Cybersecurity is no longer just about stopping hackers from entering a company’s network. For Indian large IT-services companies, the bigger question is increasingly becoming: If an attack succeeds, how quickly can the business get its most important operations running again?
That shift is pushing technology companies toward a strategy known as “minimum viability” or Minimum Business Viability (MBV).
The idea is straightforward: instead of trying to restore every system immediately after a major cyberattack, companies first identify the applications, data, people and processes that are absolutely essential to keeping the business functioning.
Recent reports indicate that companies including TCS, Infosys, Persistent Systems, LTIMindtree and Coforge are investing in MBV assessments and cyber-resilience programmes as cyber risks and potential legal consequences increase.
What exactly is “minimum viability”?
Imagine a company suffers a major ransomware attack and thousands of computers become unavailable.
The traditional instinct might be to restore everything as quickly as possible.
But that can be complicated and inefficient.
A minimum-viability strategy asks a different question:
What are the few systems we absolutely need to restart first?
These could include customer-facing applications, payment systems, communication platforms, identity-management systems, essential databases and other business-critical services.
The objective is not to return to 100% normal operations immediately. It is to reach a minimum level of functioning that allows the company to continue serving customers and generating revenue while the wider recovery continues.
Cyber-resilience specialists describe minimum viability as the combination of critical applications, assets, processes and people required to keep an organisation operational after an attack or major disruption.
Why is this becoming important now?
Cyberattacks are becoming more disruptive.
A successful attack can do much more than steal information. It can interrupt operations, lock systems, compromise backups, expose sensitive information and create significant financial and reputational consequences.
For large IT-services companies, the stakes are particularly high because they manage technology environments and sensitive information for thousands of employees and customers.
Recent incidents have highlighted the challenge.
TCS recently said it had received alerts suggesting potential exposure of some employee-related data, while stressing that there was no indication that customer data or operational systems had been affected.
HCLTech similarly said that an internal investigation found no evidence of a system compromise following claims by a hacker group involving employee information.
These cases do not establish that either company’s core systems were breached. But they illustrate why enterprises are increasingly treating cyber resilience as a board-level business issue rather than simply an IT problem.
Prevention alone is no longer enough
Companies have traditionally invested heavily in firewalls, endpoint protection, threat detection and other tools designed to prevent attacks.
Those measures remain essential.
But modern cybersecurity planning increasingly assumes that organisations may eventually face a successful intrusion or serious outage.
That changes the priority from:
“How do we make sure nothing ever goes wrong?”
to:
“How do we keep the business operating when something does go wrong?”
That is where minimum viability becomes important.
It provides a practical bridge between cybersecurity and business continuity.
The first step is identifying what really matters
An Indian company cannot create a minimum-viability plan until it understands which systems are essential.
For example, a bank might prioritise its payment and transaction systems.
An online retailer might prioritise its website, order-management platform and payment infrastructure.
A hospital would need to prioritise systems required for patient care.
An IT-services company could have hundreds or thousands of applications supporting different customers, making prioritisation particularly complex.
The goal is to map these dependencies before an emergency occurs.
Clean data is just as important as available data
Restoring a system quickly is not enough if the backup being restored is already compromised.
Cyberattackers increasingly target backup environments because they know that organisations depend on backups for recovery.
That means companies need to know not only where their backups are, but also whether those backups can be trusted.
Indian Cyber-resilience guidance recommends maintaining protected copies of critical information, including isolated or air-gapped backups, and regularly testing recovery procedures.
A recovery plan that exists only on paper may not work under real-world pressure.
Testing is becoming a critical part of resilience
One of the biggest weaknesses in disaster recovery is assuming that a plan will work simply because it has been documented.
Companies need to test it.
That can involve simulated cyberattacks, tabletop exercises and actual recovery tests.
Testing can reveal problems such as:
- Missing backup data
- Incorrect recovery priorities
- Outdated contact information
- Dependencies between applications
- Lack of trained personnel
- Systems that cannot be restored within the required timeframe
The more frequently organisations test these processes, the better prepared they can be for an actual incident.
Cybersecurity is also becoming a legal and financial issue
A serious cyber incident can result in more than technical disruption.
Companies may face regulatory investigations, contractual disputes, lawsuits, customer compensation claims and reputational damage.
This is particularly important for IT-service providers because customers may expect them to maintain strong security controls around sensitive information and systems.
Indian Infosys, for example, identifies cybersecurity as an important enterprise risk in its 2025–26 annual report and says that cyberattacks could affect operations, client satisfaction and potentially result in regulatory penalties.
This makes cyber resilience an important part of risk management—not merely an expense for the technology department.
AI is making the challenge more complicated
Artificial intelligence is creating opportunities for businesses, but it is also changing the cybersecurity landscape.
AI can help Indian security teams identify suspicious behaviour and automate parts of threat detection.
At the same time, attackers can potentially use AI to improve phishing, social engineering, malware development and reconnaissance.
Indian IT companies are already dealing with a broader transformation as AI changes the way technology services are delivered.
TCS, for example, says in its latest annual report that customers are increasing investments in areas such as cybersecurity, data foundations and application transformation as they prepare their technology environments for AI adoption.
This means Indian companies increasingly have to manage two challenges at once: adopting AI quickly while protecting the systems and information that AI depends on.
What does minimum viability mean for customers?
For customers of Indian IT-services companies, stronger minimum-viability planning could provide an additional layer of confidence.
A resilient provider should ideally be able to answer questions such as:
- Which services would be restored first after a major attack?
- How quickly could critical operations return?
- Are backups protected from the same attack?
- Who has Indian authority to make recovery decisions?
- How frequently are recovery procedures tested?
- What happens if a third-party system is unavailable?
These questions can become increasingly important when businesses outsource critical technology functions.
It is not about accepting failure
The phrase “minimum viability” might sound as though Indian companies are preparing to accept cyberattacks.
That is not the objective.
The strategy complements prevention and detection.
Indian Companies still need strong security controls to reduce the probability of an attack. Minimum viability focuses on what happens after prevention fails or another major disruption occurs.
Think of it as the cybersecurity equivalent of an emergency operating plan.
The goal is to make sure that one serious incident does not bring the entire organisation to a standstill.
The bigger shift in corporate cybersecurity
The emergence of minimum viability reflects a broader change in how businesses think about cyber risk.
Security is moving from a purely technical question to a business-continuity question.
Executives increasingly need to understand which systems are essential to revenue, customers and operations—and how those systems can be recovered safely.
For Indian IT-services industry, this could become especially important as companies manage enormous technology environments while dealing with AI-driven transformation, increasingly sophisticated cyber threats and growing regulatory expectations.
The companies that invest in resilience before an attack occurs may have a significant advantage over those that only begin planning after a crisis.
In the end, the most important cybersecurity question may not be whether a Indian company can prevent every attack.
It may be whether the company can keep its most important functions alive when the worst happens.
Disclaimer
This article is for general informational and educational purposes. Cybersecurity strategies vary by Indian organization, industry and regulatory environment. References to companies and recent security incidents describe publicly reported information and do not imply that those companies suffered confirmed breaches unless specifically stated by the relevant source.
Learn more about our site on contactarchive2in.com
Contact us on our email id contactarchive2in@gmail.com


Leave a Reply
You must be logged in to post a comment.