India’s cybersecurity startups are watching a perfect storm brew as AI-powered attacks grow more sophisticated and companies scramble to comply with the Digital Personal Data Protection Act (DPDP Act).
The conditions appear ripe for a breakout. Yet for many startups, India is proving to be only the starting point, as they look to the US, West Asia and Europe for revenue, and, in some cases, enterprise customers whose logos can help them win business back home.
“Cybersecurity, enterprise security, enterprise data management, tech founders get to $1-3 million kind of annual recurring revenue (ARR) in India, and then they quickly start building rails overseas,” said Ajay Modi, partner and founding member at asset and fund management firm Piper Serica.
The shift is not necessarily a sign that the country's cybersecurity opportunity is weakening. Rather, startups say the global market offers larger contracts, deeper enterprise demand and access to a wider pool of customers.
India’s cybersecurity market is estimated at $6.56 billion in 2026, a fraction of the nearly $100 billion US market, according to market research and advisory firm Mordor Intelligence.
Contrails AI, a seed-stage trust and safety startup that detects deepfakes and AI-generated fraud, has operated in the US since 2023 and plans to expand further into the US and enter the UK and parts of Europe.
Co-founder Amitabh Kumar said the company expects its revenue mix to shift closer to 50:50 between India and international markets by the end of 2026, as several US contracts progress.
“Right now, it's roughly 20% from the US and 80% from India. However, that's largely because we closed a very large contract in India just two days ago, which significantly changed the mix. Going forward, by the end of the year, I expect it to be much closer to 50-50 because we have several US contracts in the pipeline,” added Kumar.
“In terms of deal size, international contracts are at least 10x larger than those in India, and in some cases, even 100x larger,” Kumar said. “A 10x contract is what helps an AI startup break even, while a 100x contract gives you a healthy profit margin.”
For some founders, international customers can also act as a credibility signal when selling back into India. “If I already have a small bank in the US or the West that is using me for their data-risk management, then a smaller mid-sized bank in India would be open to considering me because I already have a regulated entity overseas as my customer,” Modi said.
“A lot of founders also think that a few early customers overseas will help convert my domestic customers,” he added.
For example, Deep Algorithms (Deep Algorithms Solutions), an Indian AI and cybersecurity startup, has already set up a subsidiary in the US and plans to enter the market with offerings tailored to the American market in the next few weeks.
“Cybersecurity is an international issue, and any organization faces similar problems in terms of identity security, ransomware, and attacks made with the help of AI technologies. With the help of expansion into the international market, we will have the chance to attract more customers and work in different security environments,” said J.P. Mishra, founder and chief executive, Deep Algorithms.
Further, founders argue that startups don't expand abroad just for customers. Mitigata, an AI-powered cyber resilience and insurance platform, has clients across Australia, West Asia, Europe, and the US, and is strengthening its presence in the United Arab Emirates, Abu Dhabi, and Europe.
“Once you reach the Series C or D stage and start raising $50-100 million rounds, most of that capital comes from global investors in the US and Europe. Having an international presence becomes important to attract that funding," said Mohit Anand, CEO and co-founder of Mitigata.
For instance, cybersecurity startup SAFE Security, which has a presence in the US, raised a $70 million Series C round in July 2025, led by India-based VC Avataar Ventures, with participation from global investors such as Susquehanna Asia Venture Capital, NextEquity Partners and Prosperity7 Ventures, alongside existing investors.
"There's a common saying in B2B (business-to-business): ‘Build from India, build for the world.’ You leverage India's cost and talent advantages to build products, then sell globally where deal sizes and margins are much higher. That's why most B2B startups eventually expand overseas,” he added.
Overall funding for Indian cybersecurity startups remained broadly flat at about $116 million in 2024 and $115 million in 2025, according to startup data platform Tracxn.
But the composition changed sharply: late-stage funding fell from $97.4 million to $19.8 million, while early-stage funding jumped from $2.1 million to $81.5 million.
In the first eight months of 2026, early-stage funding stood at $64.8 million, compared with $24 million in late-stage funding, suggesting that investors have become more selective about funding companies at the stage where they need to demonstrate significant commercial scale.
Primarily because, while the need is becoming more urgent, the domestic market is not yet deep enough for every new-age cybersecurity company to scale quickly.
Modi expects regulatory pressure to eventually push more enterprises to act. “As we get closer to the regulation, as the regulator comes and pushes enterprises to think about this, that is when adoption will scale,” he said.
The regulatory push is indeed beginning to change enterprise behaviour, particularly in financial services. Hardik Bhatia, a partner at Khaitan & Co., said that banking, financial services, and insurance (BFSI) and fintech companies have been the most active in strengthening cybersecurity and data protection frameworks.
Companies are “proactively strengthening their cybersecurity and data protection frameworks rather than waiting for penalties to materialize”, he said.
Supratim Chakraborty, partner at Khaitan & Co., added that gaps in awareness and clarity over implementation are holding back spending, with many businesses still viewing data protection as a “tick-the-box exercise”. The principles-based DPDP Act also leaves companies uncertain about what constitutes “reasonable security safeguards” and how much they need to invest.
This uncertainty, coupled with the perception of cybersecurity and data protection as cost centres, could lead companies to adopt a “wait-and-watch” approach until enforcement becomes more established, he said.
Comments ()
Be the first to share your perspective on this story!