Skip to main content

Cybersecurity for women-owned MSMEs in India

Protect business email, payments, customer data and devices. This MSME cyber-safety guide covers UPI QR scams, backups, access and incident response in India.

In this guide

Start with the accounts that could stop your business

A small business can reduce common cyber risks by protecting its main email, bank and payment access, customer records, online store, domain and backups. CERT-In's MSME guidance covers steps such as strong access controls, multi-factor authentication, backups and staff awareness. No checklist prevents every attack, so decide who will respond and how the business will keep operating if an account is locked.

Secure the business email and administrator accounts first

Use a unique long password for each critical account and store it in a reputable password manager. Turn on multi-factor authentication where offered, keep recovery codes offline in a secure place, and remove former workers' access promptly. Use named accounts rather than a shared founder login so actions can be traced and one person's departure does not lock everyone out.

Limit who can reach money, customer data and company devices

Give staff only the access needed for their work and review it when responsibilities change. Require a second approval for large or unusual payments, vendor bank-detail changes and bulk exports of customer information. Keep business records in company-controlled services, enable device screen locks and updates, and separate company activity from personal email where possible.

Keep a backup that you can restore

Back up invoices, customer and supplier records, product files, website content and accounting exports on a schedule. Keep at least one backup protected from everyday account access, and test restoring a small file so you know the copy is usable. A synced folder alone may copy accidental deletion or ransomware changes; ask your provider or IT adviser how version history and recovery work.

One-page business cyber plan
Critical assetAccount owner and backup personRecovery step
Business email and domain
Bank, UPI and payment-gateway accounts
Accounting, GST and payroll records
Online store and social accounts
Customer and supplier data
Offline or protected backup

Prevent common scams and payment mistakes

Treat unexpected links, QR codes and urgent instructions as unverified

Pause before opening a message that claims a payment failed, a marketplace account will close or a customer needs a refund. Check the sender using a known phone number or the official app, not a link or number supplied in the message. Do not install a screen-sharing or remote-access app because a caller says it is needed to receive money or release a payment.

Verify settlement and account changes through your acquiring bank

UPI merchant settlement timing and dispute handling can depend on the acquiring bank and merchant agreement. If a sale or settlement is missing, contact the acquiring bank or payment provider using the number in your contract or its official app. Do not pay a stranger a 'release fee' or share an OTP to reverse a transaction.

Respond quickly if a device, account or payment is compromised

Contain access from a clean, trusted device

If you suspect account takeover, stop using the affected device for sensitive tasks, disconnect it from the network if a technician advises that step, and use a separate trusted device to change the most important passwords and revoke other sessions. Contact the bank or acquiring provider promptly to block or secure payment access. Do not erase the device or messages before preserving evidence unless immediate safety or expert advice requires it.

Record what happened and notify the right provider

Write down the time, amount, transaction reference, account or device affected, caller numbers, URLs and actions taken. Preserve screenshots and bank messages in a restricted folder. Contact your bank, payment gateway, marketplace or telecom provider through its official channel. Ask what account block, dispute form, credential reset and business-continuity step applies; do not assume one report automatically alerts every provider.

Report suspected cyber financial fraud promptly

For a suspected cyber financial fraud in India, contact 1930 as soon as possible and report through the National Cyber Crime Reporting Portal. Rapid reporting may help the authorities and banks act on a transaction, but recovery is not guaranteed. Keep the acknowledgement number and follow the investigating agency's instructions. If employees or customer data were exposed, obtain advice on additional legal, contractual and privacy notifications.

Questions women business owners ask about cyber safety

Does a small MSME need an IT department to improve security?

No. Start with the highest-impact basics: protect email and payment access, enable multi-factor authentication, update devices, limit permissions, keep tested backups and teach staff how to verify urgent requests. Use a qualified IT professional for network design, incident response or a legal reporting question that is beyond the team's ability.

Should business and personal accounts be kept separate?

Where practical, use separate business email, devices, bank accounts and cloud storage, with permissions matched to each role. Separation makes access review, bookkeeping, backup and incident response clearer. If a founder must use one device, enable a strong screen lock, keep software current and avoid storing recovery codes where an attacker who enters the email account can also find them.