Key Points
- India reported Asia's third-highest ransomware incidence at over seven attacks hourly
- Crypto-ransomware accounted for 86 per cent of India's ransomware attacks
- Transportation and utilities sector saw fivefold growth in targeted attacks
India reported Asia’s third-highest ransomware incidence in 2014, with over seven attacks recorded every hour. Crypto-ransomware, a variant that encrypts victims’ files and demands payment for decryption, accounted for 86 per cent of these attacks. As businesses migrate to cloud environments and adopt bring-your-own-device policies, the attack surface continues to expand.
Shrikant Shitole, managing director for India at Symantec, a cybersecurity firm, spoke with TechObserver.in’s Sanjay Singh about the evolving threat landscape, the sectors most at risk and why security has moved from an IT concern to a boardroom priority.
“The proliferation of cloud, mobility and Internet of Things-enabled devices makes information security a prerequisite for businesses, creating urgent need for comprehensive threat response plans,” says Shitole.
Edited excerpts:
What trends are you witnessing in enterprise security?
Symantec’s Internet Security Threat Report Volume 20 revealed that cyber attackers are adopting new tactics by infiltrating networks and evading detection through hijacking corporate infrastructure. Attackers continue exploiting zero-day vulnerabilities, meaning security flaws unknown to the software maker at the time of attack and without existing fixes. The year 2014 saw an all-time high of 24 discovered zero-day vulnerabilities.
The year also saw 317 million new malware variants created, nearly one million unique malware samples daily. Globally, five out of six large companies were targeted in 2014, representing a 40 per cent increase year-over-year.
India’s landscape mirrors these trends. Sixty per cent of targeted attacks focused on large enterprises, while 34 per cent targeted small businesses. Email remains a primary attack vector, though criminals are increasingly experimenting with mobile and social network attacks. Ransomware attacks grew 113 per cent globally according to the report, with India reporting Asia’s third-highest ransomware incidence at over seven attacks hourly.
Particularly concerning is the rise of crypto-ransomware, which overtly holds victims’ files hostage. This variant accounted for 86 per cent of India’s ransomware attacks.
What is your outlook for enterprise security?
The threat landscape continues evolving rapidly. Emerging technologies will create new attack surfaces affecting consumers, businesses and governments. Cloud, mobility and IoT adoption will make robust security frameworks essential for all organisations.
As businesses migrate data to cloud environments, demand grows for security solutions that protect information regardless of location. Data Loss Prevention technology, which monitors and controls data transfer to prevent unauthorised access, will become foundational for enabling secure, device-agnostic data access.
Comprehensive incident response capabilities will prove critical for identifying, prioritising and neutralising advanced threats in increasingly complex environments. IoT adoption in smart cities, homes and enterprises will necessitate security frameworks as the market remains fragmented and vulnerable.
India’s smartphone user base presents attractive targets for attackers seeking personal and corporate data. BYOD adoption will make mobile device management solutions essential. Mass device adoption and insecure networks will drive demand for comprehensive encryption solutions across all platforms and communication channels.
Building cybersecurity skills through upskilling programmes and methods like security gamification, which trains users through game mechanics, will become imperative for creating human firewalls against social engineering attacks.
Which sectors are driving enterprise security demand?
While all sectors show increased security investment, critical infrastructure remains a prime target. Symantec’s report shows significant attack increases against financial services, which accounted for 17.1 per cent of attacks in 2014 versus 11.1 per cent in 2013. Transportation and communications rose to 4.4 per cent versus 0.8 per cent in the same period.
The transportation, communications and utilities sector saw fivefold growth in targeted attacks. Mining, oil and gas sectors experienced the highest phishing email volumes and second-highest malware-bearing emails in 2014.
While Symantec traditionally serves BFSI, telecom, government and IT/ITeS sectors, we now see manufacturing and pharmaceuticals increasing security investments due to their valuable data assets and endpoint vulnerabilities.
How have cloud, mobility, virtualisation and BYOD impacted enterprise security?
Today’s threat landscape features increasingly sophisticated attacks. Security has transitioned from an IT concern to boardroom priority as data disperses across physical, virtual and cloud environments.
Modern infrastructure complexity creates multiple attack surfaces, from gateways to endpoints. Organisations must shift from prevention-only strategies to rapid threat detection and response. Advanced threats like ransomware, APTs and zero-day attacks render traditional point solutions inadequate. APTs, or advanced persistent threats, are prolonged targeted attacks where intruders establish a long-term presence to steal data.
BYOD adoption, while beneficial for productivity, introduces personal security risks into corporate environments. Manual threat detection processes across endpoints, networks and email gateways remain time-consuming, giving attackers significant advantages.
What are the major enterprise security challenges today?
Contemporary attackers demonstrate exceptional persistence, often conducting espionage campaigns spanning months or years. Symantec observes advanced attackers using compromised corporate accounts to spear-phish new targets. Spear-phishing involves sending targeted emails that appear to come from trusted sources to trick specific individuals into revealing sensitive information.
By the numbers
- 86%
- Share of crypto-ransomware in India's ransomware attacks
- 317 million
- New malware variants created globally in 2014
- 40%
- Year-over-year increase in large companies targeted
Most organisations lack comprehensive security practices to address modern threats. Human factors remain critical. Accidental data exposure and device loss still cause most security breaches. Many leadership teams still lack complete understanding of security integration best practices.
Security teams face overwhelming workloads while managing disparate point solutions never designed for integration. These fragmented approaches increase both vulnerability and operational complexity, creating urgent need for unified security platforms.
Your Questions, Answered
How severe is the ransomware threat in India?
According to Symantec's Internet Security Threat Report, India reported Asia's third-highest ransomware incidence, with over seven attacks recorded every hour. Crypto-ransomware, which encrypts files and demands payment, accounted for 86 per cent of these attacks.
Which sectors face the highest cybersecurity threats?
Critical infrastructure remains a prime target. Financial services accounted for 17.1 per cent of attacks, up from 11.1 per cent. The transportation, communications and utilities sector saw fivefold growth in targeted attacks.
How has cloud adoption affected enterprise security?
As businesses migrate data to cloud environments, security has moved from an IT concern to a boardroom priority. Modern infrastructure complexity creates multiple attack surfaces from gateways to endpoints, requiring a shift from prevention-only strategies to rapid threat detection.
What human factors contribute to security breaches?
According to Symantec, accidental data exposure and device loss still cause most security breaches. Many leadership teams lack complete understanding of security integration best practices, while security teams face overwhelming workloads managing fragmented solutions.

