Skip to main content
India's Premier Invitation-Only Executive Network
insights icontechnologycybersecurityboard-governance

Cybersecurity Governance: Why Boards Are Finally Taking It Seriously — and What That Means in Practice

A
Admin CXO India
2 min read
2 min read

A combination of high-profile incidents, regulatory pressure, and growing director liability awareness has shifted cybersecurity from IT department concern to board priority. The governance response is still catching up.

Cybersecurity Moves From the Audit Committee to the Full Board

CXO India has observed a marked change in how cybersecurity is discussed in Indian boardrooms over the past eighteen months. The topic has migrated from a standing item on the audit committee agenda — where it received fifteen minutes and a status-green assurance from the IT team — to a substantive strategic risk discussion at the full board level. Several factors have driven this shift, and understanding them helps boards avoid the most common governance mistakes as they raise their engagement.

Regulation Has Raised the Governance Stakes

The regulatory factor is significant. Three developments have collectively raised the governance stakes for Indian boards in a way that is hard to ignore:

  • SEBI's cybersecurity circular for market intermediaries
  • The RBI's ongoing enhancement of cybersecurity norms for regulated entities
  • The Ministry of Electronics and IT's work on data protection compliance

Directors who fail to provide adequate cybersecurity oversight now face more clearly articulated regulatory risk than they did two years ago.

Recent Incidents Have Made the Threat Concrete

The incidents factor is perhaps more viscerally motivating. Several significant cyberattacks on prominent Indian organisations in 2024 and 2025 have made clear that large, well-resourced Indian companies are not immune to sophisticated attacks, and that the reputational and operational consequences of a significant breach are severe enough to constitute a material risk to shareholder value.

What the Boards That Are Ahead Have Done

The boards that are genuinely ahead of this challenge have taken several specific steps:

  • Appointed at least one director with substantive cybersecurity experience
  • Separated the cybersecurity discussion from the general IT discussion
  • Established a clear accountability structure for cyber risk management at the executive level
  • Conducted at least one tabletop exercise simulating a significant incident
Back to Insights
#cybersecurity#board-governance#risk-management#SEBI#data-protection

Related insights

More from CXO India

Executive insights, market intelligence, and leadership spotlights — curated for India's C-suite.