Cyber Security : A New Principle of Corporate Governance
Introduction
India’s digital growth is moving super-fast these days. You can see it everywhere –
UPI payments on every phone, startups popping up, and businesses shifting online.
Recent government data shows India crossed 1.03 billion internet users by end-
2025, with UPI hitting a record 21.63 billion transactions in December 2025. But this
boom brings serious dangers. Cybersecurity is no longer just an IT job – it has
become a core part of company governance.
The threats are real.
According to CERT-In, over 29.44 lakh cyber incidents were
handled in 2025. Cyber fraud losses crossed ₹20,000 crore, and the average data
breach costs companies around ₹22 crore. It’s surprising that India holds Tier 1
“Role Model” status in the ITU Global Cybersecurity Index 2024, yet we remain one
of the top targets for ransomware in Asia-Pacific.
The government is responding. In the Union Budget 2025-26, it allocated ₹782 crore
for cybersecurity to strengthen digital defences.
Why Cybersecurity Must Be a Boardroom Topic
Cybersecurity is more than passwords and firewalls. It’s about protecting data,
keeping business running, meeting legal rules, and building trust. The Information
Technology Act, 2000 was made for e-commerce, not today’s AI attacks or
ransomware. That’s why rules are updating fast.
In February 2026, the Information Technology (Intermediary Guidelines) Amendment
Rules, 2026 tackled deepfakes and synthetic AI content (called SGI). Platforms must
label it clearly and remove harmful material in 3 hours (or 2 hours for sensitive
cases).
The Digital Personal Data Protection Act, 2023 is rolling out in phases. As of April
2026, companies must use “reasonable security safeguards”, report breaches within
72 hours, and face penalties up to ₹250 crore.
CERT-In is the main regulator. It requires incidents reported in 6 hours and logs kept
for 180 days. Since September 2025, even MSMEs must do annual cybersecurity
audits through empanelled auditors. Skipping this can mean fines up to ₹1 crore plus
legal trouble. Other regulators like RBI, SEBI and IRDAI add their own rules, creating
overlap and extra work.
MSMEs Are the Most Vulnerable
MSMEs power India’s economy but are the easiest targets. Many still run offline or
don’t know about schemes like MSME Cyber Shikshaa. Studies show nearly 60%
shut down within six months of a major attack. One weak MSME can open the door
for bigger companies via supply chains.
AI Brings New Risks
Artificial intelligence is now part of daily business but creates fresh problems like
data poisoning and fake content. These quickly turn into governance issues directors
must handle.
Directors’ Duties under Section 166
Section 166 of the Companies Act, 2013 is clear: every director must act with due
care, skill, diligence and independent judgment in the company’s best interest.
In today’s digital world, this duty includes cybersecurity. Directors have to put cyber
risk on the board agenda, invest properly in security, ensure compliance with CERT-
In, DPDP and other rules, and watch supply-chain risks. Ignoring foreseeable threats
– especially mandatory audits – can be a breach of fiduciary duty. Personal liability is
now real.
The Road Ahead
India’s digital economy is racing ahead, but cybersecurity governance is still catching
up. The DPDP Act, CERT-In audits and 2026 IT Rules are good steps, yet gaps
remain for small businesses and overlapping rules.
As an LL.M student focusing on corporate and cyber law, this topic really stands out
to me. Cybersecurity is not optional anymore. For directors – especially in MSMEs –
it is a real fiduciary responsibility under Section 166. Boards that take it seriously will
protect companies, keep investors happy, and support safe digital growth. Those
who don’t risk heavy losses, fines and damaged reputation.
The old “just tick the box” thinking must go. Directors must lead from the front –
because one weak decision at the top can affect lakhs of people.
Khaja Riyazuddin
LLM 4 th Sem