DEV Community

Shubham Chaudhary
Shubham Chaudhary

Posted on

84% of Indian SMEs Are Spending More on Cybersecurity — Why Most Still Get Breached

 Quick question for anyone doing IT/security for a small business: when's the last time you actually checked whether your audit logging is even turned on?

A new TTBS-CyberMedia Research study on Indian SME cybersecurity just quantified a gap a lot of us in SOC/infra roles already suspected. 84% of Indian SMEs plan to increase cybersecurity spending over the next 12-24 months. Good news. But:

  • 40% got hit by a cyber incident in the last two years
  • Only 28% made structural fixes after — most just patched the symptom
  • Just 12% continuously monitor their environment
  • 35% run multiple security tools with almost zero real visibility
  • 46% spend under 5% of IT budget on security

Buying tools isn't the same as running a security program. A firewall or EDR agent nobody's watching is just software sitting on a box.

In the full writeup I go through the study's numbers, why tool sprawl often makes visibility worse instead of better, and include a one-line Windows command any sysadmin can run right now to check if basic security event logging is even enabled:

auditpol /get /category:*

If that comes back "No Auditing" on logon/logoff or account management categories, you've found your first real gap — no new budget required.

Full breakdown + self-audit:
https://www.xpert4cyber.com/2026/09/indian-sme-cybersecurity-spending-2026.html

Top comments (0)