The Framework
The 15 Elemental Cyber Defence Controls represent India’s first structured, MSME-specific cybersecurity baseline — a framework designed not for enterprise IT departments, but for the business owner whose name is on the lease. The controls cover the essential perimeter of protection that every small business in India should operate within, regardless of sector or size.
xIoTz’s contribution drew directly from field experience: working with MSMEs across India, the UAE, and Australia, the company identified the gap between what enterprise cybersecurity tools promise and what small businesses actually need. That gap — too many tools, too little real protection, at prices that don’t scale down — became the foundational problem the controls are designed to close.
| No. | Control Area | Description |
|---|
| 01 | Effective Asset Management | Know every device, software, and data asset in your business. Track them from day one to secure disposal. Nothing unknown should exist on your network. |
| 02 | Network & Email Security | Proper firewalls. Secure Wi-Fi (WPA2/WPA3). VPN and MFA for remote access. Email protection via SPF, DKIM, DMARC — the front line against phishing. |
| 03 | Endpoint & Mobile Security | Licensed EDR on every device. No pirated software. USB restrictions. Built-in OS security features switched on — no exceptions. |
| 04 | Secure Configurations | Configure every server, endpoint, and application securely before it goes live. Disable what you don’t use. Default settings are not safe settings. |
| 05 | Patch Management | Update regularly — operating systems, applications, firmware. Unpatched systems are open doors. Attackers scan for known vulnerabilities within hours of public disclosure. |
| 06 | Incident Management | Have a plan before you need one. Detection, response, investigation, recovery — all mapped out. Major incidents must be reported within 6 hours of detection. |
| 07 | Logging & Monitoring | Record system activities. Monitor anomalies. Retain logs for 180 days within India — a mandatory legal requirement. |
| 08 | Awareness & Training | Train employees at least twice a year on phishing, passwords, data protection, and social engineering. |
| 09 | Third-Party Risk Management | Evaluate vendor security posture. Enforce security standards contractually. Your vendors inherit your risk. |
| 10 | Data Protection, Backup & Recovery | Use encrypted backups stored offline/offsite. Test recovery regularly. If you can’t restore it, it doesn’t count. |
| 11 | Governance & Compliance | Assign cybersecurity ownership. Maintain approved policies. Follow regulatory guidelines — accountability is critical. |
| 12 | Robust Password Policy | Enforce strong passwords, account lockouts, and MFA. Avoid password reuse at all costs. |
| 13 | Access Control & Identity Management | Use unique user IDs, role-based access, and regular permission reviews. Revoke access immediately on role change or exit. |
| 14 | Physical Security | Secure server rooms and infrastructure with controlled access, CCTV, badges, and biometrics where required. |
| 15 | Vulnerability Audits & Assessments | Conduct annual audits via certified auditors. Focus on remediation — not just assessment. |
Significance
India has 63 million MSMEs. They employ over 110 million people, contribute nearly 30% of GDP, and are — according to every major cybersecurity report — the primary target for cybercriminals. The reason is simple: they are the least protected link in every supply chain, and most of them believe they are too small to be targeted.
That belief is the vulnerability. xIoTz has been saying it since Day 0. The National Cybersecurity Framework for MSMEs, backed by CERT-In, now says it at the level of national policy.
For xIoTz, the contribution is not a departure from the mission. It is the mission operating at scale. The same insight that drives the product — that enterprise-grade cybersecurity has never been designed for the MSME — is the same insight that shaped the framework. The 15 controls are not a simplified version of what enterprises use. They are a clean, practical, non-negotiable baseline for businesses that have never had one.
About the Contribution
xIoTz’s contribution to the National Cybersecurity Framework for MSMEs reflects the company’s broader engagement with India’s national cybersecurity ecosystem. Incubated and seed-funded by FIRST and C3iHub at IIT Kanpur, accelerated by the Data Security Council of India and the National Centre of Excellence, and recognised with the iDEX DIO DISC IX Challenge award for the Indian Navy and the National Technology Awards 2023, xIoTz has consistently operated at the intersection of product-building and national security infrastructure.

The company currently operates in India, the UAE, and Australia. It is bootstrapped and profitable. The CERT-In contribution adds a policy dimension to a commercial track record already built on protecting the segment that India’s cybersecurity infrastructure was not originally designed to serve.
About xIoTz — Cyber Assurance for MSMEs India
Founded in 2021 and headquartered in Bengaluru, India, xIoTz Private Limited is a cybersecurity company on a mission to democratise cyber assurance for MSMEs and enterprises across India. Built in India, for India and the world.
Learn more at xiotz.com →