
India recorded 265.52 million threat detections across 8 million endpoints in 2025, and the number keeps climbing despite increased security investments. At the same time, the level of expertise an attacker needs to run a sophisticated attack continues to fall. Advanced AI models allow attackers to scan an organisation’s entire footprint, surface gaps in real time, and generate an attack for each one – faster than most teams can respond.
For defenders, the challenge is clear: our current security approaches were not built for adversaries compounding their speed and scale this quickly. Gartner forecasts that Indian organisations will spend $3.4 billion on information security in 2026, up 11.7% from last year, as they respond to increasingly sophisticated AI driven threats. But if that spend doesn’t translate into an impactful strategy that actually keeps pace with attackers, organisations risk falling further behind while absorbing the consequences of breaches. Simply guarding the attack surface will not be enough. To close the gap, we have to go on the offence.
AI changes the defender’s playbook
Security professionals have a reflexive instinct to treat the release of powerful models as strictly bad news. But hand-wringing about the pace of AI capability gains won’t do anything for a security program.
Nearly all security defences started as tools built to exploit environments, and security teams repurposed them for defence. The logic that built most commercial security tools in use today applies here too, and defenders hold the same claim to advanced technology.
If attackers can now use AI to canvass an organisation’s assets and generate attacks against every gap, defenders need a mindset that drives them to canvass their own environment first, using the same technology. This instinct naturally comes from a professional background rather than a deliberate choice or method.
Different backgrounds, different security mindsets
CISOs gain their seat through several different paths. Some came from governance, risk, and compliance functions that already owned risk. Some came from IT, inheriting security along with the rest of the technology estate. Some came from security architecture, understanding how systems were actually built.
More recently, a growing number came from engineering. Each path shaped a different worldview.
Compliance and IT backgrounds tend to produce a defender mindset: wait for logging, monitoring, or an incident to show you where to invest. Engineering backgrounds, especially at software companies, tend to produce an attacker mindset, one that proactively searches for holes across the entire program the way an adversary would.
That’s the one we need right now.
Thinking like the adversary
Teams with an attacker mindset see themselves as building scalable solutions that automate outcomes for the business, while continuously discovering potential shortcomings in the program, the threat landscape, and the infrastructure and asset catalog.
That takes real curiosity. Understand how things are set up, why they’re set up that way, and what could go wrong. That’s the foundation of security research generally: an abundance of curiosity about how things work, how they’re supposed to behave, and how you can produce outcomes outside their intended use case.
The changes I have made with my own teams move us toward outcome-based, engineering-led functions. Each team supports automated agents that identify risk, triage it, remediate it, and report on it, aligned to a specific business outcome. Application security focuses on engineering enablement, building agents that handle tasks end-to-end across the software development lifecycle. Governance and risk become trust and business resilience, oriented around continuously proving the organisation is secure.
Building a lasting AI advantage
To make this work, focus on two practical steps. First, model neutrality. Build workflows that are not tied to one model or vendor, since the best models and AI tools today may not be right in six months. Model neutrality also means deployment neutrality, giving security teams the option to run models in air-gapped or self-hosted environments when data residency or IP protection demands it, not just the option to swap vendors.
Second, scope. Keep agentic tasks narrow and well defined. Give an agent a large, vague problem, and it performs well briefly, then loses the plot and starts generating whatever it thinks will satisfy the prompt. Give it a specific task and prioritise delivering the right context up front for it to succeed more consistently. That is how you orchestrate intelligent outcomes without sacrificing accuracy.
Not every program is ready to restructure around agents on day one, and that is fine. For a program earlier in this journey, the starting point does not need to be complicated: look at each area of focus, define the deterministic outcome you want from it, and work backward using the tools you already have, rather than assuming you need an entirely new stack.
It’s time for a new approach
The real danger right now is inaction. Every month the bar an attacker has to clear drops a little lower while the bar defenders have to clear climbs a little higher. We don’t have the luxury of waiting for an incident to show us where to invest, or for a vendor to ship a patch. Our security programs need to evolve with the threat if we’re to avoid falling victim to our adversaries’ reinvention.