Cyber attacks on Indian businesses increased by 300% between 2022 and 2025. Shockingly, over 60% of all cyber attacks target small and medium businesses โ not large corporations. Why? Because SMEs typically have weaker security but valuable data.
In 2023, Mahir Technology conducted VAPT (Vulnerability Assessment & Penetration Testing) for a Dubai-based MNC. In 2025, we did the same for an e-commerce business in Kenya. What we found in both cases: basic security hygiene was missing. The same is true for most businesses in Gujarat and India.
Here is your 15-point cybersecurity checklist. Go through each point and honestly assess where your business stands.
Network Security (Score yourself 1-5 for each)
- โ Next-Generation Firewall installed and configured โ Not just a basic router firewall. An NGFW (Fortinet, Palo Alto, Sophos) inspects all traffic entering and leaving your network.
- โ Wi-Fi network segmented โ Guest Wi-Fi should be completely separate from your business network. Never give clients or visitors access to your corporate Wi-Fi.
- โ VPN for remote access โ All employees working from home or on the go should connect via a secure VPN. Not using free VPN services.
- โ Regular firmware updates on all network devices โ Routers, switches, and access points need regular security patches.
Endpoint Security
- โ Endpoint Detection & Response (EDR) on all devices โ Traditional antivirus is not enough. EDR tools detect and respond to threats in real time.
- โ All devices encrypted โ Full disk encryption on all laptops. If a device is stolen, data remains unreadable.
- โ Auto screen lock enabled โ Devices should lock automatically after 5 minutes of inactivity.
- โ Mobile Device Management (MDM) โ If employees use phones for business email or data, those devices must be managed and can be remote-wiped.
In 2025, a retail business in Surat lost โน34 lakhs when an employee's laptop was stolen. The laptop had no encryption and no MDM. All customer data โ including payment information โ was compromised.
Data & Access Security
- โ Multi-Factor Authentication (MFA) on all business accounts โ Email, cloud storage, banking, ERP โ everything should require a second factor beyond password.
- โ Role-based access control โ Employees should only access data they need for their job. Not everyone needs access to payroll or client financial data.
- โ Regular data backups โ tested and offsite โ The 3-2-1 rule: 3 copies of data, 2 different media, 1 offsite (cloud). And test your backups regularly.
- โ Strong password policy enforced โ Minimum 12 characters, complexity requirements, and a password manager for your team.
Compliance & Risk
- โ DPDP Act compliance assessment done โ India's Digital Personal Data Protection Act is now enforced. If you handle customer personal data, you must assess your compliance obligations.
- โ Employee security awareness training โ 85% of cyber breaches involve human error. Your employees are your biggest vulnerability โ and your best defence when trained properly.
What is VAPT and Does Your Business Need It?
VAPT โ Vulnerability Assessment and Penetration Testing โ is a professional security audit where certified experts simulate cyber attacks on your systems to find weaknesses before real attackers do.
You should get VAPT done if:
- You handle customer financial data, health records, or personal information
- You have an e-commerce website or customer portal
- Your business operates in banking, insurance, healthcare, or government
- You have not had a security audit in the last 12 months
- You are expanding internationally or working with MNC clients who require security compliance
Mahir Technology has conducted VAPT engagements for clients in India, Dubai, and Kenya โ giving us a truly global perspective on cybersecurity threats facing businesses today.
16+ years in enterprise IT. Founder of Mahir Technology โ cloud, Apple, VMware, SAP B1, and cybersecurity partner in Vadodara serving clients across India and globally.
Connect on LinkedIn โ