Cyber attacks remain top business risk for Indian firms amid widening cyber resilience gap

Indian organisations continue to identify cyber attacks and data breaches as their top business risk, even as businesses strengthen formal response mechanisms, according to insights from Aon’s Global Risk Management Survey 2025.

The survey found that 92.9% of organisations in India have formal plans and review processes for cyber attacks. However, the rapid adoption of artificial intelligence, cloud platforms, digital technologies and third-party service providers is creating new vulnerabilities and complicating efforts to assess exposure and financial losses.

Aon said cyber resilience needs to be treated as an enterprise-wide risk involving governance, operations, business continuity, risk financing and leadership decision-making. The emergence of AI as a major future business risk further highlights the changing threat landscape.

There are signs of stronger risk management. About 70% of Indian respondents have dedicated risk management and insurance departments, while 64.9% actively measure the total cost of insurable risk. Further, 64.7% are addressing data privacy risks and 91.9% are using captive insurance solutions.

In Kolkata,  the findings are particularly relevant for businesses operating across financial services, IT, manufacturing, logistics and digitally enabled sectors, where dependence on interconnected systems and third-party platforms makes business continuity increasingly important.

Aon Cyber Leader and Vice President Apurva Gopinath said organisations need to move beyond compliance-led preparedness towards measurable cyber resilience, using metrics such as incident response and recovery times to guide investment decisions.