



Phishing has been a persistent threat for two decades, but 2025 has brought a step change in sophistication that is catching Indian enterprises off guard. Generative AI now lets adversaries craft hyper-personalised lure emails at industrial scale — cloning internal writing styles, forging believable invoice threads, and even synthesising audio deepfakes of senior executives to authorise wire transfers. For Indian CISOs managing complex, multi-site environments, the threat is no longer “someone clicked a bad link.” It is “our CFO heard the MD’s voice and moved ₹4 crore.”
This post examines how AI-augmented phishing works, what makes Indian enterprises particularly exposed, and what a layered defence — spanning email security, endpoint detection, SOC vigilance, and employee awareness — looks like in practice.
Traditional phishing relied on volume: send ten million generic emails and hope a fraction slip through. Spam filters learned to catch the obvious patterns — misspelled domains, generic greetings, suspicious attachments. Today’s AI-assisted campaigns invert that model.
India is not simply a large market for phishing — it has specific structural characteristics that raise exposure.
The pace of cloud adoption, UPI integration, and remote work expansion across Indian enterprises has outrun security investments for many organisations. Mid-market companies in sectors like manufacturing, logistics, and real estate often have modern ERP systems but rely on legacy email gateways and minimal SOC coverage.
The Indian enterprise supply chain is characterised by layered sub-contracting. An attacker compromising a tier-3 vendor’s email domain can send convincing invoices to a tier-1 enterprise. DPDP Act obligations notwithstanding, many vendors have limited incident response capabilities, making the lateral exposure difficult to contain.
The CERT-In Directions of 2022, as updated, require organisations to report qualifying cyber incidents — including phishing compromises that result in data exfiltration — within six hours of detection. Most Indian enterprises are not yet equipped to detect, triage, and report within this window without automated tooling. An undetected credential harvest that leads to a data breach can quickly become a regulatory issue on top of the operational damage.
Despite policy mandates, a significant share of enterprise applications — particularly ERP systems deployed five or more years ago — remain protected only by password. Credential phishing against these portals remains highly effective because there is no second factor to bypass.
A realistic attack chain in 2025 looks like this:
The window between initial credential compromise and containment is where the CERT-In 6-hour reporting clock starts ticking — and where most organisations lose the race.
A next-generation secure email gateway should be doing more than spam filtering in 2025. FortiMail, deployed as part of PJ Networks’ managed email security service, applies sandboxed URL detonation, AI-based sender behaviour analysis, DMARC/DKIM/SPF enforcement, and lookalike domain detection. Critically, it should be configured to quarantine — not just flag — messages from domains registered in the last 30 days, a strong signal of phishing infrastructure.
Push-based TOTP MFA is necessary but not sufficient against session-hijacking proxies. Organisations should prioritise FIDO2/WebAuthn (hardware keys or passkeys) for privileged accounts — finance approvers, IT admins, executive assistants — as these credentials are cryptographically bound to the legitimate domain and cannot be relayed by a proxy.
Traditional VPN grants network-level access after a single authentication event — a wide blast radius if credentials are phished. Zero Trust Network Access (ZTNA), as delivered through FortiGate and Fortinet’s ZTNA framework, continuously evaluates device posture and user context before allowing access to each specific application. A phished credential alone is insufficient to traverse the environment.
Phishing detection at the gateway catches many campaigns — but not all. A credential harvest via a reverse proxy may produce no malware signature at all. What it does produce is behavioural anomalies: a login from an unusual geography, an unusual volume of email forwarding rules being set, access to the ERP at 2 AM on a Sunday. A staffed 24/7 SOC with UEBA (User and Entity Behaviour Analytics) rules is the backstop.
Technology controls are necessary but not sufficient. Quarterly simulated phishing campaigns — specifically targeting finance, HR, and executive assistant roles — keep human vigilance calibrated. The goal is not to punish failures but to measure and reduce the click rate over time, and to build the muscle memory of “verify by phone before acting on an unusual request.”
A phishing campaign that bypasses the email gateway and steals a session cookie will leave traces — but only if the SOC has the visibility and automation to act on them quickly enough. This is where we deploy and operate PrahiX Ora for our clients: a unified SecOps platform built by PrahiX Tech Pvt Ltd that collapses the tooling sprawl that typically slows SOC response.
SIEM — Correlating signals across the kill chain: The platform’s SIEM ingests logs from FortiGate, FortiMail, Active Directory, ERP access logs, and cloud platforms into a single correlation engine. Detection rules mapped to MITRE ATT&CK — specifically T1566 (Phishing), T1539 (Steal Web Session Cookie), and T1071 (Application Layer Protocol) — fire enriched alerts rather than raw log lines. When an adversary sets unusual inbox-forwarding rules post-compromise, the graph-based attack storyline reconstruction surfaces it as part of a coherent attack thread, not an isolated event. For CERT-In compliance, the platform supports tiered log retention — hot, cold, and archive tiers — supporting the 180-day in-country log retention direction so your evidence trail is intact if regulators ask.
NMS — Seeing the network move: Phishing is often the entry point for a broader intrusion. The Network Management System provides unified observability across FortiGate firewalls, switches, APs, and WAN/SD-WAN links. LLDP/CDP topology discovery and network path tracing mean that when a compromised endpoint begins lateral scanning, ML-based anomaly detection flags it before it becomes a full incident. For multi-vendor estates where NOC visibility is fragmented across separate consoles, this unified view is operationally significant.
Video surveillance (VMS) — Closing the physical loop: Social engineering attacks do not always begin digitally. An adversary may tailgate into a facility to physically insert a rogue device, or conduct physical reconnaissance before a targeted spear-phishing campaign. The video surveillance (VMS) module manages ONVIF/Hikvision/Dahua cameras with video analytics, bringing physical and network security under a single operations view — particularly valuable for manufacturing, retail, and multi-site estates where physical access events should be correlated with network anomalies.
SOAR — Making CERT-In’s 6-hour clock achievable: The hardest part of CERT-In compliance is not documentation — it is detection-to-response speed. The SOAR module automates the response actions that would otherwise require manual SOC intervention: isolating a compromised endpoint, pushing an attacker’s IP to the FortiGate blocklist, disabling a compromised AD account, and generating the structured incident log needed for CERT-In notification. Pre-built playbook connectors cover common phishing response scenarios. Without this automation, reliably meeting a 6-hour reporting window across a large, distributed estate is aspirational. With it, it becomes operational.
If your organisation is assessing whether your current SecOps stack can deliver this kind of coordinated response, we are happy to walk through what a PrahiX Ora deployment looks like in an Indian enterprise context.
For Indian enterprise security leaders looking to address AI-augmented phishing in a structured way, the following phased approach provides a practical starting point.
India’s Digital Personal Data Protection Act 2023 creates data fiduciary obligations that phishing attacks directly implicate. A successful credential phish that leads to unauthorised access to personal data — employee records, customer databases, healthcare information — triggers breach notification requirements. Combined with CERT-In’s 6-hour technical incident reporting, organisations face a tight, overlapping compliance timeline in the event of a successful attack.
Importantly, the DPDP Act does not allow organisations to contractually shift liability to a vendor — the data fiduciary is accountable. This means that even if a phishing attack originates through a third-party vendor’s compromised email, the data fiduciary holding the personal data remains responsible for notification and remediation. Third-party risk management programmes, including vendor email security assessments, are no longer optional.
Keeping detailed, timestamped incident logs is also a practical prerequisite for demonstrating compliance. Without automated log retention across all relevant systems, reconstructing what happened — and when — after a compromise is painstaking and often incomplete. This is precisely where tiered SIEM retention helps evidence compliance obligations under both the DPDP Act and CERT-In directions.
PJ Networks delivers managed security services purpose-built for the Indian enterprise environment. Our FortiMail managed email security service covers gateway configuration, ongoing tuning, and threat intelligence updates — without requiring in-house expertise. Our 24/7 NOC/SOC, backed by the PrahiX Ora platform we deploy and operate for clients, provides the continuous monitoring and automated response capability that makes CERT-In compliance achievable rather than aspirational. Where organisations are moving from VPN to ZTNA, our FortiGate and Fortinet ZTNA deployment practice handles the architecture and migration.
AI-augmented phishing is not a future threat — it is the current reality for Indian enterprises. The organisations that manage it well in 2025 will be those that move from perimeter-centric email security to layered, behaviour-aware defences with genuine SOC depth. If you would like a no-obligation assessment of your current email security and SOC coverage, reach out to the PJ Networks team.