By Digvijaysinh Chudasama, Partner, Deloitte India
India’s digital economy is expanding at speed, with AI, cloud services, digital payments and connected infrastructure now central to everyday life. As India’s digital footprint grows, cyberattacks are no longer limited to data theft.
Such attacks can also threaten the availability of essential services, from digital payments and healthcare to power, transport and public services. India’s cybersecurity strategy must shift from prevention alone to resilience, so that the systems remain available, secure and can recover quickly even when attacks succeed.
Why resilience matters
Traditional security was designed to anticipate and stop attacks before they happened. That model is under pressure today, as attackers use advanced tools, zero-day vulnerabilities and social engineering to bypass defences. Trying to outrun them at machine speed is no longer enough. The emphasis needs to be on acknowledging that some attacks will succeed, while ensuring that they do not have catastrophic consequences.
When ransomware brought down essential systems at a major public healthcare institution, staff had to manage patient registration, appointments, admissions, billing and medical reports manually. Most services were restored within two weeks.
In another case, attackers used a compromised employee email account to access sensitive information and publish it on the dark web. For government and PSU systems that support utilities, citizen services and public-sector banking, the consequences can be much greater. These incidents are a clear reminder that cyber resilience is about protecting data and keeping essential services running.
Practical methods to build resilient infrastructure
Risk management
Plan for AI and automation risks: AI and automation also create risks. They can fail, behave unexpectedly or be misused, especially in live environments. Recent incidents involving AI tools show that automated tools also need clear guardrails. That is why clear guardrails, monitoring, isolation and containment must be built in from day one.
Check the new software before use: New programmes or any updates should be tested extensively before use. New versions of third-party packages should be admitted into production after a short cooling period (for example, 30 days) and automated checks. This reduces the risk of compromised updates spreading across critical systems.
Limit credentials and access: Credentials and access must also be controlled. Short-lived passwords and tokens should be used wherever possible. Access should be given only when it is needed, and only for the specific work required. This makes it harder for hackers to use stolen credentials to move deeper into systems, as seen in several banking-sector incidents.
Resilient architecture
Isolate workloads: Workloads should be isolated so that a compromise in one area does not affect the rest of the environment. Network microsegmentation, strict API gateways and workload-specific identities reduce lateral movement and make forensic containment tractable.
Recovery and backup: Rebuild regularly from a trusted source code. Production systems should be rebuilt regularly from a clean, approved version of the code that has been reviewed before use. This ensures that any hidden changes made by attackers on a running system are wiped out during the next rebuild. This decreases the time attackers can stay in the system, restricting their foothold until the next rebuild.
Maintain secure and recoverable backups: Backups should be stored separately from live systems, protected from unauthorised access or changes and tested regularly. This helps ensure that critical systems and data can be restored within the required timeframe following a cyber incident.
Business continuity and disaster recovery
Test continuity and recovery plans: Business continuity and disaster recovery plans should define critical services, dependencies, recovery priorities and alternative operating arrangements. Regular testing can help identify gaps before a disruption occurs.
Conduct cross-sector drills: Realistic exercises should be undertaken by public-sector undertakings and central agencies with banks, telecoms, technology providers and other critical collaborators. Scenarios should test end-to-end recovery against credential compromise, supply-chain attacks, service outages and AI containment failures.
Incident response
Detect and recover quickly. Not every attack can be stopped before it begins. Effective detection identifies breaches and security gaps early. With AI, it should also trigger immediate action, including revoking stolen credentials, isolating affected systems and restoring safe versions.
Deploy crisis playbooks and cross-sector drills. Crisis playbooks should define roles, when to escalate, how to communicate and contain an incident. Regular drills allow teams to respond quickly and consistently. This helps organisations to stay resilient, while continuing to innovate and grow.
Resilience through sovereignty
Strong resilience depends on practical regulations and incentives. The government should define minimum security standards for essential services. These should cover clean system rebuilds, log retention, and checks on software providers and upgrades. Procurement should favour providers that follow secure development practices, enforce strong access controls and recover quickly from disruptions.
The path ahead
India should reduce its dependence on external technologies and invest in domestic skills. This will help the country respond more effectively to evolving threats. Prevention will always matter, but the defining capability will be operational resilience.
It recognises the practical truth that attacks will happen, but with the right design, their impact can be contained, and recovery can be swift. This is how India secures its digital future.