Shifting from Reactive Defense to Proactive Cyber Resilience: Exposure Management in India
Cybersecurity threats have become increasingly sophisticated in India, with the average cost of a data breach rising to $195 million in 2024, a 39% increase since 2020. Amidst growing security investments, organisations continue to face breaches due to traditional vulnerability lists lacking business context. Rajnish Gupta, MD & Country Manager, Tenable India, explains how exposure management enables organisations to move from reactive defence to proactive risk reduction by providing contextual visibility into attack paths, minimising alert fatigue, and focusing on addressing vulnerabilities that truly impact business resilience.
Key Takeaways:
- Threat adversaries exploit established trust relationships between systems to create new attack paths, leveraging the interconnected nature of cloud, identity, IoT, and on-premises systems.
- Organisations have various security tools, but they rarely work well together, resulting in tool sprawl that bloats security budgets and worsens alert fatigue.
- Exposure management brings together all essential elements of a modern, risk-based strategy, allowing teams to close visibility gaps, expose possible attack pathways, protect what matters most, and cut through alert noise.
- Establishing complete and unified asset visibility is the first practical step to disrupting likely attack paths.
- Organisations must eliminate blind spots and achieve total visibility across the entire extended attack surface, from traditional IT and cloud infrastructure to identities and applications.
- Older systems pose significant risks due to their inability to integrate modern security, reliance on outdated identity controls, and poorly secured connection points to cloud applications.
- Automation is essential for managing massive volumes of security tasks, but human judgement is necessary for creative problem-solving and strategic input to avoid getting caught flat-footed by blind spots.
- CISOs can use exposure management platforms to present a comprehensive picture of risks and mitigation steps, highlighting critical exposures and explaining how they could lead to attack pathways that erode brand trust.
- Cybersecurity strategy must adapt to satisfy regulators', insurers', and board members' expectations by focusing on three shifts: establishing continuous and demonstrable due care, linking security controls directly to financial risk modelling, and delivering business-centric reporting of cyber risk.
Statistics:
- Average cost of a data breach in India increased to $195 million in 2024, a 39% increase since 2020.
- Tool sprawl and alert fatigue are significant issues due to the use of disparate security tools.
- India's breach costs have climbed, with organisations facing breaches due to traditional vulnerability lists lacking business context.
- $195 million: the average cost of a data breach in India in 2024.
- 39%: the increase in average cost of a data breach in India since 2020.
Sources:
- Interview with Rajnish Gupta, MD & Country Manager, Tenable India, in an interaction with CiOL.
- Data from various security tools and vulnerability lists.
- Reports and studies on cybersecurity and data breaches in India.