Facing both national and global calls to fortify cybersecurity, the Indian government unveiled the National Cyber Security Policy. This policy outlined 14 objectives, aiming to bolster the safeguarding of critical infrastructure and cultivate proficient cybersecurity professionals by the close of 2018. A pivotal aspect of the National Cyber Security Policy is the promotion of public–private partnerships (PPPs) to elevate the cybersecurity environment. PPPs prove particularly effective in domains demanding a range of expertise to tackle intricate issues, cybersecurity being a prime example.
Staffing Struggles: The Cybersecurity Workforce Dilemma in India

Networking giant Cisco revealed its plan to provide cybersecurity training to 500,000 individuals in India over the next three years. This initiative is a component of Cisco’s broader 10-year objective to equip 25 million people globally with digital skills through its Networking Academy. The flagship program, now celebrating its 25th anniversary, has already impacted 17.5 million students in 190 countries.
In a recent report by ISACA on the cybersecurity threat landscape, hiring, and budgets, it was revealed that 40% of respondents in India believe their cybersecurity teams are not adequately staffed. The ninth annual research report, sponsored by Adobe and based on insights from 113 security leaders in India, highlighted that while there have been improvements in addressing employee retention, it remains a significant challenge. A substantial 69% of survey respondents expressed difficulties in retaining qualified cybersecurity professionals.
India Disclosure Index 2023: A Stark Reality Check on Cybersecurity Practices
In a recently published report on October 12, FTI Consulting revealed that 47% of the top hundred Indian companies, as tracked in the India Disclosure Index 2023, neglect regular cybersecurity audits and training to brace for potential data breaches or ransomware attacks. The index monitors disclosure practices among India’s leading publicly listed corporations (Nifty 100), evaluating parameters such as cyber risk preparedness. This includes specific metrics regarding cyber breach incidents and details about cybersecurity audits or training mentioned in the companies’ latest Annual Report (FY 2022-23).

The report raises concerns about the high proportion of companies overlooking such crucial cybersecurity measures, especially given the substantial risk. Interestingly, 80% of these companies claim zero cyber incidents, possibly creating a misleading perception of sufficient and best-in-class cyber preparedness, according to FTI Consulting.