Compliance officer at an Indian NBFC reviewing documents and a laptop during a data breach cost investigation

What a Data Breach Actually Costs an Indian Mid-Size Company (We Calculated It)

TL;DR: IBM’s global survey puts the average Indian data breach at ₹19.5 crore, but that number is stretched upward by large enterprises with hundreds of servers and a dedicated SOC. For a 100 to 500 employee company, the honest range is ₹18 lakh to ₹1.2 crore once you add forensic investigation, the CERT-In six-hour reporting scramble, legal counsel, customer notification, and DPDP penalty exposure. Below is the line-item math, built off a real client’s breach, an 85-person NBFC in Nashik.

4:10 PM on a Wednesday, and Sneha’s phone would not stop buzzing. She ran compliance for the NBFC, and the query had come from a lending partner doing their annual vendor risk review: “confirm your data loss prevention controls for customer KYC records.” A routine box to tick, most quarters. This quarter, when she asked IT to pull the access log for the KYC folder, the answer took forty minutes longer than it should have.

That gap is where this story starts. Not a hacker, not ransomware, not the dramatic version everyone pictures when they hear “breach.” A relationship manager’s laptop had a personal Google Drive account synced for backup. It was the kind of thing IT sets up once for convenience and never revisits. Seven months of client KYC folders had been quietly mirroring to that drive. Nobody broke in. Somebody just never closed a door.

The discovery: what an “amber” flag actually looks like

Sneha’s team found it because the vendor review forced a proper access audit, not because anything alerted. That is the part people get wrong about data breach cost in India: the breach itself is usually silent. What costs money is everything that happens in the six weeks after you find it. The forensic firm arrived on day two. The lawyer arrived on day three, because CERT-In’s rule is not gentle: unauthorised access to personal data has to be reported within six hours of becoming aware, not six hours of the breach happening. Sneha’s clock started the moment she saw the gap in the log. It did not care that she was still confirming whether the finding was even real, or that it was 6 PM on a Wednesday and her son had a school project due.

By Thursday evening they had a forensic timeline, a lawyer drafting the CERT-In notification, and 340 client records confirmed exposed. Bas, that was the scope. Small by breach standards. The bill was not small.

The quiet exit route nobody had budgeted for

Here is what took the rest of the week: proving the scope had not grown. The relationship manager who set up the sync had left the company four months earlier, and nobody had revoked the Drive connection on exit. This is the pattern I see most often in mid-size Indian companies, not a sophisticated attacker but an unmonitored exit route, a personal email, a USB drive, a sync folder, left open long after the person who opened it is gone. We wrote about the same gap in five real data theft scenarios HR teams should worry about, and Sneha’s case is the fourth one on that list, almost line for line.

The investigation had to rule out every other laptop that relationship manager had touched, every shared drive he had access to, every client he had personally serviced. That is not a technology problem. That is hours, billed by the day, by a forensic team and a lawyer who both charge Mumbai rates.

There is a small, dark comedy to this part of the job. IT swore the offboarding checklist was followed to the letter. It was, mostly, laptop collected, email disabled, badge deactivated. Nobody had put “revoke third-party cloud sync tokens” on that checklist, because nobody had thought to ask what a laptop does quietly in the background before it gets wiped. Phir bhi, the sync job kept running regardless, four months and counting.

What a data breach actually costs in India: the math

This is the table an auditor never shows you and a vendor never volunteers. Here is what Sneha’s NBFC actually paid, and the honest range for a company her size, once you strip out the enterprise-scale noise from the IBM number.

Cost lineSneha’s NBFC (85 employees)Typical range, 100 to 500 employees
Forensic investigation₹6.8 lakh₹4 lakh to ₹15 lakh
Legal counsel and CERT-In filing₹3.2 lakh₹2 lakh to ₹8 lakh
Customer notification and credit monitoring₹1.9 lakh₹1 lakh to ₹6 lakh
Business downtime and internal hours lost₹4.1 lakh₹3 lakh to ₹20 lakh
Remediation and new controls₹5.5 lakh₹4 lakh to ₹18 lakh
DPDP penalty exposure (post-enforcement)Not yet applicableUp to ₹250 crore, discretionary
Total, excluding DPDP penalty₹21.5 lakh₹18 lakh to ₹67 lakh

The logistics client we have written about before lost ₹47 lakh from a single unmonitored laptop, which sits comfortably inside that upper band once you add reputation cost and one lost contract. Sneha’s NBFC landed closer to the lower end, mostly because the exposure was caught before it reached a regulator’s desk on someone else’s terms. That difference, catching it yourself versus a regulator or a client catching it for you, is most of what separates ₹21 lakh from ₹67 lakh.


200+ Indian businesses served. Response within 24 working hours. No card, no contract, no sales call.

The mistake I almost made

I want to be honest about something here, because the mistake is the lesson. When Sneha first called, 340 records sounded small enough that I nearly told her to handle the notification internally and skip the full forensic engagement. Achha, I thought, contained scope, contained cost. What changed my mind was one question I asked late: how long had the sync been running. Seven months is not a snapshot, it is a pattern, and a pattern means you cannot be certain the count stops at 340 until someone actually checks. I had read a small number as a small problem. It was a small number with an unverified edge, which is a different thing entirely, and the ₹6.8 lakh forensic spend existed specifically to find that edge.

If you are calculating this yourself

What I would tell any IT head trying to price this out before it happens to them. None of this is expensive to prepare in advance. It gets expensive the day you are preparing it under a six-hour clock instead:

  • Get a real forensic quote now, not during an incident. Prices triple under time pressure.
  • Check who still has active sync connections from devices that left the company. This is the single most common exit route we find.
  • Know your CERT-In clock starts at awareness, not at the breach date. Have the lawyer’s number saved before you need it.
  • Ask what your cyber insurance actually covers. Most Indian mid-size policies exclude notification costs unless you read the fine print closely.
  • Budget remediation separately from the incident response. Fixing the control that let this happen costs almost as much as the breach itself.

Questions Sneha wishes she had asked earlier

Does DPDP apply if the breach happened before the Act is fully enforced?
The exposure event and the enforcement date are different things. Regulators and RBI-supervised vendor risk teams are already asking about your DPDP readiness in vendor questionnaires today, penalty or not. The financial risk starts well before the ₹250 crore fine becomes live.

Is CERT-In’s six-hour rule really six hours, even for a small company?
Yes. Company size does not change the clock. What changes is whether you have a lawyer and a forensic partner on retainer, which is the entire difference between a calm six hours and a panicked one.

Would DLP have prevented this specific breach?
A properly configured endpoint DLP policy blocks exactly this pattern, an unauthorised sync destination on a managed laptop, and flags it the week it starts rather than seven months later. We cover the mechanics in how a Mumbai NBFC SOC almost waved an amber alert through, which is close to the same failure mode.

How do we know if our exposure is closer to ₹21 lakh or ₹67 lakh?
Mostly it depends on how long the gap existed before anyone looked and whether a regulator or client found it before you did. We can walk your fleet and give you a real number, not a guess, before you are calculating it under pressure.

Still deciding

If you want the calm version of this exercise rather than the panicked one, start with what you already have live. Read what your auditor will ask about data protection this year, then run the numbers on your own fleet before a vendor questionnaire forces the question.


200+ Indian businesses served. 17+ years in IT. Reach us on WhatsApp at +91 91375 93228, 10 to 7 IST, or start above. Response within 24 working hours.

P.S. Sneha’s team closed the loop in eleven days, forensic report, CERT-In filing, remediation, done. Six months later the same lending partner sent their annual review again. This time the answer took four minutes, not forty. She told me that was the number she actually cared about.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *