Knowledge Hub / Rohan Desai

Analyst Spotlight

Rohan Desai

Security Engineer

Tenable

Analyst Spotlight

Securing an AI-Powered Business: What India's Enterprises Need to Get Right

The cybersecurity landscape is changing: the attacker behind the screen is often not a human anymore; it’s an AI agent. Businesses are noticing this shift and are pouring money into cybersecurity, with India’s cybersecurity spending projected to reach US$4.4 billion by 2026. Cybersecurity is evolving and growing, but not necessarily at the speed of AI. Security strategies must now be built for a new reality where non-human adversaries are becoming pervasive.

AI is becoming both an augmentative force and attack vector, often within the same organisation. Machine identities now outnumber human users in most enterprises, and many carry broader access than any employee. Through shadow AI, employees are introducing applications without IT oversight, creating blind spots for security teams still relying on pre-AI strategies. Adversaries are using AI just as extensively to spot infrastructure gaps, bypass controls and attack before anyone notices. Frontier models add extra muscle, making attacks harder to detect, easy to miss in the constant stream of security alerts, and exploiting weaknesses before security teams even know those exposures exist.

In India, where enterprises are racing to integrate the latest AI advancements, the security complexities just compound. Cyber defence has to fight fire with fire. Automated remediation was always treated as a forbidden fruit in cybersecurity. That reluctance doesn’t hold up anymore. Attackers operate at machine speed now and manual intervention alone will fall flat in front of sophisticated AI attacks.

AI-powered security built for this era should surface exposures continuously, weigh risk against real business and identity context, and fix vulnerabilities before anyone can exploit them. That becomes a real step up from the first generation of AI security tools, which were largely prompt-driven, reactive, and blind to context. Those tools waited for someone to ask the right question. Today’s world doesn’t have that luxury.

Indian enterprises are changing how they operate because of AI, and security has to become more preventive than reactive. There needs to be continuous visibility into both human and machine identities, real governance over sanctioned and unsanctioned AI, and the ability to respond as fast as the attacks themselves. Patching and periodic audits still matter, but they aren’t enough on their own anymore. Automated attacks need automated defence to match them.