VOIWORLD
As artificial intelligence (AI) adoption accelerates across industries, Indian companies are facing growing threats from within their own walls. A new study by consulting firm Protiviti and Microsoft warns that insider-related data breaches are becoming one of the biggest security challenges for organisations navigating India’s new data protection regime.
The whitepaper, titled “Safeguarding From Within: Insider Risk Management in India,” released on October 15, 2025, reveals that 63% of all data breaches involve insiders in some form, according to Microsoft’s security data. The report highlights particular vulnerability in the banking, financial services and insurance (BFSI) and information technology (IT) sectors, both of which handle vast amounts of sensitive customer information and intellectual property.
The findings come at a crucial moment, as companies work to comply with the Digital Personal Data Protection Act, 2023 (DPDPA) while integrating AI and generative AI technologies into their operations. Regulators such as the Reserve Bank of India (RBI) are also tightening oversight of how organisations protect personal and financial data.
“Insider risk management is no longer optional—it’s a regulatory necessity,” said Sandeep Gupta, Managing Director, Protiviti Member Firm for India. “Frameworks such as the DPDPA, SEBI, RBI, IRDAI, and the Telecommunication Act make it imperative for Indian enterprises to proactively safeguard data.”
The study found significant preparedness gaps across Indian organisations. 84% of respondents said they need stronger measures to prevent risky or unmonitored employee use of AI tools.
Based on interviews with senior executives from sectors like banking, healthcare, pharmaceuticals, and technology, the report notes that insider risk management has evolved into a board-level concern.
“Proactive Insider Risk Management (IRM) provides a structured way to protect sensitive information, ensure compliance, and build stakeholder trust,” said Anand Jethalia, Country Head for Cybersecurity at Microsoft India. “Following the strategies in this whitepaper will help organisations innovate safely in an AI-driven world.”
Among its key recommendations, the whitepaper urges companies to:
Form cross-functional committees to define accountability for insider risk management.
Strengthen protection of high-value data assets such as intellectual property, unpublished financial data, and patient records.
Deploy enhanced monitoring systems for sensitive or regulated information.
With insider incidents now responsible for the majority of data breaches—and AI introducing new dimensions of risk—the report calls for insider risk management to become a strategic priority. It concludes that the future of AI-led innovation in India depends on how effectively companies balance technological progress with robust security and regulatory compliance.
