For many years, business owners treated cybersecurity as a technical matter to be handled by the IT department. In my view, that approach is no longer sufficient.
A cyber incident can interrupt operations, expose confidential information, damage customer confidence and affect a company’s reputation. These are not merely computer problems. They are business and leadership problems.
Preparation must begin before an incident
Leaders should know what information their organisation holds, who can access it and how frequently it is backed up. Employees must receive practical training because many attacks begin with an ordinary-looking email, message or link.
Basic discipline matters: strong passwords, multi-factor authentication, updated software, limited access rights and tested backups. These measures may sound simple, but ignoring them can make an organisation unnecessarily vulnerable.
Responsibility cannot be outsourced completely
Businesses naturally depend on technology vendors and cybersecurity professionals. However, appointing an expert does not remove the leadership team’s responsibility.
Management should know who will respond if systems stop working, which authorities or clients may need to be informed, and how essential operations will continue. A response plan that has never been tested is only a document.
India’s CERT-In directions also establish specific reporting and record-maintenance requirements for covered organisations. Companies should obtain professional technical and legal advice to ensure that their procedures meet the applicable requirements.
Trust is the real asset at risk
Customers, employees and partners share information with a business because they expect it to be handled responsibly. If that trust is damaged, technical recovery alone may not repair the relationship.
My personal view is straightforward: cybersecurity should be discussed in the boardroom just like finance, compliance and operational risk.
A responsible leader does not need to understand every line of code. But the leader must ask the right questions, allocate adequate resources and ensure that everyone knows what to do when something goes wrong.
Cybersecurity is ultimately not about creating fear. It is about preparedness, accountability and protecting the trust on which every serious business depends.
—Tushar Kumar
Official reference
CERT-In directions under Section 70B of the Information Technology Act