AI is now attacking India’s mid-market. Most companies won’t know until it’s too late

/ 5 min read
AI Hub

Large enterprises in India have built out security operations centres, retained managed detection and response contracts, and staffed dedicated incident response functions.

An industry report on data security found that 65% of organisations in India have already experienced a deepfake-driven attack, and 64% now rank AI-enabled attacks as their top data security risk
An industry report on data security found that 65% of organisations in India have already experienced a deepfake-driven attack, and 64% now rank AI-enabled attacks as their top data security risk | Credits: Getty Images

In the last year, most of my conversations with IT and security leads at Indian mid-market companies have started the same way. They ask about AI. Not how to use it defensively, but whether the sophisticated, AI-generated attacks they keep reading about will come for a company their size. My answer has changed. Two years ago, I would have said the large enterprises are the bigger draw for serious attackers. Today I tell them the opposite is closer to true, and the reason has less to do with who attackers prefer and more to do with who can see the attack in time.

ADVERTISEMENT

Large enterprises in India have built out security operations centres, retained managed detection and response contracts, and staffed dedicated incident response functions. Most mid-market companies I work with, typically 200 to 2,000 employees, run security within an IT team of two or three people who also handle helpdesk tickets, patching, and vendor management. That gap in headcount did not matter as much when attacks unfolded over weeks. It matters enormously now that AI has compressed the timeline to days.

The advisory that changed the conversation

In April 2026, CERT-In issued a high-severity advisory warning MSMEs and resource-constrained organisations specifically that AI-enabled attacks could carry out credential theft, targeted social engineering, and service disruption at a speed and scale that previously required teams of skilled human operators. That last phrase is the part worth sitting with—at a speed and scale that previously required teams of skilled human operators. AI has not necessarily made attacks more sophisticated in a technical sense. It has removed the labour-intensive bottleneck that slowed attackers down. A single operator can now run reconnaissance, draft a convincing spear-phishing message in fluent Hindi or English, and clone a CFO's voice for a follow-up call, all in a single afternoon.

ADVERTISEMENT

This shows up in the India-specific data. An industry report on data security found that 65% of organisations in India have already experienced a deepfake-driven attack, and 64% now rank AI-enabled attacks as their top data security risk. Credential theft is the leading technique used against cloud infrastructure in India, cited by 68% of organisations. A separate industry threat report on the Indian market puts AI-generated phishing and business email compromise at around 22% of tracked incidents, and notes these are increasingly reinforced with deepfake audio or video.

The clock, not the toolkit

Sophos recently published its AI Security 2026 report drawing on incident response and managed detection casework across more than 625,000 organisations worldwide, and it put a number on what CERT-In was warning about in the abstract. It documented a case where a threat actor ran roughly a dozen AI agents inside a compromised network to write and test attack code against several major endpoint security products, producing close to 80 modules and more than 70 evasion techniques. Work that would ordinarily take a human team weeks was done in a few days. The report was careful to note that AI has not yet invented new categories of attack. It has simply removed the time a defender had to notice and respond before an attack reached operational readiness.

That same research flagged something mid-market companies in India should pay close attention to. As more teams adopt AI coding assistants, agents, and third-party AI tools, the OAuth tokens, API keys, and service accounts behind them are becoming a new attack surface, often with weaker governance than the controls applied to a human employee's login. A compromised AI agent credential can open a path into a network the same way a stolen password does, except almost nobody is reviewing what permissions that agent quietly accumulated over the past six months. For a mid-market team that has enthusiastically rolled out AI tools to boost productivity without a parallel review of what access those tools now hold, this is a gap that did not exist 18 months ago and rarely appears on any audit checklist today.

Why sophistication is not the decisive factor

Here is the part that matters for a company running security with three or less people. Our State of Ransomware 2026 report, based on India-specific findings found that 81% of ransomware attacks in India now begin with identity compromise rather than a technical exploit, higher than the 79% global average. Even more striking: multi-factor authentication was already in place in 98% of these Indian incidents, yet failed to prevent the breach—nearly matching the global figure of 97%. This was the first time in more than three years that identity compromise, rather than an exploited vulnerability, became the leading route in. An identity-based intrusion does not trip the alarms in the same way a malware infection would. It looks, in the logs, like someone logging in with a valid password. The only thing that catches it is a person or a system actively watching for behaviour that does not fit a pattern, and doing so continuously, not during business hours.

Recommended Stories

This is where enterprise and mid-market genuinely diverge, and it is not about budget for the flashiest tool. It is about coverage. An industry benchmarking report on breach costs shows that organisations using AI and automation extensively in their own defences cut the time to identify and contain a breach by roughly 80 to 100 days compared with those that do not. That gap exists because faster detection depends on constant, automated correlation of signals across endpoints, identity, and network activity, paired with someone able to act on what the system flags at 2 a.m. on a Sunday. A three-person team can buy the same detection software an enterprise uses. What they usually cannot do is the round-the-clock watching every day of the year.

Our 2025 Annual Threat Report reinforces that this is not a small-business problem that enterprises have outgrown. Ransomware accounted for 70% of incident response cases involving small businesses in 2024, and more than 90% for midsized organisations, a higher share than at the small-business end. Separately, an industry tracking report on ransomware victims puts the median size of a ransomware victim organisation at 228 employees. The mid-market is not collateral damage in attacks aimed elsewhere. It sits squarely in the range attackers are hitting most often, and it is the range least likely to have continuous monitoring in place.

ADVERTISEMENT

What this changes for a mid-market security leader

None of this means the answer is buying more tools. In my experience walking mid-market teams through their environment, the companies in the best position are not the ones with the largest security budget. They are the ones that have decided, deliberately, how identity activity and endpoint behaviour get watched outside working hours, whether that is a rotation among existing staff, a managed detection service, or some combination of the two. They have enforced MFA

everywhere, including on the accounts everyone assumes are already covered. They keep a current list of every AI tool, agent, and third-party integration connected to their systems, and review what access each one actually has, not just what it was originally granted. They test their backups by restoring from them, not just confirming a backup job completed. None of that requires enterprise headcount. It requires treating detection speed as a business continuity decision that sits with leadership, not a line item that gets deferred to whenever the IT budget allows for it.

Most Powerful Women In Business 2026
View Full List >

The uncomfortable truth is that most mid-market leaders still think about this threat in terms of how advanced an attacker's tools are. The more useful question is how long it would take their own team to notice something wrong at 3 a.m. on a public holiday, and what happens in the hours before anyone does. AI has not changed what good security practice looks like. It has considerably shortened how much time a company has to get the basics right before the gap becomes visible—the hard way.

(The author is director, Sales Engineering, Sophos. Views are personal.)

NEXT STORY