HomeLatest NewsInterviewsCloud, IoT and mobility are creating new attack surfaces for cybercriminals, says Symantec India MD Shrikant Shitole

Cloud, IoT and mobility are creating new attack surfaces for cybercriminals, says Symantec India MD Shrikant Shitole

Symantec warns India's critical infrastructure faces growing threats from ransomware and advanced persistent attacks.

Preferred Source of Google

Key Points

  • India reported Asia's third-highest ransomware incidence at over seven attacks hourly
  • Crypto-ransomware accounted for 86 per cent of India's ransomware attacks
  • Transportation and utilities sector saw fivefold growth in targeted attacks

India reported Asia’s third-highest ransomware incidence in 2014, with over seven attacks recorded every hour. Crypto-ransomware, a variant that encrypts victims’ files and demands payment for decryption, accounted for 86 per cent of these attacks. As businesses migrate to cloud environments and adopt bring-your-own-device policies, the attack surface continues to expand.

Shrikant Shitole, managing director for India at Symantec, a firm, spoke with TechObserver.in’s Sanjay Singh about the evolving threat landscape, the sectors most at risk and why security has moved from an IT concern to a boardroom priority.

Advertisement
Infosec Reimagined
Infosec Reimagined
Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.
Register Now →
Digital Senate
Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.
Register Now →
CIO Prism
CIO Prism
CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.
Register Now →
National DefTech Summit
National DefTech Summit
Featuring keynotes, expert panels, live tech demos and strategic networking, the summit will drive actionable insights for defence sector.
Register Now →
Future-Ready Defence
Future-Ready Defence
A Leadership Dialogue on sovereign, trusted data infrastructure, AI readiness and mission resilience for Defence Forces.
Register Now →

“The proliferation of cloud, mobility and Internet of Things-enabled devices makes information security a prerequisite for businesses, creating urgent need for comprehensive threat response plans,” says Shitole.

Edited excerpts:

What trends are you witnessing in ?

Advertisement

Symantec’s Internet Security Threat Report Volume 20 revealed that cyber attackers are adopting new tactics by infiltrating networks and evading detection through hijacking infrastructure. Attackers continue exploiting zero-day vulnerabilities, meaning security flaws unknown to the software maker at the time of attack and without existing fixes. The year 2014 saw an all-time high of 24 discovered zero-day vulnerabilities.

The year also saw 317 million new malware variants created, nearly one million unique malware samples daily. Globally, five out of six large companies were targeted in 2014, representing a 40 per cent increase year-over-year.

India’s landscape mirrors these trends. Sixty per cent of targeted attacks focused on large enterprises, while 34 per cent targeted small businesses. Email remains a primary attack vector, though criminals are increasingly experimenting with mobile and social network attacks. Ransomware attacks grew 113 per cent globally according to the report, with India reporting Asia’s third-highest ransomware incidence at over seven attacks hourly.

Advertisement

Particularly concerning is the rise of crypto-ransomware, which overtly holds victims’ files hostage. This variant accounted for 86 per cent of India’s ransomware attacks.

What is your outlook for enterprise security?

The threat landscape continues evolving rapidly. Emerging technologies will create new attack surfaces affecting consumers, businesses and governments. Cloud, mobility and IoT adoption will make robust security frameworks essential for all organisations.

As businesses migrate data to cloud environments, demand grows for security solutions that protect information regardless of location. Data Loss Prevention technology, which monitors and controls data transfer to prevent unauthorised access, will become foundational for enabling secure, device-agnostic data access.

Comprehensive incident response capabilities will prove critical for identifying, prioritising and neutralising advanced threats in increasingly complex environments. IoT adoption in smart cities, homes and enterprises will necessitate security frameworks as the market remains fragmented and vulnerable.

India’s smartphone user base presents attractive targets for attackers seeking personal and corporate data. BYOD adoption will make mobile device management solutions essential. Mass device adoption and insecure networks will drive demand for comprehensive encryption solutions across all platforms and communication channels.

Building cybersecurity skills through upskilling programmes and methods like security gamification, which trains users through game mechanics, will become imperative for creating human firewalls against social engineering attacks.

Which sectors are driving enterprise security demand?

While all sectors show increased security investment, critical infrastructure remains a prime target. Symantec’s report shows significant attack increases against financial services, which accounted for 17.1 per cent of attacks in 2014 versus 11.1 per cent in 2013. Transportation and communications rose to 4.4 per cent versus 0.8 per cent in the same period.

The transportation, communications and utilities sector saw fivefold growth in targeted attacks. Mining, oil and gas sectors experienced the highest phishing email volumes and second-highest malware-bearing emails in 2014.

While Symantec traditionally serves BFSI, telecom, government and IT/ITeS sectors, we now see manufacturing and pharmaceuticals increasing security due to their valuable data assets and endpoint vulnerabilities.

How have cloud, mobility, virtualisation and BYOD impacted enterprise security?

Today’s threat landscape features increasingly sophisticated attacks. Security has transitioned from an IT concern to boardroom priority as data disperses across physical, virtual and cloud environments.

Modern infrastructure complexity creates multiple attack surfaces, from gateways to endpoints. Organisations must shift from prevention-only strategies to rapid threat detection and response. Advanced threats like ransomware, APTs and zero-day attacks render traditional point solutions inadequate. APTs, or advanced persistent threats, are prolonged targeted attacks where intruders establish a long-term presence to steal data.

BYOD adoption, while beneficial for productivity, introduces personal security risks into corporate environments. Manual threat detection processes across endpoints, networks and email gateways remain time-consuming, giving attackers significant advantages.

What are the major enterprise security challenges today?

Contemporary attackers demonstrate exceptional persistence, often conducting espionage campaigns spanning months or years. Symantec observes advanced attackers using compromised corporate accounts to spear-phish new targets. Spear-phishing involves sending targeted emails that appear to come from trusted sources to trick specific individuals into revealing sensitive information.

By the numbers

86%
Share of crypto-ransomware in India's ransomware attacks
317 million
New malware variants created globally in 2014
40%
Year-over-year increase in large companies targeted

Most organisations lack comprehensive security practices to address modern threats. Human factors remain critical. Accidental data exposure and device loss still cause most security breaches. Many leadership teams still lack complete understanding of security integration best practices.

Security teams face overwhelming workloads while managing disparate point solutions never designed for integration. These fragmented approaches increase both vulnerability and operational complexity, creating urgent need for unified security platforms.

Your Questions, Answered

How severe is the ransomware threat in India?

According to Symantec's Internet Security Threat Report, India reported Asia's third-highest ransomware incidence, with over seven attacks recorded every hour. Crypto-ransomware, which encrypts files and demands payment, accounted for 86 per cent of these attacks.

Which sectors face the highest cybersecurity threats?

Critical infrastructure remains a prime target. Financial services accounted for 17.1 per cent of attacks, up from 11.1 per cent. The transportation, communications and utilities sector saw fivefold growth in targeted attacks.

How has cloud adoption affected enterprise security?

As businesses migrate data to cloud environments, security has moved from an IT concern to a boardroom priority. Modern infrastructure complexity creates multiple attack surfaces from gateways to endpoints, requiring a shift from prevention-only strategies to rapid threat detection.

What human factors contribute to security breaches?

According to Symantec, accidental data exposure and device loss still cause most security breaches. Many leadership teams lack complete understanding of security integration best practices, while security teams face overwhelming workloads managing fragmented solutions.

NEWSLETTERThe Daily BriefingThe day's top enterprise technology stories, curated by our editors. Monday to Friday.

Free. One-click unsubscribe anytime. We never share your email.

Sanjay Singh
Sanjay Singh
Sanjay Singh covers startups, consumer electronics and telecom for TechObserver.in
Advertisement
- Advertisement -
- Advertisement -

From ₹4 lakh crore capex to AI risk models, PSU CFOs redraw the playbook

As state-owned companies fund the energy transition, infrastructure and digitisation, senior executives say the PSU CFO's calculus is widening beyond conventional project returns to capital structure, technology risk, commodity exposure and climate resilience.

RELATED ARTICLES