
Featured story
Cover Story
BUILDING TRUST IN THE AGE OF AI: WHY ROLE OF OEMS MATTER
Artificial intelligence (AI) has become both the engine of innovation and a powerful tool for cybercriminals. From deepfakes and synthetic identities to autonomous AI-powered attacks, the same technologies transforming businesses are also creating unprecedented risks. As digital trust becomes a competitive differentiator, securing AI is no longer optional. As AI becomes more widely used across businesses, organisations are focusing on a simple question: can they trust the data that their operations, decisions and AI systems depend on? As organisations move AI from experimentation into critical business processes, the quality, integrity, provenance, security, and governance of data become fundamental to business outcomes. AI can generate powerful insights and automate complex decisions, but its effectiveness ultimately depends on the integrity of the data behind it. Organisations therefore need to look beyond simply securing data to establishing its provenance, accuracy, authenticity, and governance—ensuring that the data powering both business decisions and AI systems remains trustworthy throughout its lifecycle. ROLE OF OEMS AS GUARDIANS OF TRUST OEMs sit at a critical point in this ecosystem, with the ability to embed security, privacy, authenticity, and resilience into the technologies that businesses and consumers increasingly depend on. Their role is therefore evolving—from technology manufacturers to architects of trust. They therefore, now have to play a pivotal and a meaningful role - Security by design: OEMs have a pivotal role in embedding security, privacy, and responsible AI principles into products and platforms from the outset, rather than treating them as add-ons. Authenticity and integrity: As AI makes it easier to generate deepfakes, synthetic content, and sophisticated cyberattacks, OEMs can help establish mechanisms to verify the authenticity of devices, software, data, and digital identities. Securing the AI lifecycle: Trust must extend across the entire AI stack—from chips and infrastructure to models, applications, endpoints, and cloud environments. OEMs are uniquely positioned to strengthen security across these layers. Transparency and accountability: Customers increasingly want to know how AI systems use data, make decisions, and manage risk. OEMs can build greater transparency, explainability, and accountability into their technology ecosystems. Privacy and data sovereignty: With regulations evolving globally, OEMs must help organizations maintain control over sensitive data while ensuring that AI systems comply with local requirements. Supply-chain resilience: The growing complexity of technology supply chains makes hardware, firmware, software, and third-party components potential attack vectors. OEMs can play a crucial role in ensuring the integrity and security of the technology supply chain. The core idea is that OEMs are no longer just technology providers; they are becoming critical custodians of trust in an AI-driven ecosystem. The future belongs to technology leaders who can deliver responsible AI while protecting customers from rapidly evolving AI-driven threats. --------------------------------------------------------------------------------------------------------------------------------------- TURNING RESPONSIBLE AI INTO THE NEXT LINE OF DEFENSE Sujit Shetty Channel Director – Indian Subcontinent, Alcatel-Lucent Enterprise AI security cannot be an afterthought. At Alcatel-Lucent, we embed security, privacy and responsible AI principles across the architecture and lifecycle of our AI-enabled solutions. We apply AI where it delivers measurable business and operational value while maintaining strong controls around data, identity, access and infrastructure. Our generative AI capabilities, including ALIE chatbot powered by our PythiALE engine, are designed for controlled enterprise environments with encryption, least-privilege access and data protection, while taking into account GDPR and EU AI Act considerations. Deepfakes and synthetic identities are challenges to trust. Securing AI therefore means securing the entire ecosystem around it - people, devices and data - through network visibility, behavioral analytics and Zero Trust principles. AI should not only be protected from attacks; AI should become part of the defense mechanism. INVESTING IN NEXT FRONTIERS OF SECURITY We see sovereignty and security as increasingly interconnected with the adoption of AI. Our approach to Sovereign AI is broader than simply hosting an AI model locally. It is about creating the secure digital infrastructure, connectivity, cloud environment and governance required for organizations to adopt AI while maintaining control of data and operations. Zero Trust and privacy are equally important. Intelligent, continuously monitored networks with behavioral analytics, segmentation, identity- aware access and proactive threat detection will be essential to securing AI-driven environments. Finally, we view post-quantum security as an important long-term priority. We are focused on building secure, standards-based, and upgradeable infrastructure that enables customers to adapt their security architecture as quantum threats and cryptographic standards evolve. ----------------------------------------------------------------------------------------------------------------------------------------- TRANSFORMING AI FROM AN ATTACK SURFACE INTO A DEFENSE LAYER Aditya Khemka Managing Director CP PLUS As AI becomes increasingly capable, the security challenge is no longer limited to protecting systems from conventional attacks. The industry must also address manipulated identities, deepfakes, adversarial inputs and increasingly autonomous cyber threats. At CP PLUS, our approach is to build security into the architecture of our AI-enabled surveillance ecosystem rather than treating it as an additional layer. Our AI solutions are designed around trusted hardware, secure device architectures and controlled data flows. CP PLUS Trusted Core (CTC) Technology strengthens the device foundation through mechanisms such as secure boot, hardware-level protection and encryption, helping establish confidence that the device and its firmware have not been compromised. We are also strengthening our capabilities in AI-driven video analytics, intelligent detection and authentication while focusing on the provenance and integrity of data feeding these systems. AI AS THE NEW FRONTLINE OF CYBER DEFENSE The differentiation for CP PLUS when it comes to AI strategy will not come from adding AI as a feature, but from creating an integrated ecosystem where AI, hardware, cybersecurity, cloud and surveillance work together reliably at scale. Through CP PLUS.AI and our expanding portfolio of AI-enabled cameras and solutions, we are bringing intelligence closer to the edge and enabling faster detection, smarter analytics and more efficient security operations while reducing unnecessary movement of data. Our approach to compliance is not to view regulation as a constraint on innovation, but as an essential design parameter. We are investing in secure-by- design engineering, responsible data practices and stronger technology governance so that innovation remains accountable. ------------------------------------------------------------------------------------------------------------------------------------------- MOVING BEYOND DETECTIONS TO CONTINUOUS VERIFICATION IS THE NEW SECURITY NORM Huzefa Motiwala Senior Director, Technical Solutions, India and SAARC, Palo Alto Networks Palo Alto Networks is securing against threats like deepfakes and synthetic threats by protecting the AI ecosystem at multiple layers. Prisma AIRS provides visibility and runtime controls across AI applications, models, data and agents, including defenses against prompt injection, data leakage, identity impersonation and unsafe tool use. For autonomous threats, we treat AI agents as privileged identities: they need verified identities, tightly scoped permissions, continuous monitoring and the ability to stop unauthorized actions in real time. Our Unit 42 research shows why this matters. AI can compress attack timelines dramatically, while enabling highly convincing deepfakes and autonomous, multi-step attacks. Our approach is therefore not simply to detect malicious content, but to continuously verify identity, behavior, access and intent across the AI environment. REDEFINING SECURITY THROUGH ZERO TRUST, PRIVACY AND QUANTUM READINESS Palo Alto Networks is investing in Zero Trust by treating every user, device, workload and AI agent as an identity that must be continuously verified and granted only the access it needs. This is especially important as autonomous agents gain the ability to access data and systems on behalf of users. On privacy, the focus is on securing data wherever it moves and is processed, with visibility and controls designed to prevent sensitive information from being exposed through cloud, AI and network environments. Post-quantum security is also becoming a practical priority. We have introduced PQC capabilities across our Next Gen Firewall, Prisma Access and Prisma SD- WAN, including hybrid encryption and PQC- aware TLS inspection. This helps organizations prepare for “harvest now, decrypt later” attacks while maintaining visibility into encrypted traffic. ----------------------------------------------------------------------------------------------------------------------------------------------- PRIVACY IS NOW A CORE PILLAR OF CYBERSECURITY Bikramdeep Singh Vice President of India & SAARC Proofpoint AI is supercharging threats we have been dealing with for years—making phishing, impersonation, social engineering and other attacks faster, more convincing and easier to scale. At the same time, autonomous AI agents can now reason, plan and act across enterprise systems on behalf of users. Proofpoint’s 2026 AI and Human Risk Landscape report shows how quickly this is happening in India: 94% of organisations have deployed AI assistants beyond the pilot stage, while 88% are piloting or rolling out autonomous agents. Yet 63% report having experienced a suspicious or confirmed AI- related incident, and 26% are not fully confident their existing controls would detect a compromised AI. Proofpoint continuously evaluates whether a human or an AI agent's behaviour aligns with the original request, policy and intended purpose, including across multi-step agent workflows. FUTURE-PROOFING SECURITY Proofpoint is investing in a unified approach to data security that helps organisations discover and classify sensitive data, prevent its loss, and detect risky behaviour by careless, compromised or malicious users. India is an important part of this global shift. The country is simultaneously experiencing rapid AI adoption, a fast- growing digital economy and an evolving data protection environment through the Digital Personal Data Protection Act. We are investing in India accordingly. Proofpoint has had a local data centre supporting Indian customers since Q3 2025, helping address data residency and sovereignty requirements. We also just announced the expansion of our engineering presence in Hyderabad with a new AI Security Engineering Centre of Excellence, alongside our existing Pune capabilities. ----------------------------------------------------------------------------------------------------------------------------------------------- FROM DATA SECURITY TO DATA TRUST Himanshu Kathpal VP, Product Management, Platform and Technologies, Qualys Our approach when it comes to securing our products against deepfakes, synthetic identities, and autonomous cyber threats combines identity security, continuous monitoring, threat intelligence, and behavior-based detection with automated response. We are extending identity risk coverage beyond human users to non-human and AI identities — service accounts, API keys, and autonomous agents - since these are increasingly the vector for synthetic-identity and impersonation attacks. Our agentic AI capabilities apply this same automation to defense - continuously validating exposures, prioritizing real risk over noise, and triggering remediation with minimal manual intervention. As autonomous threats grow more sophisticated, we are focused on improving anomaly detection and attack-pattern recognition across the environment, while keeping human oversight in the loop for high-risk decisions. The goal is to match the speed of AI-driven attacks with equally autonomous, intelligence-led defense. INVESTING IN ZERO TRUST, PRIVACY & POST-QUANTUM SECURITY Zero Trust underpins our security architecture, with ongoing investment in identity-centric controls — privileged access, continuous verification, and non-human identity governance — alongside network security. We are extending role-based access control and identity risk management across both human and machine identities as environments grow more agentic and interconnected. On post-quantum readiness, we are strengthening our PKI and certificate lifecycle management with a focus on cryptographic agility, so our internal and external certificate infrastructure can transition to post-quantum algorithms as standards mature. This lets customers move to stronger cryptography without disruption, while continuing to protect sensitive data and privacy throughout the shift. ------------------------------------------------------------------------------------------------------------------------------------------ BALANCING AI INNOVATION WITH TRUST AND COMPLIANCE Deepak Puligadda Global CTO Redington Limited We have come to realize lately that the same technologies that champion innovation are also being weaponized against the systems that use them. We believe that security has to be built into every product, platform, and process from the start. Internally, we follow a Zero trust security model, embedding AI into our own security operations - from identity verification and behavioral analytics that help detect deepfakes and synthetic identities, to AI-driven threat detection that responds at machine speed. When attacks become autonomous, defense has to become autonomous too. As a technology orchestrator, we work closely with OEMs and cybersecurity innovators to ensure the solutions we take to market are secure by design. Through platforms like the CloudQuarks and Redington AI Exchange, we curate and validate AI solutions before they reach partners and customers, so that trust travels with technology. TRUST & COMPLIANCE ARE THE STRATEGY Our AI strategy is built on a simple belief: the real challenge today is not access to AI, but adoption with confidence. That is what differentiates Redington. This plays out in two ways. Horizontally, we are infusing AI into our own core processes - credit, presales, sales, and our digital platforms - with equal investment in security and governance, so we use AI responsibly ourselves before asking customers to. Vertically, through the Redington AI Exchange, our AI Centres of Excellence, and CloudQuarks, we enable partners to discover, validate, and deploy AI solutions that are secure and compliant by design. Trust and compliance are not constraints on this strategy; they are the strategy. ----------------------------------------------------------------------------------------------------------------------------------------- SECURING CONNECTIVITY WITHOUT COMPROMISING INNOVATION Dipesh Kaura Country Director, India and SAARC Securonix Physical AI, including robots, industrial cobots, and autonomous systems, is expanding the attack surface across both digital and physical environments. Traditional security architectures were not designed to protect machine identities, automated decisions, and AI-powered workflows at this scale. Cyber resilience now requires security operations that can detect, investigate, and respond across this broader threat landscape while maintaining governance, accountability, and human oversight. Securonix Unified Defense SIEM provides the operating foundation for the modern SOC. The cloud-native platform brings together detection, investigation, and response through Agentic AI, with Sam, the AI SOC Analyst, performing Tier 1 and Tier 2 work across triage, investigation, and response. Sam operates within the Agentic Mesh, which coordinates specialized agents across the threat lifecycle. Every action is policy-bound, auditable, explainable, and subject to human oversight. Built on an open architecture, Securonix integrates with existing tools and data sources, adapts to each customer’s threat landscape, and supports flexible deployment at scale. Organizations can reduce response times, cut through noise, improve SOC efficiency, and demonstrate measurable cyber resilience to the board. BALANCING SECURITY, GOVERNANCE AND INNOVATION Governance must move past manual controls and become part of every stage of the security lifecycle. Securonix Agentic Mesh provides that governance layer by ensuring actions remain controlled, auditable, explainable, and aligned with defined policies. Within this framework, Sam, the AI SOC Analyst, performs investigative work with built-in guardrails, transparent reporting, and human oversight across every workflow. Organizations can track completed work in real time, understand how decisions are made, and measure productivity against defined analyst outcomes. --------------------------------------------------------------------------------------------------------------------------------------------- BUILDING RESILIENCE FOR AN EVOLVING DIGITAL WORLD Justin Henkel Chief Information Security Officer SolarWinds As identity becomes the primary attack surface, we focus on continuous verification, controlled access, and full auditability rather than assuming AI can operate autonomously without oversight. To stop automated attacks from sneaking malicious code into updates, our Next-Gen Build System compiles software in isolated, temporary environments simultaneously. If the outputs don't match the exact cryptographic signature, the build halts instantly. We block synthetic identity fraud through a Zero Trust architecture, strict access controls, and hardware-based MFA. AI can guide, recommend, and prepare actions, but effective remediation still requires human oversight and decision-making. Human oversight takes time, while threat actors are increasingly using AI to automate attacks, enabling them to move faster and adapt in real time. No organization is completely immune from attack. What separates resilient organizations from vulnerable ones isn't whether they get hit. Trust in these systems has to be earned incrementally, through consistent, observable behavior over time, not assumed upfront. PREPARING TODAY FOR TOMORROW’S SECURITY CHALLENGES From a Zero Trust and privacy perspective, organizations need to be continuously challenging their assumptions. That means clear access controls, appropriate data protection, regular auditing, and understanding where sensitive information is being used and stored. These cannot be treated as ‘set and forget’ measures. The same thinking applies to quantum readiness. We may not know the exact timeframe for when quantum computers will become powerful enough to overcome today’s widely used public-key encryption, but the preparation cannot wait until that point. The objective is not simply to prepare for one technology shift, but to build the operational resilience to adapt as the technology and threat landscape evolve. -------------------------------------------------------------------------------------------------------------------------------------------- RETHINKING IDENTITY SECURITY IN THE AGE OF AI Aaron Bugal Field CISO, APJ Sophos Deepfakes and synthetic identities are getting a lot of attention, but the real challenge is trust. Organisations need visibility into human and non-human identities, continuous assessment of their risk, and controls that reduce the blast radius if an identity is compromised. If something malicious happens, the goal is to ensure it can't move freely through the environment and cause broader damage. PREPARING TODAY FOR TOMORROW’S SECURITY CHALLENGES As organisations manage growing numbers of human and non-human identities, continuous verification and visibility become increasingly important to reducing cyber risk. Strong governance, oversight, and accountability are also essential to ensuring data is handled securely and responsibly. From a post-quantum perspective, the focus has shifted from whether organisations should prepare to when. Government agencies and industry bodies are already recommending that organisations begin planning their transition to quantum-resistant cryptography. Sophos is actively preparing for that transition. We already provide visibility and control over post-quantum cryptographic traffic, track emerging NIST standards, and are undertaking a broader program to migrate cryptographic dependencies across products and services toward quantum-safe standards. Organisations should be inventorying their cryptographic use today and developing migration plans now, rather than waiting for quantum computing to become a mainstream reality. ------------------------------------------------------------------------------------------------------------------------------------- KEEPING INNOVATION AHEAD OF AN EXPANDING THREAT LANDSCAPE Selvakumar Natesan Technical Partner and Director Thoughtworks Physical AI and autonomous agents fundamentally change the way enterprises need to think about cyber resilience. Security can no longer sit around applications but must be engineered into the architecture from the outset. Many enterprises still rely on architectures designed for predictable, human-driven workflows. AI-powered environments are dynamic, distributed and constantly evolving, requiring platforms that can detect, respond and recover without disrupting business operations. At Thoughtworks, we believe cyber resilience must become a core engineering capability. Organisations that embed security, resilience and responsible AI practices into modern digital platforms will be far better equipped to innovate confidently as Physical AI becomes mainstream. As AI systems begin making decisions, interacting with connected devices and operating with increasing autonomy, organisations need continuous verification of identities, data, models and system behaviour. This calls for a zero-trust approach, real-time observability, secure software supply chains and resilience that is built into every stage of software development. Along with these techniques, teams need to have the processes and runbooks established and practiced for patching production systems swiftly before they can be exploited when new security vulnerabilities are identified. BALANCING SECURITY, GOVERNANCE AND INNOVATION As AI, connected devices and edge computing expand the attack surface, organisations need governance that is automated, continuous and embedded into engineering workflows rather than applied through periodic reviews. We are seeing increasing adoption of policy-as-code, automated compliance, DevSecOps, software supply chain security and AI governance frameworks that enable continuous risk management. And the new channels for accessing the system demand the security control measures applied at the right layer in the architecture, rather than Perimeter-based security. ------------------------------------------------------------------------------------------------------------------------------------------- BEYOND DATA SECURITY: BUILDING LONG-TERM TRUST Sharda Tickoo Country Manager for India and SAARC TrendAI AI has fundamentally changed the threat landscape, so our approach is to use AI to defend against AI. Through Trend Vision One™, we provide unified visibility across endpoints, cloud, email, networks, identities, and AI systems, enabling organizations to detect and respond to emerging threats before they become business risks. TrendAI has introduced advanced deepfake detection capabilities that go beyond traditional image analysis by incorporating behavioural indicators to identify AI-generated fraud and impersonation attempts. To address synthetic identities and autonomous attacks, we combine AI-powered threat intelligence, risk-based analytics, XDR, and continuous attack surface management to identify anomalous behaviour, privilege misuse, and adversary activity at speed. The objective is to empower organizations with a unified visibility, context basis prioritized threats, and intelligence needed to establish trust in an environment where digital deception is becoming harder to detect. FUTURE-PROOFING SECURITY Our investment strategy is centered on building cyber resilience for the AI era. We continue to expand Trend Vision One™ with Zero Trust Secure Access capabilities that continuously verify users, devices, applications, and AI interactions, enabling least-privilege access and real-time risk-based decision-making. On privacy, we are focused on securing data wherever it resides, helping customers gain visibility into sensitive information, prevent data leakage, and govern AI usage responsibly. At the same time, we are investing in AI security, cyber risk exposure management, and platform consolidation to eliminate operational blind spots and strengthen trust across digital ecosystems. As quantum computing advances, we are actively monitoring and preparing for post-quantum security requirements through our research-led approach to future cryptographic risks. ------------------------------------------------------------------------------------------------------------------------------------------- SECURING DATA TODAY, TRUSTING IT TOMORROW Sandeep Bhambure Managing Director and Vice President – India and SAARC, Veeam AI is making cyberattacks more convincing and easier to scale. Deepfakes, synthetic identities and AI-driven impersonation attacks are making it harder for people and organisations to know what information and interactions they can trust. For organisations, the challenge is not only preventing attacks, but is also understanding what data is being accessed, how it is being used, and how quickly they can recover if something goes wrong. The reality is that no organisation can assume it will stop every attack. EPL Limited, an Indian specialty packaging manufacturer, reported recovering from a cyberattack within four hours with no data loss. It is a reminder that resilience is not just about keeping threats out, but about being able to restore operations quickly when an incident occurs. BUILDING RESILIENCE WITH ZERO TRUST, PRIVACY, AND POST-QUANTUM SECURITY The common thread across all three areas - Zero Trust, privacy, and post-quantum security - is trust. With Zero Trust, the principle is straightforward: access should be continuously verified rather than automatically assumed. As organisations become more distributed and data moves across multiple environments, that approach becomes increasingly important. On privacy, organisations are under growing pressure to understand where sensitive data resides, who has access to it and how it is being used. Those challenges become even more important as AI is adopted across everyday business processes. Post-quantum security is about looking beyond today's threat landscape and thinking about the long-term protection of data. One of the concerns organisations are increasingly discussing is the possibility that data stolen today could be stored by an attacker and decrypted years later as computing capabilities advance. ------------------------------------------------------------------------------------------------------------------------------------------
Read full story











