When Indian regulators began demanding six-hour breach reporting in 2022, most companies scrambled to figure out what that even meant. Two years later, as data protection rules phase in and compliance costs mount, a Bengaluru-based startup thinks it's found the sweet spot: bundle the security monitoring, the regulatory paperwork, and the insurance policy into one platform—then charge for all three.
Mitigata, as the company calls itself, is hardly inventing this playbook. In the U.S., firms like Coalition and At-Bay have spent years fusing continuous scanning with underwriting, using real-time risk signals to adjust premiums and coverage on the fly. Coalition claimed north of 110,000 policyholders at a $5 billion valuation; At-Bay hit $1.35 billion in a 2021 Series D. The model works, or at least it has so far.
Now that convergence is arriving in India—a market research firm IMARC Group pegged at around $752.6 million this year, though precise sizing in this category tends to be squishy. What's less debatable: Indian regulators are tightening the screws, and most small and mid-sized enterprises lack the in-house teams to keep up.
A License, a Console, and 800 Clients
Mitigata holds an IRDAI direct broker license (No. 1013, valid through late 2027) and says it's serving over 800 clients, partnering with the usual roster of Indian insurers—HDFC ERGO, ICICI Lombard, TATA AIG, Bajaj Allianz. On the security side, it's weaving in tooling from CrowdStrike, Netskope, Splunk, and Okta.
The company was founded in 2021 by Mohit Anand (CEO), Sarthak Dubey (COO), Mayank Morya (CTO), and Akshit Kaushik (CBO). Last August, it closed a $5.9 million Series A led by Nexus Venture Partners, with Titan Capital and WEH Ventures joining in. Earlier seed rounds brought in roughly another million, putting total confirmed capital at approximately $7.08 million.
Its core product, the Mitigata Console, bundles dark web monitoring, security findings dashboards, phishing risk assessments, and insurance claims management. A separate offering, the Gordon Console, is explicitly tailored to Indian compliance frameworks: the Reserve Bank's cyber resilience rules, SEBI guidelines, the Digital Personal Data Protection Act. Services extend into managed detection and response, digital forensics, and certifications for GDPR, HIPAA, PCI DSS, SOC 2—the alphabet soup of regulatory acronyms that keeps compliance officers employed.
Regulation as Catalyst

India's cybersecurity landscape shifted meaningfully when CERT-In rolled out its six-hour breach reporting mandate in 2022, alongside 180-day log retention for virtually every entity doing business online. The Digital Personal Data Protection Act followed in 2023, with rules phasing in starting last November. Together, these create a dual pressure: disclose incidents fast, handle personal data meticulously, and document everything in between.
That's the wedge Mitigata is betting on. In markets where regulation lags, cyber insurance remains a nice-to-have. Where it's mandated or culturally embedded—think financial services in the U.S., or increasingly India's banking sector—demand follows.
Safe Security, another Indian startup focused on cyber risk quantification, pulled in $50 million in July 2025, a signal that investors see opportunity in India-focused risk platforms. Mitigata's partnerships with Scrut Automation, a compliance automation platform that itself raised $10 million in April 2024, suggest it's building an ecosystem rather than trying to own every layer of the stack alone.
The Numbers, Such As They Are
Employee counts are always tricky with startups. Third-party trackers have Mitigata at anywhere from 33 to 65 people, depending on when you check and who's counting. The company has been hiring—recent job postings include a Head of Digital Forensics and Incident Response—and it opened a new Bengaluru office. LinkedIn shows over 32,000 followers as of the latest data, though that metric measures interest more than headcount.
Mitigata lists offices in Bengaluru's Bellandur area, Mumbai's Bandra Kurla Complex, and Gurugram outside Delhi. Marketing materials claim "500+ global partners," "10K+ protected businesses," and presence in "50+ countries," but those figures are self-reported, undated, and impossible to verify independently. Take them as aspirational rather than audited.
Can It Scale?

The global cyber insurance market is entering what some brokers are calling a "normalization" phase. After years of spiking premiums and shrinking capacity—insurers got burned badly by ransomware payouts—pricing began to ease in late 2025 and into this year, according to outlooks from Munich Re, Gallagher, and CRC. That could create more room for bundled offerings targeting mid-market buyers who can't afford bespoke security operations centers but need more than off-the-shelf antivirus.
For Mitigata, the test is execution. Can it scale a brokerage in a market still learning to buy cyber insurance, while also delivering credible managed security and compliance automation? The U.S. comparables are well-capitalized and years ahead. The regulatory tailwinds in India are real, and the Series A provides some runway.
Whether that's enough to build sustainable differentiation in a space where every quarter brings new funded competitors and shifting insurer appetites—well, that's the bet Nexus and its co-investors just made. The answer will come not in pitch decks but in renewal rates, claims payouts, and whether Indian SMEs actually start treating cybersecurity as infrastructure rather than overhead.
For now, Mitigata is placing itself at the intersection of two things enterprises hate spending money on until it's too late: insurance and compliance. The irony, perhaps, is that the very regulations forcing companies to pay attention are also creating the market for platforms like this. Whether "full-stack cyber resilience" becomes a category or just another piece of vendor jargon is still anybody's guess.
