Trending
ee-track">

Cyble and DRONA Announce Collaboration to Extend India’s Cyber Defence Beyond the Enterprise

Cyble will supply the intelligence, investigation and endpoint technology. DRONA will operate it as a service from its 24×7 command and control centre in Ahmedabad. Together the two companies have set out to reach the businesses, institutions and individuals in India who have never had access to defence of this kind — and have named the outcomes they intend to be measured against. 

 

Ahmedabad, India — 26 August 2026 — Cyble, the global AI-native cybersecurity company, and DRONA Cyber Solutions today announced a collaboration intended to widen access to cyber defence in India well beyond the large enterprises and government bodies that have historically been able to obtain it. 

 

Under the collaboration, Cyble supplies the platforms — adversary intelligence, digital risk protection, investigation tooling and AI-native endpoint security. DRONA delivers them to Indian customers as an operated service, staffed by its own analysts from its established command and control centre in Ahmedabad. The technology is already in use by central banks, national cyber agencies and defence organisations in several countries. What changes is who in India can now be defended by it. 

 

The intended reach is deliberately broad: manufacturers with no security staff, hospitals that cannot take systems offline, schools, mid-sized businesses in Tier-2 and Tier-3 cities — and, in a category that has until now had almost nothing, individuals and their families. 

 

What the collaboration sets out to do 

Both companies were direct that this is a statement of intent, and proposed five outcomes against which it should be judged: 

 

  • Bring intelligence-led defence to organisations below the enterprise threshold — the segment currently absorbing the fastest-growing share of attacks in India and least equipped to answer them. 
  • Extend protection to individuals. Monitoring of stolen credentials, leaked identity documents, impersonation and synthetic likeness has not been purchasable by a private person at any price. The collaboration is intended to change that. 
  • Shorten the distance between compromise and discovery. In most cases today, weeks pass before anyone notices. The target is hours. 
  • Improve the evidentiary quality of what reaches Indian investigators. Of 28.15 lakh cybercrime cases reported in 2025, 55,484 became FIRs — two in every hundred. Findings preserved to evidentiary standard at the moment of discovery are intended to raise how many complaints can actually be acted upon. 
  • Build capacity that outlasts both companies. Through DRONA’s Cyber Yodha Campaign, analysts are trained on live collection and live incidents inside a working command centre rather than on simulations. 

None of these are claims about what has been achieved. They are the terms the two companies have proposed for their own assessment. 

“India’s exposure is far too large for any one company or any one partnership to claim credit for solving. This is one collaboration among many that need to exist, and more of them should. The measure of it is whether the country’s defences are stronger in three years — not whether we hold a larger share of them.” 

Mandar Patil, Executive Vice President, Cyble 

Why this has been out of reach 

Capability of this kind has been enterprise-only, and not because anyone decided smaller organisations did not deserve it. Threat intelligence platforms are priced for institutions, sold on annual contracts, and — more decisively — they assume a security team exists to operate them. A system producing a thousand findings a week is worthless to a company with nobody to read them. Below a certain size, the operating model breaks down entirely. 

 

The collaboration addresses that operating model rather than the technology. Cyble contributes collection, correlation and enforcement at a scale no regional provider could build alone. DRONA contributes the analysts, the shift rota, the forensics bench and the accountability — the part that was always the obstacle, and the part that cannot be licensed. 

“Neither of us could have done this alone, and both of us could have tried. Cyble has collection and analysis at a scale we would have spent a decade building badly. We have the analysts, the forensics bench and the shift rota, and we are in the same time zone as the customer. Putting the two together is what makes this reachable for a company of thirty people, or for one person.” 

— Dhruv Pandit, Co-Founder & CEO, DRONA Cyber Solutions 

What it means in practice 

Four things, and they are deliberately simple to state: 

 

  • Somebody is looking. Continuously, on the customer’s behalf — for an organisation’s exposure, and for a named individual’s credentials, identity documents, family details, likeness and voice. 
  • Somebody answers. At any hour, in Indian time, by name. Not a ticket queue and not a dashboard — DRONA analysts on shift who pick up the phone, backed by a published 10-minute response commitment. 
  • The evidence is kept. Findings are preserved to an evidentiary standard at the moment of discovery, so a customer can file an FIR, approach a court, or answer a regulator with proof rather than a description. 
  • Somebody follows through. Content is pursued for removal, the infrastructure behind it is investigated, and the matter is worked until it is resolved — rather than detected and then left. 

“Most security failures are failures of follow-through. Something is detected, and then nothing happens for six weeks. What this collaboration puts in front of India is one continuous chain — intelligence gathered before the attack, enforcement when it comes, investigation afterwards, and a person accountable for the decision. Large enterprises spend years and considerable money assembling that from separate vendors. A hospital or a mid-sized manufacturer can now reach it without any of that.” 

— Mandar Patil, Executive Vice President, Cyble 

Reaching individuals 

The dimension with the least precedent is protection for named individuals — executives and directors, actors, musicians, sportspeople, creators, doctors, founders, and high-net-worth households. Cyble supplies the collection and analysis; DRONA operates it, and can extend cover from an organisation’s leadership team to a single person and their family. Public figures are treated first as victims of an offence; the reputational damage that follows is a consequence of the crime, not a separate exercise. 

 

What is watched. Criminal marketplaces and closed channels — Tor and I2P hidden services, invite-only forums, ransomware leak sites, Telegram, initial access broker listings, combolists and infostealer log repositories — for the individual’s credentials, identity documents, home address, family contact details and banking data. Open platforms — social networks, video and short-form feeds, app stores, and newly registered or lookalike domains — for impersonation accounts, fraudulent endorsements and fabricated statements. And synthetic likeness: manipulated or AI-generated audio and video using the person’s face or voice, together with the coordinated campaigns built around it — clusters of accounts pushing an identical claim, the amplification networks behind them, and the re-cut and translated versions that follow a first removal. 

 

When something is found, an analyst verifies it and the evidence is preserved before any removal is attempted — URLs, account metadata, timestamps, hashes and mirrors — because a successful takedown destroys the proof that will later be needed. Takedown requests are then filed with platforms, hosts, registrars and app stores, using the statutory windows the Government created in February 2026, which oblige platforms to act on lawful orders within three hours and within two for the most serious categories. Cyble Hawk investigates the infrastructure behind the campaign, which frequently reveals the same operation running the same template against many other people. Where a situation is live, DRONA’s forensics, incident response and negotiation teams take it on directly. And where exposure traces back to an infected personal device, the infection itself is dealt with, so the same credentials do not reappear in the next dump. 

 

Removal is not the end of the matter. A file can be taken down in three hours; what an audience has come to believe about it does not come down with it. Monitoring therefore continues after enforcement, tracking whether the same claim resurfaces under new accounts or in a new language. Where the individual has a communications, legal or management team, the partners work alongside them, supplying the verified account of what happened and the underlying evidence in a form that can be handed to a platform, a regulator, a court or a newsroom. The objective is a documented factual record, not a managed narrative. 

“Our customers do not call at convenient hours. When someone reaches us at two in the morning because a video of them is circulating, they do not want a dashboard. They want someone to tell them what has happened, get it down, find out who did it, and take responsibility for the decision. That is what changes — collection gathered globally, but worked and answered on Indian soil, by analysts the customer can name.” 

— Dhruv Pandit, Co-Founder & CEO, DRONA Cyber Solutions 

What Cyble contributes 

  • Cyble Vision, powered by Blaze AI, collects continuously across the criminal ecosystem and correlates findings against the customer’s own attack surface — domains, brands, executives, credentials and third-party estate — returning evidence and reasoning so an analyst can verify a conclusion rather than accept it. 
  • Cyble Hawk supports investigation and attribution to the standard required when a matter proceeds to law enforcement or a regulator. 
  • Cyble Titan provides AI-native endpoint security. Detection is behavioural, anchored to a hardware root of trust: boot chain and sensor integrity are verified against silicon-level measurements across Intel, AMD and ARM, so a tampered agent is identifiable rather than quietly relied upon. Autonomous actions are logged, attributable and reversible, with analyst approval required for consequential response. 

The organisational and personal halves are not separate propositions. The credentials taken from a director’s personal laptop are what open the company; the company’s leaked internal detail is what makes an attack on that director’s family convincing. Covering one and not the other leaves the door open at the hinge. 

“The intelligence a central bank relies on and the intelligence a mid-sized manufacturer in Coimbatore needs are not different intelligence. The adversaries overlap, the infrastructure overlaps, the stolen credentials sit in the same repositories. What has differed is who could afford to consume it. The same is true of a person — the monitoring that protects a listed company’s board is what a schoolteacher whose face has been stolen also needs.” 

— Mandar Patil, Executive Vice President, Cyble 

Proven at national scale 

The platforms being made available through this collaboration are the same ones Cyble operates for some of the most heavily targeted organisations in the world. Cyble’s customer base includes one of the world’s largest social media platforms; several of India’s largest private and public sector banks, and financial institutions across South Asia, the Middle East and North America; Big Four professional services firms; the majority of the world’s major global systems integrators; central banks and national financial regulators in multiple countries; national cybersecurity coordination bodies; defence and national security agencies; and law enforcement agencies internationally, where Cyble’s investigative capability has supported operations against dark web trafficking networks, fraud syndicates and ransomware infrastructure. 

 

Cyble has been recognised as a Challenger in the Gartner® Magic Quadrant™ for Cyber Threat Intelligence Products and Services, is cited in Forrester research, and is consistently rated among the leading vendors in its category on G2 and Gartner Peer Insights. 

 

Building the defenders India needs 

The collaboration also supports DRONA’s Cyber Yodha Campaign, a national initiative to establish 50 integrated Cybersecurity Command Centre labs and train more than 1,00,000 cyber defenders. Both companies work with a range of partners, industry bodies and government agencies across India, and intend to continue doing so; the agreement is not exclusive. 

“Trainees who only ever practise on simulations are unprepared the first time something real happens. Here they work live collection and live incidents inside an operating command centre. That is what closes the country’s skills gap — not certificates, but analysts who have already seen an incident through to the end.” 

— Dhruv Pandit, Co-Founder & CEO, DRONA Cyber Solutions 

The service is delivered from DRONA’s existing command and control centre in Ahmedabad, with capacity intended to serve customers nationally and, in time, internationally. 

About Cyble

Cyble is a global, AI-native cybersecurity company specializing in threat intelligence, digital risk protection, and dark web monitoring. Its flagship platform, Cyble Vision, powered by Blaze AI, delivers rapid threat detection, automated analysis, and contextual insights into ransomware, phishing, and fraud. Cyble Titan extends this with AI-native endpoint security, combining silicon-rooted attestation, agentic EDR, and autonomous, auditable response for the AI era. Together, these platforms help enterprises and governments identify risks faster, cut through alert noise, and respond with precision. Real-time alerts and automation strengthen cyber resilience, enabling proactive defense worldwide. www.cyble.com

 

Media Contacts:
[email protected]
+1 678 379 3241

About DRONA Cyber Solutions

DRONA Cyber Solutions Pvt. Ltd. is an Ahmedabad-headquartered cybersecurity company operating under the mission Securing Bharat, Building the World, offering SOC-as-a-Service, digital forensics, incident response, ransomware negotiation, malware analysis, dark web monitoring, OT security, compliance audit, data recovery and corporate cybersecurity training. DRONA leads the Cyber Yodha Campaign, a national initiative to establish 50 integrated Cybersecurity Command Centre labs and train more than 1,00,000 cyber defenders. www.dronacybersolutions.com
Scroll to Top

Book your session

Request a Personalized Demo

See how Cyble's threat intelligence protects your organization. A specialist will reach out within one business day.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams

Download the brochure

Get the Cyble Vision Brochure

Explore how Cyble Vision delivers AI-powered threat intelligence across your attack surface. Fill in your details to access the brochure.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams