A DPDPA-ready Mumbai SME needs five things in place: data mapping, consent management, breach-notification capability, endpoint detection (EDR), and immutable backups. Most businesses have one or two of these; almost none have all five without dedicated help. This checklist covers what a genuine compliance posture looks like, not just what a policy document claims.
Key facts
- DPDPA 2023 penalties for breach-notification failure can reach ₹250 crore for the most serious violations
- MDR (Managed Detection and Response) services in Mumbai typically run ₹15,000–₹60,000/month depending on endpoint count
- Over 80% of ransomware in India still enters via phishing email, email security is a foundational, not optional, control
- ITSolvez has contained a live ransomware incident for a healthcare MDR client in under 9 minutes from detection to isolation
The DPDPA-ready checklist
1. Data mapping
You cannot protect what you haven't located. Map every system that touches personal data, CRM, HRMS, email, support tickets, backups, even shared spreadsheets. Most Mumbai SMEs discover personal data living in places nobody officially tracks, like an old Excel export sitting on a shared drive.
2. Consent and purpose limitation
Every form, signup flow and data-collection point needs a documented, specific purpose, and data collected for one purpose (say, support tickets) can't quietly get reused for marketing without fresh consent.
3. Breach notification readiness
DPDPA requires notifying the Data Protection Board and affected individuals "in the prescribed manner" following a breach. That means having an actual incident-response runbook today, not drafting one after an incident happens.
4. Endpoint Detection and Response (EDR)
Traditional antivirus catches known malware signatures; EDR watches behaviour in real time and can stop ransomware mid-encryption. For any Mumbai business above roughly 10 employees, this is now table-stakes, not a premium add-on.
5. Immutable, tested backups
Backups that an attacker can delete or encrypt are not protection. Object-locked or air-gapped backups, tested via an actual restore at least annually, are what separates "we have backups" from "we can actually recover."
MDR services in Mumbai: what's a fair price?
| Business size | Typical MDR cost/month | Coverage |
|---|---|---|
| Up to 25 endpoints | ₹15,000–₹25,000 | 24/7 monitoring, EDR, monthly reporting |
| 25–75 endpoints | ₹25,000–₹45,000 | Above + quarterly incident-response drills |
| 75+ endpoints / regulated sector | ₹45,000–₹60,000+ | Dedicated SOC analyst time, compliance reporting |
Local context: BFSI and financial-sector Mumbai businesses
Mumbai's density of banking, NBFC and capital-markets firms means a large share of the city's SMEs are either directly regulated or serve regulated clients as vendors, which pulls DPDPA obligations into sharper focus, since a breach affecting a bank's vendor ecosystem draws board-level scrutiny fast. If your business serves BFSI clients, your own security posture is increasingly part of their vendor risk assessment, not just your own compliance concern.
Building the case internally: how to justify the spend
Security spend is often the easiest budget line to defer, nothing visibly breaks until it does. The strongest internal case ties cost directly to two numbers: the average cost of a data breach for a business your size (typically running into tens of lakhs once you count downtime, remediation, legal exposure and reputational damage), and the DPDPA penalty exposure for a notification failure specifically, which can reach ₹250 crore for the most serious violations. Framing MDR and EDR spend as insurance against a quantifiable, realistic downside, rather than an abstract "best practice" cost, tends to land better with finance stakeholders than generic risk language.
It also helps to separate "must-have now" from "roadmap" items when presenting to leadership. EDR and immutable backups are foundational and should be treated as non-negotiable regardless of budget cycle; a full SOC-as-a-service engagement or advanced threat-hunting capability can reasonably be phased in over two or three budget cycles as the business scales, without leaving the foundational gaps that actually cause most incidents.
Why ITSolvez
ITSolvez's MDR service is delivered under ISO 27001:2022-certified process, and in one healthcare-sector engagement contained an active ransomware incident within 9 minutes of detection, the difference between a contained incident and a multi-day outage with breach-notification obligations attached.
Frequently Asked Questions
Is DPDPA 2023 actually being enforced yet?
Yes, DPDPA became law in August 2023 and applies to current data processing activity now; this is not a future requirement to plan around later.
What's the difference between antivirus and EDR?
Antivirus matches known malware signatures; EDR monitors real-time process behaviour and can halt an attack (like ransomware encryption) as it happens, even from previously unseen malware.
How often should we test our backup restore process?
At minimum annually, a backup that has never been test-restored is an assumption, not a verified recovery capability.
Do small Mumbai businesses really need MDR, or is that overkill?
Any business above roughly 10 employees handling customer or financial data is a realistic ransomware target today, initial access to Indian networks sells on dark-web forums for as little as $500, meaning size alone doesn't provide protection.
Download our full DPDPA technical-controls checklist, or book a free security assessment as part of our cybersecurity services to see exactly where your current setup stands.