Secure, compliant and future-ready enterprises

      As organisations accelerate digital transformation, embrace cloud technologies and navigate evolving regulatory requirements, cyber risk and compliance have become critical business priorities. Managing technology risk today requires a holistic approach that balances innovation, security, governance and compliance while maintaining stakeholder trust.

      KPMG in India's Cyber Risk and Compliance practice helps organisations identify, assess and manage cyber and technology risks across their digital ecosystem. Leveraging expertise in cyber strategy, governance, risk management, compliance, cloud assurance, privacy, resilience and technology assurance, we help clients strengthen security, address regulatory obligations and support business growth.

      Bringing together capabilities across cyber strategy and governance, cyber maturity assessments, risk and compliance programmes, data privacy, third-party risk management, cloud assurance, IT internal audit, ERP security, responsible AI, technology controls and business resilience, we help organisations enhance risk visibility, strengthen governance and build confidence in their digital operations.

      Whether responding to regulatory change, strengthening cyber governance, assessing technology risks, enhancing digital trust or modernising assurance functions, we help organisations improve resilience, transparency and long-term business value through practical and outcome-focused solutions.

      DPDPA compliance is a transformation journey, not a last-minute fix.

      With 13 May 2027 on the horizon, the clock is already ticking.

      --

      Creating a trusted digital world together

      Whether you’re entering a new market, launching products and services, or interacting with customers in a new way, KPMG in India can help you anticipate tomorrow, move faster and get an edge with technology that is secure and trusted. That’s because we can bring an uncommon combination of technological expertise, deep business knowledge, and creative professionals who are passionate about helping you protect and build your business.

      Creating a trusted digital world together

      Our offerings

      New technologies. Sales channels. Customer experiences. Does your organisation have the confidence and agility to seize these kinds of opportunities, or are cyber threats holding you back?

      Cyber risk, compliance and audit functions are the cornerstones to manage risks while organisations make progress on strategic growth initiatives
      Stop playing defense optimise your Security Operations Center for real impact

      Stop playing defense optimise your Security Operations Center for real impact

      SOC Efficacy and Maturity Assessment measures your SOC’s effectiveness across people, processes, technology, services, and strategy and governance. It benchmarks maturity against industry standards, identifies gaps, and delivers a phased roadmap with actionable recommendations for continuous improvement.

      IRDAI Mandates Incident Response Retainership

      IRDAI Mandates Incident Response Retainership

      As per the recent IRDAI (Insurance Regulatory and Development Authority of India) circular dated 24 March 2025, IRDAI has laid down some guidelines regarding cyber incident and crisis preparedness for all regulated entities.


      Driving growth with Cyber and Compliance trends

      Kunal Pande

      National Leader - Cyber, Risk and Compliance Services

      KPMG in India

      As smaller businesses accelerate their digital journey, trust concerns often stem from:
      • gaps in access controls,
      • oversharing of sensitive data, and
      • misconfigured security systems.

      The conversation should move beyond investing in security solutions. Lasting trust is built when organisations exercise sound judgement over their data and ensure security controls are configured and managed effectively

      Kunal Pande

      National Leader - Cyber, Risk and Compliance Services

      KPMG in India

      While, businesses are experiencing meaningful value from AI, most are concerned about data security, privacy and AI induced risks.

      Recent RBI advisories rightly focuses on the two important aspects:

      • Having strong governance for responsible and safe use of AI and
      • Strengthening capabilities against AI accelerated cyberattacks.
      Rahul Singhal

      National Co-Head - Cyber Assurance

      KPMG in India

      Generative AI brings immense promise, but trust will depend on going back to the basics. It starts with solving the right problems, using the right data, and understanding the risks that extend beyond security. True confidence in AI comes from human validation, cross‑functional collaboration, and compliance with emerging regulations. Building trusted AI is not a choice for tomorrow, it is a responsibility for today.

      Kunal Pande

      National Leader - Cyber, Risk and Compliance Services

      KPMG in India

      In an era where every click, nudge, and interface decision can influence customer behavior, transparency and fairness must be engineered into the user journey itself. India Dark Patterns Guidelines mark a pivotal shift requiring such capabilities to be embedded into the digital journeys ensuring that digital experiences empower users, not exploit them.

      Rohan Padhi

      Partner, National Co-Lead, Digital Risk and Cloud Security

      KPMG in India

      Given the proliferation of digital channels in driving modern day commerce, the Dark Pattern guidelines are important guardrails for protecting the consumer’s interest. With these guidelines in place, India joins a select group of nations which have enforced this.

      Sony Anthony

      Partner and Head of Department – Cyber Defence and Incident Response

      KPMG in India

      As the DPDP Act begins to take effect, organisations are starting to look beyond compliance and focus more deeply on accountability, governance, and trust in how data is managed.

      The line between vulnerability discovery and weaponisation has collapsed exponentially. If the security posture still relies on manual triage and weekly patch cycles, you're treating an AI-speed problem with a human-speed solution.

      The metric for success is no longer how fast we find exposure, it's how rapidly we translate that intelligence into actionable, risk-based resilience

      Rupak Nagarajan

      Partner, Cyber Strategy & Govn
      KPMG in India

      The DPDP Act marks a fundamental shift in how organisations think about handling personal data. The conversation is moving beyond compliance towards building trust, strengthening governance and responsible innovation.

      For businesses navigating an increasingly digital ecosystem, privacy is becoming a strategic differentiator that provides competitive advantage.

      Kunal Pande

      National Leader - Cyber, Risk and Compliance Services

      KPMG in India

      As organisations accelerate adoption of AI, cloud, and emerging technologies, the conversation today is no longer just about transformation - it is about enabling trusted and responsible transformation at scale.

      Organisations need to implement secure-by-design practices, continuous monitoring, automation for rapid response action as well as technology-enablement of governance for machine speed decisioning to confidently innovate with greater speed, resilience, and trust. In a cloud environment, one additionally requires a clear understanding of shared responsibility model, deploying right security controls and crucially maintaining unified view of the entire environment.

      Kunal Pande

      National Leader - Cyber, Risk and Compliance Services

      KPMG in India

      • In our 'always-on' world, digital trust is earned when a service is not just convenient, but consistently available and inherently secure. Beyond the code, trust is psychological - a user’s confidence that a system will act in their best interest without cause for harm. Building digital trust today requires a convergence of reliability, resilience, and an infrastructure agile enough to pivot with business needs while responding instantly to security events. Ultimately, this trust is solidified through robust communication, ensuring the user is not only protected but remains consciously aware and confident in the system’s integrity.
      • Digital trust is the intersection of technical security and resilience, and psychological safety. It is built when 'fit-for-purpose' services are consistently secure and available, backed by an infrastructure that can adapt to user needs and security threats at lightning speed. To trust a system is to believe it will act in our interest, every single time.
      Akhilesh Tuteja

      Partner & National Leader, Clients and Markets

      KPMG in India

      While the large corporations in India may be ready for the new DPDP rules, the ecosystem of partners, vendors, suppliers, etc. may not be ready - this is one of the significant holes in the entire readiness for our country. Smaller organisations have a lower level of understanding to start with, and also sometimes implementation of DPDP rules.

      It's not the notice, it's not the consent, it's not about getting your system right, it's about getting your ecosystem right. Because larger organisations will take several months just to educate their ecosystem partners what it is, why is it important, even before they start to put the first process in.

      Atul Gupta

      Partner and Head - Digital Trust and Cyber

      KPMG in India

      DPDPA rules build on the pragmatic approach adopted while publishing the act, which is evident from the additional considerations for significant data fiduciaries and prioritising identified industry segments. These rules will enable addressing the wider issue that the citizens and consumers face today of mass data proliferation across digital channels and need of adequate protection around digital data. Having a data protection board shall lead to stronger enforcement and will go a long way in addressing the vision as part of Digital India and Viksit Bharat.

      Nitin Shah

      Partner, DT-Cyber Strategy and Govn
      KPMG in India

      The Digital Personal Data Protection Act empowers India Inc to put customers at the heart of digital transformation. By giving individuals greater control over what data is processed, why it’s processed, and how outcomes are delivered, organisations can build trust as the foundation for innovation and growth.

      Akhilesh Tuteja

      Partner & National Leader, Clients and Markets

      KPMG in India

      Human intelligence has driven modern economies; the next phase of growth will depend on how well we harness intelligent data. As this report suggests, data risk is market risk. Treating data as core market infrastructure is critical for India to sustain market leadership and investor confidence.

      Hear from the experts

      For MSMEs, trust is built on getting the fundamentals right. As smaller businesses accelerate their digital journey, trust concerns often stem from gaps in control, oversharing of sensitive data and misconfigured security systems

      Insights from the new 2026 KPMG global TPRM study

      Akhilesh Tuteja shares his insights on cybersecurity skills in an AI-first world.

      While the large corporations in India may be ready for the new DPDP rules, the ecosystem of partners, vendors, suppliers may not be ready, this is one of the significant holes in the entire readiness for our country.

      Akhilesh Tuteja in conversation with Business Standard on the new DPDP Rules.

      Akhilesh Tuteja shares his insights on the new DPDP rules 2025 with The Core.

      Watch the webinar to understand how to run compliance into advantage and build a credible privacy foundation

      Cybersecurity is no longer what it used to be. Attackers use AI for deepfakes, blurring truth and fiction. AI systems change by design, complicating protection. Risks come from outside organisations, by targeting small companies to attack big systems.

      Akhilesh Tuteja shares his insights on the Data Protection Act in India.

      India Insights

      Our insights is your gateway to thought leadership and in-depth reports. Explore our curated collection of valuable content, where we delve into complex business challenges, share industry trends, and provide actionable insights.

      Evolving regulatory landscape around dark patterns signals a shift towards greater accountability for how consumer choices are designed and presented

      Key war time considerations for data centres and the shift towards resilient and survivable future designs

      Read more

      Supporting organisations with integrated cyber risk, compliance, and assurance solutions for sustainable growth
      Read more

      Building trust and enabling innovation in a dynamic world

      A forward-looking view on how trusted, intelligent data can accelerate the next phase of innovation and market growth in India’s securities ecosystem

      Transform your risk management strategy for the future by integrating AI

      Aviation milestones reflect not just expansion but promises deeper connectivity and a far more complex domestic and international network

      DPDPA demands strong vendor oversight, data minimisation, clear consent, rapid breach response and protection across IoT and smart rooms

      DPDP Act 2023, through the 2025 Rules, defines a techno‑legal, enforceable framework for GCCs to safeguard digital personal data

      DPDPA aims to strengthen the techno-legal framework for protection of digital personal data by providing necessary details and an actionable framework

      This PoV explores India’s SBOM regulations, outlining an approach to help ensure compliance and strengthen supply chain security

      RBI has released directions requiring all digital payment transactions in India to be authenticated using two-factor authentication (2FA)

      The DPDP Rules 2025 serves as a crucial extension to the DPDP Act 2023, providing operational clarity for entities processing digital personal data

      RBI’s FREE framework sets guiding principles and actionable steps for regulators, industry, and policymakers

      RBI has published a directive applicable to Banks in India to mandate stricter AePS controls, which will come into effect on 1st January 2026

      A guide for regulated entities to operate securely within UPI, aligned with evolving cybersecurity standards and regulatory expectations

      India is proactively harnessing the power of tech-led innovation to carve its unique path of digitalisation with AI

      A successful attack on business applications could lead to financial losses, operational disruptions, reputational damage, and regulatory penalties

      In an AI-dominated business environment, the foundational principles of cybersecurity are even more critical

      Key Contact

      Kunal Pande

      National Leader - Cyber, Risk and Compliance Services

      KPMG in India

      Connect with us

      Contact our specialists for more information

      connect with us