- within Technology topic(s)
- in United States
- with readers working within the Business & Consumer Services industries
- within Technology, Insurance and Family and Matrimonial topic(s)
I. INTRODUCTION
As the curtain falls on 2025, the corporate world is fastened in an unrelenting race to weave Artificial Intelligence (AI) into every layer of commerce. Yet, much like the tale of Icarus, the pursuit of innovation raises a pressing question: has the thirst for technological ascendancy led companies to soar too close to the sun, neglecting the shield of cyber resilience? The consequences are clear: global cyberattacks are escalating at an unprecedented pace, with India witnessing a particularly sharp surge in targeted breaches, phishing scams, and ransomware incidents.
Today, the corporate challenge is no longer to find the most efficient AI tool, but to ensure that these systems are safe, robust, and ethically deployed. Acknowledging the adage, “with great power comes great responsibility”, in the age of AI, that responsibility extends to fortifying digital frontiers against sophisticated, AI-enabled threats to not just be reactive, but also pre-emptive. This evolving reality demands that boards recalibrate corporate governance frameworks, embedding cybersecurity not as an afterthought, but as a cornerstone of transparency, accountability, and sustainable innovation.
II. WHAT IS ‘CYBERCRIME’?
Cybercrime can be broadly understood as the umbrella term for a wide spectrum of unlawful activities conducted through computers, networks, or other digital technologies. It encompasses a range of offences, including hacking and phishing, identity theft, ransomware, and malware intrusions, each exploiting the digital environment to commit fraud, disrupt systems, or steal sensitive information.1
Globally, the financial damage from cybercrime is staggering. According to Cybersecurity Ventures, worldwide cybercrime costs are expected to rise by about 15% each year, reaching nearly USD 9.5 trillion in 2024 and climbing to USD 10.5 trillion annually by the end of 2025. This represents a significant increase from just USD 3 trillion in 2015. 2
To put that into perspective, if cybercrime were treated as a nation, it would rank as the world’s third-largest economy, trailing only behind the United States and China. These figures underscore how cybercrime has evolved from a niche technology issue to one of the defining global economic challenges of our time. According to the World Economic Forum’s Global Risks Report 2024, nearly half of all organisations, around 47%, now view adversarial generative AI as their single biggest concern, recognising its ability to enable more sophisticated and far-reaching cyberattacks.3
This anxiety is reinforced by the findings of the Global Cybersecurity Outlook survey, which found that 72% of respondents reported a noticeable increase in cyber risks, particularly in areas such as social engineering and ransomware. The report highlights how the growing sophistication of generative AI is not only accelerating the pace of attacks but also equipping cybercriminals with tools to make their strategies more deceptive, adaptive, and difficult to defend against.4
Shifting focus to India, the scale of cybercrime is nothing short of alarming. In the last year alone, 3.6 million cyber fraud cases were reported via national reporting systems, resulting in an estimated loss of ₹22,845 crore, a staggering 206% increase from ₹7,465 crore in 2023. Authorities arrested over 10,000 individuals in connection with these frauds, reflecting both a harsh crackdown and the sheer volume of criminal activity.5
India’s rapid digital adoption has drastically expanded the attack surface. With the country hosting the second-largest population of internet users, low digital literacy compounds vulnerabilities. Only a third of youth (15–29) can confidently conduct online transactions or send emails securely. Between 2014 and 2024, cybercrime cases increased from 9,622 to over 77,000 (as of August), reflecting a growing digital presence across banking, healthcare, e-commerce, and government platforms.6
III. WHO IS AFFECTED BY CYBERCRIME?
- Individuals
Individuals often bear the brunt of cybercriminal activity. In Pune alone, between January and May 2025, digital arrest scams caused losses of ₹9.21 crore, with one Mumbai software executive defrauded of a staggering ₹6.3 crore in a single incident. Although reported cases have declined compared to 2024, the strategy continues to exploit fear and low digital literacy, particularly among the elderly.7 Across a broader urban landscape, Mumbai’s dedicated cybercrime helpline, ‘1930’, has recovered more than ₹300 crore over three years, demonstrating both the scale of criminal activity and the effectiveness of proactive response channels.8
For individuals, the danger of cyber fraud lies in its invisibility and insidious nature. The growth of scams like “digital arrests” or AI-driven impersonation attacks shows that fraudsters no longer need to rely on brute force; rather, they weaponise psychology, digital illiteracy, fear, and trust. A single misplaced click can empty bank accounts or expose sensitive data. What is most concerning is how quickly these tactics evolve, making digital literacy not only desirable but also essential for personal safety in the 21st century.
- Corporations
Businesses and Corporations face a dual threat, not just financial loss, but operational disruption and reputational damage. While global data breach costs have declined slightly, the average cost now stands at USD 4.44 million globally, thanks largely to AI-powered defence improvements. Yet, breaches remain costly and complex, with 30% of breaches involving data spread across multiple environments, which carried a higher average cost of USD 5.05 million and a longer lifecycle.9
For corporations, cyberfraud is less a discrete incident and more a persistent, systemic risk. Breaches that spread across multiple platforms or cloud environments underscore the interconnected fragility of modern business operations. The financial losses are damaging, but the true peril is reputational collapse: one high-profile breach can erode years of carefully built consumer trust. In this context, cybercrime operates like a shadow economy, exploiting corporate ambition and complexity, forcing boards to accept that cyber resilience is inseparable from strategic corporate governance.
- Governments
As governments pursue hyper-digitalisation, they have inadvertently positioned themselves among the most attractive targets for cyberfraud, largely because of the vast volumes of sensitive data they hold. The recent ransomware attack on St. Paul in the U.S., which forced the city to declare a state of emergency after critical systems went offline and confidential records were leaked, illustrates how paralysing a single breach can be.10
Globally, the threat has grown more sophisticated: the Microsoft SharePoint “ToolShell” exploit compromised nearly 100 organisations, including federal agencies, through Chinese state-linked actors, while Canada’s House of Commons suffered a SharePoint zero-day breach that exposed internal parliamentary records, underscoring how even legislative bodies are not immune.11
The situation is equally pressing in India, where CERT-In reported a surge in government-related cyber incidents, from 1.39 million in 2022 to 2.04 million in 2024, highlighting the rapid expansion of the domestic threat landscape.12 Furthermore, the attack on Morocco’s National Social Security Fund by Algeria-linked hackers, which compromised the data of nearly two million individuals and half a million companies, serves as a vivid reminder that state-level cyberattacks not only destabilise governments but also directly jeopardise public infrastructure and citizen privacy.13
As nations accelerate their digital transformation, governments have become some of the most attractive and vulnerable targets for cybercriminals. From ransomware shutting down city administrations in the U.S. to breaches of parliaments and social security databases across Europe, North America, and Africa, the risks reveal just how vulnerable national infrastructure has become. For a country like India, where state services and citizen records are rapidly being digitised, the danger is that a single breach could compromise millions of lives in one sweep. In a hyper-connected world, governments are no longer just administrators of data; they are guardians of national identity and public trust, making cyber resilience a matter of state survival.
IV. CYBERSECURITY: A BOARDROOM IMPERATIVE
This article has explored the scale and nature of cyberfraud, but the pressing question remains: how have these crimes reshaped, and will continue to shape, the way corporations govern themselves? Boards don’t just inherit cyber risk; they inadvertently manufacture it with every digital bet they approve. If a single breach can vaporise market value and erode stakeholder trust, why isn’t cyber resilience reviewed with the same cadence as capital allocation and audit?
Treat security not as insurance but as a strategy: set risk appetite, fund detection and response like core ops, stress-test AI systems, and make incident readiness a board-owned KPI. The sections that follow examine recent corporate frauds and breaches, and what they reveal about a simple governance test: are we building systems robust enough to survive their first contact with a real threat?
A Case Study of Cybercrime in Indian Corporations
- Ticketmaster
In mid-2024, the ‘ShinyHunters’ hacker group claimed responsibility for one of the largest data breaches in modern history, targeting Ticketmaster via Snowflake, its cloud data repository. As much as 1.3 terabytes of user information was exfiltrated, affecting up to 560 million individuals, including names, emails, encrypted payment data, and order histories.14
The breach originated from unauthorised access to a third-party cloud database. Investigations revealed that hackers exploited stolen credentials, enabling lateral movement across Ticketmaster’s data environment. Notably, the company’s detection of the breach was significantly delayed as it allegedly took approximately 51 days before action was taken, after the hacker group publicised their claim.15
- Nippon Life India Asset Management
On April 9, 2025, Nippon Life India Asset Management (NAM India), India’s fourth-largest AMC with over ₹5.5 lakh crore AUM and more than 20 million unique investors, suffered a cyberattack that brought its online operations, including website and mobile portal, to a halt.16
The company rapidly isolated affected systems and engaged cybersecurity experts. Core fund management operations remained unaffected, and investment activities continued seamlessly. Within days, alternate distribution channels and third-party platforms enabled investor access. Remarkably, despite the outage, Nippon’s stock rose 6%, likely reflecting investor confidence in its swift response.17
Key Takeaway
The lessons from Ticketmaster and Nippon Life make one truth abundantly clear: cyber resilience must sit at the very core of corporate governance. Third-party risk is a boardroom risk. It is no longer sufficient to secure internal systems if weak links in contractors, cloud vendors, or supply chains can provide the opening for catastrophic breaches. Equally, the speed of detection is critical, as every day a breach goes unnoticed is a day of vulnerability to potential damages, underscoring the need for boards to mandate continuous monitoring and AI-driven anomaly detection.
Perhaps most importantly, resilience is defined not only by prevention alone, but also by instantaneous response. Nippon’s swift isolation of systems, transparent communication, and the creation of backup transaction channels demonstrate that recovery can sustain market confidence even in the face of disruption. These cases underscore that cybersecurity is not merely insurance against unlikely events, but a strategy in itself: governance frameworks and capital allocation must embed it as a fundamental pillar of market trust and long-term growth.
V. BUILDING CYBER-RESILIENCE: AN ACTIONABLE BOARDROOM STRATEGY
To move beyond mere awareness and into meaningful defence, corporate boards must treat cyber-resilience as a strategic investment, not an IT add-on. First, identity protection demands immediate attention: multi-factor authentication, phishing-resistant protocols (like FIDO2), and least-privilege access management must become standard. Simultaneously, companies must adopt Continuous Exposure Management (CEM) to maintain visibility of their potential attack surface across on-premises, cloud, and hybrid systems. Organisations deploying CEM are three times less likely to suffer breaches by 2026.18
Moreover, vulnerability management should prioritise rapid detection and patching, particularly for edge, VPN, and internet-exposed systems, as these vectors now account for 20% of breaches.19 AI and automation aren't optional, and organisations that utilise AI extensively in security operations save approximately USD 1.9–2.2 million per incident and lower breach costs by accelerating detection and containment, contributing to a 9% global decline in breach costs to USD 4.44 million in 2025.20
Data strategy must also evolve. Hybrid cloud architectures, featuring immutable backups, real-time data replication, and failover mechanisms, can minimise ransomware disruption and reduce recovery times.21 Finally, cyber governance requires mature incident preparedness: tabletop simulations, law enforcement partnerships, clear crisis communications, and regulatory-ready disclosure processes are now referenced in best-practice playbooks. The industry consensus is growing as 84% of executives and investors now see cyber-resilience as a core indicator of board stewardship.22
VI. CYBERSECURITY AS THE PILLAR OF CORPORATE GOVERNANCE
Cyber threats are no longer remote IT problems; instead, they are central challenges to corporate stability, ranging from sophisticated impersonation scams to disruptive service attacks and data breaches. The cases of Ticketmaster and Nippon Life reinforce that cyber risk is board-level risk woven into every governance decision around third parties, digital transformation, and stakeholder trust. The data tells a consistent story: prevention matters, but response defines resilience, not just in financial terms, but also in terms of sustained credibility, trust, and shareholder value.
Boards must act with urgency, but also with clarity of purpose. Embedding identity controls, AI-enhanced detection, continuous exposure management, immutable recovery systems, and rigorously tested incident-response plans into governance structures is no longer prudent; it is indispensable. Regulators are already moving in this direction: the RBI in India and the EU’s NIS2 and DORA frameworks are explicitly tying cyber-resilience to executive accountability. The companies that anticipate this shift and build resilience into their core strategy will not only reduce liability but also convert security into a competitive advantage.
In an era defined by artificial intelligence and escalating fraud, cyber-resilience is no longer a protective measure at the margins—it has become the very currency of trust on which sustainable growth and corporate legitimacy depend.
Footnotes
1 Proofpoint, 'What Is Cyber Crime? Definition & Examples | Proofpoint AU'
2 Cybersecurity Ventures, 2024 Cybersecurity Almanac: 100 Facts, Figures, Predictions and Statistics (EIN Presswire, 28 June 2024)
3 Fortinet, ‘Top Cybersecurity Statistics: Facts, Stats and Breaches for 2025’
4 Ibid
5 Bharti Jain, ‘India’s Cybercrime Reporting Systems Logged 36 Lakh Fraud Cases in 2024; ₹22,845 Crore Lost, Over 10,000 Arrested’ Times of India (New Delhi, 22 July 2025)
6 Tripathy, Sudhanshu. (2024). A comprehensive survey of cybercrimes in India over the last decade. International Journal of Science and Research Archive
7 TNN, ‘Rs 9 Crore Lost to 21 Digital Arrest Scams in Jan-May This Year’ Times of India (Pune, 8 June 2025
8 TNN, ‘Cybercrime Helpline in Mumbai Helps Recover ₹300 Crore Over 3 Yrs From Frauds’ Times of India (Mumbai, 23 August 2025)
9 Limor Kessem, ‘2025 Cost of a Data Breach Report: Navigating the AI Rush Without Sidelining Security’ IBM Think (30 July 2025)
10 Times of India World Desk, ‘Nevada Hit by Cyberattack: State Offices Shut for Two Days — Websites, Phone Lines Go Offline’ Times of India (Times World Desk, 27 August 2025)
11 Emma Woollacott, ‘Everything We Know So Far About the Canadian House of Commons Data Breach’ IT Pro (15 August 2025)
12 Manisha Singh and Srinjoy Banerjee, Cybersecurity Laws and Regulations: India Chapter (ICLG - International Comparative Legal Guides, 06 November 2024
13 Center for Strategic and International Studies, Significant Cyber Incidents – Strategic Technologies Program (CSIS, no date)
14 StrongDM, ‘Ticketmaster Data Breach: What Happened and How to Prevent It’ (StrongDM, 28 February 2025)
15 ibid
16 ET Bureau, ‘Nippon MF Portal Yet to Be Restored After Cyber Attack’ The Economic Times (Mumbai, 19 April 2025)
17 Prajwal Jayaraj, ‘Nippon Life Fully Restores Website and Mobile App After April 9 Cyberattack’ NDTV Profit (21 April 2025
18 TechRadar, ‘Organizational Resilience: We Need to Think Beyond Cyber Attacks’ TechRadar Pro (21 August 2025)
19 ibid
20 IBM, Cost of a Data Breach Report 2025: The AI Oversight Gap (IBM Think, co-authored with Ponemon Institute, 2025)
21 Joe Baguley, ‘Organizational Resilience: We Need to Think Beyond Cyber Attacks’ TechRadar Pro (21 August 2025)
22 Mike Scott, ‘ESG Watch: Companies ‘Complacent About Cybercrime’, Despite Rise in Risk from AI’ Reuters (3 February 2025)
The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.