ESET cybersecurity report exposes Indian enterprise's AI risk gap

AI is spreading across Indian enterprises, but security visibility is not keeping pace. ESET’s latest findings reveal how phishing, data leakage, deepfakes and human behaviour are reshaping the enterprise risk picture.

author-image
DQChannels Bureau
New Update
ESET cybersecurity report exposes Indian enterprise's AI risk gap

AI is quickly becoming part of everyday enterprise operations, but security controls are not always keeping pace. The ESET cybersecurity report finds that 85% of organisations in India faced at least one AI-related cyber threat in the past 12 months, even as 99% are already using or piloting AI.

Advertisment

The findings come from a study of 400 cybersecurity decision-makers across Indian enterprises, including large organisations and SMBs. AI is being used across customer service, analytics, software development, risk management, document processing and threat detection.

AI adoption is moving faster than oversight

The gap becomes clearer when organisations look at how AI is being managed. Only 56% have measures in place to monitor AI tool access and outputs.

At the same time, internal and external risks are growing. Forty percent of organisations reported employee misuse of generative AI, while 48% experienced data leakage through AI platforms. AI-generated phishing and impersonation attacks were reported by 48%, followed closely by deepfake or voice-cloning attacks at 47%.

Advertisment

For Indian enterprise cybersecurity, the issue is therefore no longer simply whether businesses should adopt AI. It is how they can maintain visibility as AI becomes part of more workflows and decisions.

Enterprise AI risks extend beyond AI tools

The broader threat picture adds another layer. Eight in ten organisations experienced at least one major cybersecurity incident in the past year, while 44% faced three or more. Data exfiltration, cloud breaches and business email compromise were among the most common incidents.

Although 95% of respondents expressed confidence in their ability to withstand and recover from an attack, delayed detection, limited resources and poor visibility remained major challenges.

Advertisment

The report also points to weaknesses across the wider technology environment. Lack of visibility was cited by 42% as a leading cause of incidents, followed by third-party or supply chain compromise at 40%.

Human risk remains part of the security equation

Cybersecurity training is widespread, but 45% still identified employee awareness and training as a major challenge. Lack of engagement and unengaging training materials were also common barriers.

As AI makes phishing and impersonation more convincing, the human layer becomes harder to ignore.

Advertisment

Security priorities are shifting

The report shows organisations moving towards capabilities designed for faster detection and response. MDR was the most widely planned capability over the next 12 months, with 84% using or planning to adopt it.

The broader message is that AI adoption is creating a wider security task. Enterprise AI risks now sit alongside cloud, third-party, identity and human risks. For enterprises, the challenge is turning confidence in cyber resilience into measurable visibility, response speed and stronger oversight.

Read More: 

Tier 2 and Tier 3 Markets: What UBON sees in India's next growth phase

RiskProfiler MCP Connector launch changes how analysts explore risk

Nagarro Agentic Salesforce Solutions take shape at Dreamforce 2026

Virtusa New Chairman Srinivas BG takes the board