and risk management.
- Corporate Strategy: Firms are defining “Minimum Viable Business” services to ensure continuity during crises.
- AI Risks: While AI enhances detection, it also complicates governance by processing sensitive data in opaque ways.
FAQ: Cybersecurity Laws and Compliance
Q1. What is the DPDP Act and why is it important?
The Digital Personal Data Protection Act (2023) is India’s landmark privacy law requiring companies to protect personal data, obtain consent, and report breaches. It aligns India with global data protection standards.
Q2. When must companies comply with DPDP?
By May 2027, all organisations handling personal data must demonstrate full compliance.
Q3. How has RBI strengthened cyber resilience?
RBI mandates banks to maintain disaster recovery sites, define impact tolerance thresholds, and conduct resilience drills to ensure continuity during outages.
Q4. Which sectors face the highest compliance burden?
Banking, telecom, and large enterprises face the most stringent requirements due to high exposure to phishing and systemic risks.
Q5. How do geopolitical conflicts affect cybersecurity law enforcement?
Conflicts amplify cyberattacks, prompting regulators to tighten rules and companies to accelerate compliance with resilience mandates.
Q6. What role does AI play in compliance?
AI improves threat detection but also raises risks of data exposure. Regulators stress strong governance to prevent misuse of sensitive information.
Q7. What penalties exist for non-compliance with DPDP?
The Act prescribes hefty fines for violations, including penalties for failing to secure personal data or disclose breaches.
Conclusion
India’s cybersecurity landscape is being reshaped by legal mandates (DPDP Act, RBI rules) and geopolitical realities. Companies are no longer treating cyber resilience as optional; it is now a boardroom priority. With compliance deadlines looming, firms must balance AI adoption, disaster recovery, and data governance to stay secure and legally compliant.

