A Cybersecurity Perspective on the Risk Hiding in Plain Sight — Your Own Team
Every small business owner pictures the same villain when they think about a cyberattack: a hooded figure in a dark room, breaking through a firewall from thousands of miles away. It's a comforting image, because it puts the threat safely outside the building.
It's also wrong more often than most owners realize — and under India's Digital Personal Data Protection Act, 2023, that misconception now carries legal consequences, not just operational ones.
The employee who forwards a client list to a personal email before resigning. The contractor who reuses a weak password across a dozen client accounts. The well-meaning staff member who pastes sensitive customer data into a public AI chatbot to "save time." None of these people set out to cause a breach. But under DPDP, intent is irrelevant to liability. The law doesn't ask whether your employee meant to expose personal data — it asks whether your organization had "reasonable security safeguards" in place to prevent it. For most SMBs, insider risk is precisely where that safeguard is weakest.
A common misconception is that DPDP obligations scale with company size — that a 20-person business somehow carries lighter duties than a hospital chain or a bank. It doesn't. The Act defines any entity that determines the purpose and means of processing digital personal data as a Data Fiduciary, with no carve-out for headcount or revenue. If your business collects customer names, phone numbers, payment details, or employee records digitally, you carry the same fiduciary duty as a large enterprise — including the obligation under Rule 6 to implement safeguards such as encryption, access controls, and audit logging, and the obligation to report a personal data breach within 72 hours of becoming aware of it.
That last point deserves emphasis: a breach doesn't have to come from a hacker to trigger this clock. If an employee emails a customer database to a personal account, or a departing staff member walks out with access to your CRM, that is a personal data breach under DPDP — and it starts the same 72-hour notification obligation as a ransomware attack would. Most SMBs are simply not built to detect an insider incident quickly enough to meet that window, let alone respond to it.
According to the Ponemon Institute's 2026 Cost of Insider Risks Global Report, sponsored by DTEX, negligent employees were the root cause of 53% of insider incidents in 2025, malicious insiders accounted for 27%, and credential theft made up the remaining 20%. Roughly three out of every four insider incidents involve no criminal intent at all — just an employee who clicked, shared, or stored something they shouldn't have. Under a consent-and-accountability framework like DPDP, "we didn't mean to" is not a defense; it's the exact failure the law is designed to catch.
For smaller organizations, the same research puts the average annual cost of insider risk exposure at roughly $8 million for companies under 500 employees. Containment isn't fast either — the industry-wide average time to contain an insider incident sits at 67 days, with only 13% resolved inside 30 days. That containment gap matters enormously under DPDP: a business that takes 67 days to even understand what happened cannot credibly meet a 72-hour disclosure obligation.
The broader SMB threat picture reinforces the urgency. The Verizon 2025 Data Breach Investigations Report found that ransomware now appears in 88% of breaches affecting small and mid-sized businesses, compared with 39% at large enterprises. The Identity Theft Resource Center's 2025 Business Impact Report found that 81% of small businesses experienced a security breach, data breach, or both in the preceding twelve months. And StrongDM's 2025 research found that 59% of SMB owners with no formal security program believe their business is too small to be worth attacking — a belief that, under DPDP, doesn't just increase your risk of a breach. It increases your risk of being found non-compliant when one occurs, since "we didn't think it applied to us" carries no weight with a regulator.
Large organizations build entire teams around insider risk. Most SMBs have none of that — and the resulting gaps are exactly where DPDP's "reasonable security safeguards" requirement gets exposed:
* Access sprawl. Everyone has access to everything because granular permissioning takes time nobody has — directly at odds with DPDP's expectation of role-based, purpose-limited access.
* Informal communication habits. Client data moves through WhatsApp and personal email because there's no approved alternative — data leaving controlled systems entirely, outside any auditable trail.
* No exit protocol. Departing employees retain system access for days or weeks, an unmonitored window in which fiduciary data remains exposed with no accountability trail — precisely what Rule 6's audit-logging requirement exists to prevent.
* Unmanaged AI use. Staff paste customer records into free AI tools to save time, unaware this may constitute unauthorized processing or cross-border transfer of personal data under the Act.
None of these are exotic attack techniques. They're everyday operational gaps — and each one is a DPDP compliance gap wearing an IT-hygiene disguise.
Here's the encouraging part: insider risk responds dramatically to training, and that responsiveness is exactly what regulators expect a fiduciary to demonstrate. One of the largest phishing benchmarking studies conducted to date — analyzing more than 67 million simulated phishing attempts across 14 million employees worldwide — found a global baseline "phish-prone" rate of 33.1% before any structured training. After 90 days of consistent training, that rate fell by 40%. After twelve months of continuous training, it dropped to 4.1% — an 86% overall reduction from baseline.
The Verizon 2025 Data Breach Investigations Report adds important context: 60% of all breaches still involve a human element, with a median gap of just 21 seconds between an employee opening a malicious email and clicking the link — a window too short for technology alone to close. The data is unambiguous either way: training isn't a compliance checkbox. It's one of the most measurable risk-reduction levers available to any organization, regardless of which platform delivers it.
1. Tighten access to a "need it, not nice to have it" standard. This directly satisfies DPDP's expectation of access controls proportionate to risk, and closes the single largest source of insider exposure.
2. Formalize offboarding, with a timestamped log. Revoke every departing employee's access on their last working day — and record it. That log becomes your evidence of reasonable safeguards if a regulator ever asks.
3. Replace informal channels with approved, auditable ones. Give staff a sanctioned tool for moving client data instead of WhatsApp or personal email — this closes an unmonitored channel DPDP expects fiduciaries to control.
4. Set clear rules for AI tools, including what data may never be entered into an external platform.
5. Invest in ongoing awareness training. Industry data makes the case clearly: consistent, year-round training can cut employee susceptibility to phishing and social engineering by well over 80%. It isn't better firewalls that close this gap — it's sustained training, and it's also the clearest, most demonstrable safeguard a small business can point to under DPDP.
DPDP doesn't ask whether your business is large enough to be a target. It asks whether you built reasonable safeguards around the data you hold — and insider risk is where that question gets answered fastest, because the threat isn't trying to get in. It's already inside, with legitimate access and, all too often, no oversight at all.