Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
IBM’s 2024 Cost of a Data Breach Report put the average cost of a breach involving an Indian organisation at ₹19.5 crore, up 9% from 2023 and 39% from 2020. That is a study estimate of total economic impact—not a fine, ransom, or bill every company should expect. It is also a historical figure: later reporting put India’s 2025 average at about ₹22 crore. Business Standard’s subsequent coverage reports that later estimate.
What the ₹19.5 crore estimate includes
The ₹19.5 crore figure is the average total cost attributed to a data breach in the organisations covered by IBM’s India findings. It can include investigating and containing an incident, restoring systems, legal and response work, notifying affected people, lost business and disruption. It is not the value of stolen data, a standard compensation amount, or necessarily the amount paid to attackers.
Lost-business costs can reflect downtime, customers who leave, and reputational damage. Notification costs cover the work of informing affected people or organisations and managing related communications. Both can add substantially to direct technical recovery costs.
Recommended Free Tools
The estimate should not be read as a prediction for any particular organisation. Actual losses depend on factors such as the sensitivity and volume of data, how long systems are disrupted, sector, customer exposure, and the organisation’s ability to detect, contain and recover from an incident.
#1 Best Overall
- ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
- ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
- ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
- ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
- ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
Why costs rose
IBM’s report attributed much of the increase to lost business, which rose by about 45% year over year, and notification costs, up 19%. Detection and escalation costs rose 7% and were reported as the largest component of breach costs in India. These are reported changes in cost categories; they do not establish that any one factor alone caused the overall 9% increase.
Downtime and customer loss can turn a technical incident into a business crisis. A company may have to halt operations while it investigates, restore systems, determine what information was accessed and communicate with customers, partners or regulators. Complex environments and stretched response teams can make that work harder.
Common entry points are not always the costliest
The reported findings distinguish how often an attack route appeared from the average cost associated with a root cause. Phishing and compromised credentials were each listed as an initial attack type in 18% of the India cases; cloud misconfiguration accounted for 12%. Among the listed root causes, compromised business email had the highest average cost.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
| Measure | Finding in the India report coverage |
|---|---|
| Common initial attack types | Phishing: 18%; stolen or compromised credentials: 18%; cloud misconfiguration: 12% |
| Highest average cost among listed root causes | Compromised business email: ₹21.5 crore |
| Other high-cost listed root causes | Social engineering: ₹21.3 crore; phishing: ₹20.9 crore |
Business-email compromise can involve fraudulent payment instructions, invoice diversion or executive impersonation. Those are ways such incidents can create financial and operational damage; the listed cost figures do not mean every incident involved those specific tactics. Phishing and compromised credentials are frequent concerns, but frequency and financial severity are different measures.
Industrial breaches had the highest reported sector average
Among the Indian sectors listed in the coverage, industrial organisations had the highest average breach cost, followed by technology and pharmaceuticals.
| Sector | Average breach cost reported |
|---|---|
| Industrial | ₹25.5 crore |
| Technology | ₹24.3 crore |
| Pharmaceutical | ₹22.1 crore |
These are average costs in the study, not counts of which sectors suffered the most incidents. An industrial disruption, for example, may have costly effects on production and supply commitments, but the figures do not show that every industrial breach is more expensive than every breach elsewhere.
Rank #3
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Universal Connectivity (USB-C, USB-A, & NFC): Designed for PCs, Macs, iPhones, and Android. For mobile use, simply unfold the key, align it with your phone’s NFC antenna, and hold for a few seconds to authenticate.
- Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.
Cloud and hybrid environments can complicate response
In the India findings, 34% of the breaches involved data stored on a public cloud, while 29% involved multiple environments, such as public cloud, private cloud and on-premises systems. Breaches involving public-cloud data had the highest reported average cost at ₹22.7 crore. Incidents spanning multiple environments took an average of 327 days to identify and contain.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteThese findings do not mean that cloud adoption itself causes breaches. They point to the importance of configuration, identity and access controls, permissions, logging and consistent response procedures. When an incident crosses cloud and on-premises systems, investigators may need to reconcile different logs, owners and security controls—work that can slow containment.
Faster identification and containment were associated with lower costs
Organisations that identified and contained a breach in under 200 days recorded an average cost of ₹18.4 crore; those with a breach lifecycle longer than 200 days recorded ₹20.5 crore. A shorter response window can plausibly limit an attacker’s time to access data or disrupt operations, but this comparison is an association in the study—not proof that each additional day directly adds a fixed amount to a breach bill.
Rank #4
- USB-C or tap via NFC for easy authentication on any compatible device. No drivers needed; optional Kensington software available for advanced management features.
- Works across Windows, macOS, iOS, Android, ChromeOS, and supports Passkeys and Apple ID.
- Slim, keychain-ready form for easy carry and on-the-go authentication
- IP68-rated for dependable performance
- FIDO CTAP 2.1 for enhanced security features (e.g. resident credentials, Passkey support) and backwards compatibility with CTAP 2. FIDO2 L2 certified security for phishing resistant protection against identity theft and unauthorized access.
Security AI and automation showed a similar association. The report said 28% of Indian organisations in the study had extensively deployed these tools, compared with 20% in 2023; 35% reported limited use and 37% none. Extensive use was associated with a breach lifecycle 112 days shorter and average costs ₹13 crore lower. This is not a guaranteed saving or a causal return on investment: organisations that deploy more automation may differ in other ways, and tools need good data, tuning and human oversight.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What Indian organisations can take from the findings
The practical lesson is to reduce the chance of account compromise and make an incident easier to spot, contain and recover from. Priorities include:
- Protect high-risk identities. Use strong multifactor authentication, preferably phishing-resistant methods for privileged and sensitive accounts, and review access regularly.
- Harden email and payment workflows. Verify changes to supplier bank details and urgent payment requests through a separate trusted channel; train staff to report suspicious messages.
- Review cloud exposure. Check public access, excessive permissions, identity configurations and whether logs are enabled and retained across cloud accounts.
- Improve visibility and response. Bring identity, endpoint, email and cloud signals together where feasible. Set escalation thresholds and measure time to detect, contain and recover.
- Prepare for disruption. Maintain resilient backups and test restoration, not just backup completion. Exercise incident plans with IT, leadership, legal, communications and key vendors.
- Know where personal data sits. Map data stores and processors, preserve evidence during incidents, and establish who makes decisions about internal escalation and external communications.
Centralised monitoring and automation can help teams investigate more quickly, but they require usable logs, staffing and careful configuration. Restrictive access controls can reduce exposure but may create workflow friction; the goal is to apply stronger controls where the risk is highest and make recovery procedures work under pressure.
Best Value
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Regulatory context: prepare, but don’t confuse cost estimates with penalties
IBM’s India commentary connected the findings with the rollout of the Digital Personal Data Protection Act, 2023, and urged organisations to assess regulatory implications and end-to-end compliance. The report’s ₹19.5 crore estimate is an economic-cost measure, not a statutory penalty. Organisations should separately assess applicable data-protection, CERT-In, contractual and sector-specific requirements against current official rules and guidance. The study figures do not establish a particular legal deadline or penalty.
How to interpret the report
The report was researched by the Ponemon Institute and sponsored and analysed by IBM. Its global study covered 604 organisations with real-world breaches occurring from March 2023 through February 2024. The ₹19.5 crore result is IBM’s India estimate from that study—not a census of every Indian breach.
The available coverage does not establish the number of Indian organisations in the sample or provide enough detail to assess how representative it is by company size or sector. It also does not establish from the reported figures how costs were weighted, or whether particular accounting items such as ransom payments, insurance recoveries or avoided losses were included. Treat the number as a benchmark from a defined study, not a universal price tag. Smaller organisations may have lower absolute losses yet face more severe consequences relative to their resources.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchCurrentness: ₹19.5 crore was the India figure in IBM’s 2024 report, released on July 31, 2024, for breaches occurring between March 2023 and February 2024. It is not the latest India estimate: subsequent reporting put the 2025 average at approximately ₹22 crore. The two figures belong to different report years and should not be treated as one continuous measure without consulting the underlying reports.
Business Standard’s report on the India findings and Scroll’s summary of IBM’s study provide the reported figures and study context. For general security-control categories, see IBM’s cybersecurity overview.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

