top of page

CERT-In's 15 Essential Cyber Security Controls for MSMEs: A Practical Implementation Guide


Introduction

 

Cybersecurity has become a business necessity for every organization. As cyber threats continue to evolve, many Indian small and medium enterprises (MSMEs) struggle to understand where to begin.

To help organizations strengthen their cyber resilience, the Indian Computer Emergency Response Team (CERT-In) has published the 15 Essential Cyber Security Controls for MSMEs. These controls provide practical guidance that organizations can adopt to improve their security posture without requiring large security teams or expensive technology.

This guide explains each control in simple language and provides practical recommendations for implementation.

 

What is CERT-In?

 

The Indian Computer Emergency Response Team (CERT-In) is the national agency responsible for responding to cybersecurity incidents and strengthening cyber resilience across India.

 

CERT-In regularly publishes advisories, best practices, vulnerability alerts, and security recommendations for government departments, enterprises, and MSMEs.

 

The 15 Essential Cyber Security Controls serve as a practical baseline that organizations can use to improve their cybersecurity maturity.

 

Are the 15 Controls Mandatory?

 

The 15 Essential Cyber Security Controls are recommended best practices, not a standalone law.

 

However, implementing these controls can help organizations:

  • Improve cyber resilience

  • Reduce operational risk

  • Prepare for customer security assessments

  • Support compliance with other regulations such as the Digital Personal Data Protection (DPDP) Act

  • Demonstrate good cybersecurity governance

 

Organizations operating in regulated sectors may also need to comply with additional industry-specific requirements.

 

CERT-In's 15 Essential Cyber Security Controls

 
1. Asset Inventory

 

Know what hardware, software, cloud services, and digital assets your organization owns.

 

Practical Steps

  • Maintain an inventory of laptops and servers.

  • Document software licenses.

  • Track cloud accounts.

  • Remove unused systems.

 
2. Identity and Access Management

 

Ensure that users have only the access they need.

Best Practices

  • Enable Multi-Factor Authentication (MFA)

  • Use strong passwords

  • Remove inactive accounts

  • Review user permissions regularly

 
3. Secure Configuration

 

Avoid using default configurations.

Examples include:

  • Disable unnecessary services

  • Change default passwords

  • Apply secure configuration baselines

  • Restrict administrative access

 
4. Patch Management

 

Keep operating systems and applications updated.

 

Organizations should:

  • Install security updates promptly

  • Prioritize critical vulnerabilities

  • Maintain an update schedule

 
5. Malware Protection

 

Deploy modern endpoint protection solutions.

 

Recommendations include:

  • Antivirus or Endpoint Detection and Response (EDR)

  • Email malware scanning

  • Web filtering

  • USB device controls

 
6. Backup and Recovery

 

Maintain secure backups of critical business data.

 

A good backup strategy includes:

  • Regular automated backups

  • Offline or immutable backups

  • Periodic recovery testing

 
7. Network Security

 

Protect internal and external network traffic.

 

Typical controls include:

  • Firewalls

  • Network segmentation

  • Secure Wi-Fi

  • VPN for remote access

 
8. Email Security

 

Email remains one of the primary attack vectors.

 

Organizations should implement:

  • SPF

  • DKIM

  • DMARC

  • Anti-phishing protection

  • Email filtering

 
9. Logging and Monitoring

 

Collect and review security logs to detect suspicious activity.

Monitor:

  • Login attempts

  • Administrative actions

  • Failed authentication

  • System changes

 
10. Vulnerability Assessment

 

Regularly identify security weaknesses.

 

This may include:

  • Vulnerability scanning

  • Configuration reviews

  • Cloud security assessments

 
11. Incident Response

 

Prepare for security incidents before they occur.

 

Every organization should have:

  • Incident response procedures

  • Contact lists

  • Escalation processes

  • Recovery plans

 
12. Employee Awareness

 

Human error remains one of the largest cybersecurity risks.

 

Conduct regular awareness training covering:

  • Phishing

  • Password hygiene

  • Safe internet practices

  • AI usage policies

 
13. Data Protection

 

Protect sensitive business and personal data.

 

Measures include:

  • Encryption

  • Access controls

  • Secure sharing

  • Data classification

 
14. Third-Party Risk Management

 

Assess the cybersecurity practices of vendors and service providers.

Review:

  • Cloud providers

  • Software vendors

  • Outsourced IT partners

 
15. Governance and Continuous Improvement

 

Cybersecurity should be reviewed continuously rather than treated as a one-time project.

 

Organizations should:

  • Review security posture regularly

  • Track improvement over time

  • Assign ownership

  • Measure cyber readiness

 
Practical Implementation Roadmap for MSMEs

 

Organizations do not need to implement all controls simultaneously.

A phased approach works best.

 

Phase 1 – Foundation
  • Asset Inventory

  • MFA

  • Backups

  • Antivirus

  • Email Security

 
Phase 2 – Strengthening
  • Patch Management

  • Vulnerability Assessment

  • Logging

  • Secure Configuration

 
Phase 3 – Governance
  • Incident Response

  • Vendor Risk

  • Data Protection

  • Security Awareness

  • Continuous Cyber Readiness Reviews

 
Common Challenges Faced by MSMEs

 

Many organizations struggle because they:

  • Have limited cybersecurity expertise

  • Use multiple disconnected security tools

  • Lack visibility into cloud environments

  • Cannot prioritize remediation efforts

  • Are unsure which controls need immediate attention

 

Rather than implementing controls in isolation, organizations benefit from understanding their overall cyber readiness and focusing on the most significant risks first.

 

How CyBelt Helps

 

CyBelt helps organizations continuously assess their cyber readiness by evaluating key security domains, identifying gaps aligned with recognized cybersecurity practices, and prioritizing remediation actions in clear business language.

Instead of generating lengthy technical reports, CyBelt provides actionable recommendations that help organizations improve security posture over time while supporting compliance initiatives.

 

Frequently Asked Questions

 

Does CERT-In require all MSMEs to implement these controls?

The controls are recommended best practices that provide a strong cybersecurity baseline. Organizations in regulated sectors may have additional mandatory requirements.

 

How often should these controls be reviewed?

Cybersecurity should be reviewed continuously. At a minimum, organizations should reassess their controls annually or whenever significant changes occur.

 

Are these controls sufficient for DPDP compliance?

The controls support stronger security practices but do not, by themselves, guarantee compliance with the Digital Personal Data Protection (DPDP) Act. Organizations should also address privacy governance, consent management, and other legal obligations.

 

Do I need expensive cybersecurity software?

Not necessarily. Many organizations can significantly improve their security posture through better configurations, strong identity management, timely patching, employee awareness, and regular assessments before investing in additional tools.

bottom of page