Tuesday, September 22, 2026
AboutContact
HomeBlogTechnologyCERT-In Cybersecurity Controls For Indian MSMEs: A 30-60-90 Day Plan
Technology
5 min read

CERT-In Cybersecurity Controls For Indian MSMEs: A 30-60-90 Day Plan

A practical 30-60-90 day implementation plan that turns CERT-In cybersecurity controls for MSMEs into clear actions for Indian small businesses.

B

Bhojraj Pilaniya

September 22, 2026 · 923 words

CERT-In Cybersecurity Controls For Indian MSMEs: A 30-60-90 Day Plan

CERT-In’s elemental cyber defence controls give Indian MSMEs a useful starting point, but founders still need a practical sequence for what to do first.

The simple answer is to assign ownership, enable MFA, document assets, test backups, review payment-change workflows and then build monthly evidence that the controls actually work.

Why this matters now

Many small businesses have a website, email, WhatsApp Business, accounting software, cloud storage and payment collection tools, but no single person owns the security checklist.

A phased plan matters because buying tools before fixing account ownership, backups and access removal creates expense without resilience.

Indian teams also need to consider how quickly operational details change. Staff roles, vendors, bank accounts, devices, apps, branch locations and customer channels can change faster than the website or policy document. A checklist that is not reviewed becomes stale, so every recommendation below includes an owner and evidence item.

Action checklist

  • Owner: Name one security owner and one backup owner.
  • MFA: Turn on multi-factor authentication for email, domain, hosting and payment tools.
  • Assets: List admin accounts, devices, software and vendors.
  • Backups: Restore one sample file or database, not just confirm that backups exist.
  • Payments: Verify bank-account changes through a second channel.

Implementation plan

First week

In the first week, do not try to solve every control. Protect email, domain, hosting, payment and cloud-storage accounts first, because compromise of these systems can disrupt the whole business.

During the first week, keep the scope narrow and visible. A founder or manager should be able to open one document and see the status of every important item. If the team cannot explain who owns the task, the task is not ready for automation.

First month

Within a month, create a monthly review calendar covering patches, inactive users, backup restore tests, vendor access and payment-verification exceptions.

The first month should convert one-time cleanup into a repeatable habit. Create a calendar reminder, define the evidence to be saved and agree who signs off. This prevents the checklist from becoming a document that was created once and forgotten.

Quarterly review

Every quarter, run one tabletop exercise: a hacked mailbox, a ransomware note, a lost laptop or an unauthorised website admin login.

A quarterly review should not only mark items as complete. It should ask whether the business model changed, whether a new vendor was added, whether a branch or remote team changed the process, and whether any customer complaint exposed a weak point.

Decision table

AreaWhat to checkOwnerEvidence
EmailMFA, forwarding rules and recovery emailFounder or IT partnerSettings screenshots
BackupsRestore test and retentionOperationsRestore notes
PaymentsVendor bank-change approvalFinanceApproval log
WebsiteCMS, plugin and hosting updatesDeveloperUpdate log

Practical worksheet

Create a working sheet with five columns: owner, current status, evidence link, next action and review date. This makes the article usable by a founder, agency manager, finance lead or IT partner instead of leaving it as a reading exercise.

The worksheet should include only actions the team can prove. If an item is not complete, mark it as pending and add a date. A visible pending item is better than a control that everyone assumes exists but nobody can demonstrate.

For multi-location businesses, add one more column for branch or channel. A website form, a WhatsApp sales number, a marketplace listing and a physical counter can all need different handling even when the headline policy is the same.

What to measure

Track a small number of signals after the change. Useful signals include open exceptions, old accounts removed, evidence collected, failed checks, staff questions and customer complaints. Measurement should help the team improve the process, not create paperwork for its own sake.

For a young business, the most important metric is consistency. A weekly or monthly review that actually happens is more valuable than a complex dashboard that nobody opens.

Common mistakes

The most common mistake is treating cybersecurity as a one-time purchase. MSMEs often subscribe to a tool but continue using shared passwords and unmanaged freelancer access.

Another mistake is keeping no evidence. During an incident, screenshots, logs, invoices, admin lists and timeline notes are more useful than memory.

A third mistake is outsourcing responsibility without requiring evidence. Agencies, freelancers, payment partners and IT vendors may perform important work, but the business still needs a record of what was configured and when it was last checked.

How IndiaPress readers can use this

Use this plan as a working checklist in a spreadsheet. Add a due date, owner and proof link for every line item.

If you outsource IT, make the vendor share monthly evidence rather than only saying that updates were completed.

Teams can turn this article into a one-page internal SOP. Copy the checklist, remove anything irrelevant, add owner names and review it in the next weekly meeting. The goal is not perfection on day one; the goal is visible progress and fewer unknowns.

Practical note for Indian teams

For small teams, the best control is the one that someone can repeat. Keep the first version simple, then improve it with every monthly review.

Keep the first version simple enough for the smallest branch, store, agency desk or founder-led team to follow. Once the process works, add automation, dashboards and deeper controls. If the process fails on a busy day, simplify it before adding more software.

Teams should also keep ownership visible. A checklist without a named owner usually becomes a forgotten document. Add the owner’s role, backup owner and the date when the item was last reviewed.

Finally, keep customer communication plain. If a change affects payments, support, privacy, security or service availability, staff should know how to explain it without jargon. Clear explanations reduce disputes and make the business look more reliable.

Related IndiaPress reading

Sources

B

Bhojraj Pilaniya

AI Automation developer and Content Writter