India’s enterprise security priorities have quietly but decisively shifted. For years, cloud misconfigurations and network intrusions dominated CISOs’ anxiety; today, Generative AI and Shadow AI top the list, according to the CISO Forum Survey 2026. Employees are pasting sensitive data into unsanctioned chatbots, building AI-driven workflows outside IT’s visibility, and unknowingly expanding the attack surface faster than security teams can map it.
In this wide-ranging conversation, Rajnish Gupta, MD & Country Manager at Tenable India, unpacks what this shift means in practice from the “entitlement debt” quietly accumulating across Indian enterprises’ identity systems, to why exposure management, not tool accumulation, is becoming the default operating model for CISOs juggling banking cores, manufacturing plants, and cloud-native business units simultaneously.
Gupta also addresses the harder, less technical questions: how to bring OT teams into a security program without breaking their trust, how DPDP Act compliance demands technical proof rather than paperwork, and why India’s talent shortage means automation must multiply human judgment rather than replace it. He closes with a candid diagnosis of where CISO influence still falls short and what needs to change structurally, not technologically, for security to shape business decisions before risk is inherited rather than after.

MD & Country Manager
Tenable India
CISO Forum: The CISO Forum Survey 2026 shows Generative AI and Shadow AI have overtaken cloud and network threats as the #1 CISO concern in India. How are you seeing this play out in Indian enterprises — and do most organisations yet recognise that AI is an active threat vector inside their own environments, not just an external risk?
Rajnish Gupta: Generative AI tools land on endpoints before security teams even know they exist. Employees connect to external AI platforms, paste sensitive data into chatbots, and build shadow workflows that bypass every data loss prevention control the organisation spent years building. This is Shadow AI, and it operates entirely below the visibility threshold of traditional security tools.
Attackers use AI to compress the time between vulnerability discovery and active exploitation, with a 49% year-over-year surge in active ransomware and extortion groups. These are operators who reuse leaked tooling, follow established playbooks, and now tap AI to automate reconnaissance, targeting, and execution. The barriers to entry have effectively collapsed.
At the same time, Tenable telemetry detected 457 million AI-related security issues across customer environments in a single 30-day period, averaging roughly 62,000 exposures per organisation. These are not theoretical risks. They are active misconfigurations, exposed credentials, and unsanctioned AI integrations that attackers can exploit today. The truth is that most Indian enterprises have not yet made that cognitive leap from treating AI as a productivity tool to treating it as an attack surface that requires the same rigour as cloud or network infrastructure.
CISOs who get this right are not waiting for their AI governance policy to mature. They are deploying continuous AI exposure management to discover and assess what AI tools employees actually use, map the attack paths those tools create, and act before adversaries do.
CISO Forum: Identity-centric breaches are rated severe by 68% of respondents, yet identity lifecycle governance — entitlement hygiene, lifecycle automation, and continuous access evaluation — remains among the weakest operational capabilities. What is the most dangerous identity gap you see in Indian enterprises today, and what does it actually take to move beyond IAM tooling to genuine identity-first security?
Rajnish Gupta: The most dangerous gap is not a missing tool. It is accumulated entitlement debt. Indian enterprises run complex, multi-cloud environments with identity sprawl across on-premises Active Directory, cloud directories and SaaS platforms. Adding to this is the increasing use of AI agents that hold credentials and act on behalf of users. Somewhere in that sprawl, thousands of accounts retain permissions they no longer need, service accounts operate with near-admin privileges granted during a project sprint years ago, and orphaned identities persist long after employees have left.
The Tenable 2026 Cloud and AI Security Risk Report highlights how deeply this problem runs in cloud environments. Excessive permissions are the norm. When an attacker compromises any one of those over-permissioned identities, the blast radius extends far beyond the initial breach point. The identity becomes the vehicle for lateral movement.
Moving beyond Identity and Access Management (IAM) tooling requires a shift in how CISOs frame the problem. IAM tools provision and authenticate. Identity-first security continuously evaluates whether the existing access should continue. That means entitlement hygiene at scale, automated lifecycle governance that revokes access when context changes, and real-time detection when legitimate credentials behave anomalously.
For Indian enterprises specifically, the challenge is organisational as much as technical. Identity governance programs tend to stall because they require cooperation across HR, IT, application owners, and the business. CISOs who succeed treat identity as a risk management function, not an IT provisioning function. They build the business case around breach scenarios, not compliance checklists, and they use continuous exposure mapping to show exactly which identity paths connect to crown-jewel systems.
CISO Forum: Indian CISOs are clearly moving away from tool accumulation toward architectural coherence. For a CISO in a large bank or diversified conglomerate managing multiple verticals and cloud environments, what is the practical argument for consolidating on an exposure management platform rather than maintaining specialised best-of-breed tools across each domain?
Rajnish Gupta: The practical argument comes from a single question: does your team know the top five attack paths an attacker would most likely use right now to reach your organisation’s most critical systems? In a best-of-breed tool environment, the answer is almost always no. Each tool generates its own findings. Vulnerability scanners report CVEs. Cloud security tools flag misconfigurations. Identity tools surface excessive permissions. No single team sees how those findings connect to create an exploitable attack path.
Tenable research shows that on average, an organisation faces three attack paths for every single security finding. If your environment contains 50,000 findings, attackers have access to roughly 150,000 potential routes to breach. The tools that generated those findings cannot tell you which paths lead directly to your banking core systems, your customer data repositories, or your trading infrastructure. That context gap is where attackers operate.
An exposure management platform changes the operating model. It delivers unified visibility through continuous asset discovery across the entire hybrid attack surface, capturing vulnerabilities, misconfigurations, excessive permissions, and exposed secrets in one view. It maps how isolated findings interconnect to form dangerous, exploitable attack paths. And it applies AI-powered prioritisation to identify which paths your team must break first to protect the assets that matter most.
For a CISO managing manufacturing plants, financial services subsidiaries, and cloud-native business units simultaneously, that contextual intelligence is the difference between reactive firefighting and proactive risk management. The consolidation argument is not about vendor count. It is about whether your security program can answer the question every board member and regulator will eventually ask: which exposures, if exploited, would cause the most damage, and what is your team doing about them right now?
CISO Forum: Tenable One AI Exposure was built to close the visibility gap as AI agents, shadow AI, and enterprise AI platforms proliferate. Yet 18% of Indian organisations have no formal AI security process. At what maturity level does an organisation need continuous AI exposure management rather than policy-based controls—and what should a CISO do in the next 90 days if they have neither?
Rajnish Gupta: Policy-based controls work when you know what you are governing. The problem with AI adoption in Indian enterprises is that the inventory itself is unknown. Employees deploy AI tools, connect AI agents to internal systems, and build automated workflows without informing security teams. A policy that says ‘employees must seek approval before using AI tools’ does nothing for the tools that are already running.
That is why continuous AI exposure management is not a maturity-gate question. It is relevant from day one of any serious AI adoption curve, and India’s enterprise AI adoption curve is steep. You need to discover what AI assets exist before you can govern them. Waiting until you have a mature AI security program to start discovering your AI attack surface is the wrong sequence. Discovery drives governance, not the other way around.
For a CISO without a formal AI security process or continuous monitoring, the 90-day playbook is straightforward. In the first 30 days, deploy asset discovery that surfaces AI tools, agents, and integrations operating across your environment. Treat this as an inventory exercise. You cannot manage what you cannot see. In the next 30 days, use that inventory to classify AI assets by risk, identify which ones connect to sensitive data or critical systems, and establish a baseline of exposures. In the final 30 days, build the remediation workflow. Prioritise by attack path, not by finding count, and automate the fixes where guardrails allow.
Tenable One AI Exposure operationalises this sequence. It detects shadow AI alongside sanctioned platforms, maps how AI infrastructure connects to the broader attack surface, and provides the continuous visibility that policy documents alone cannot deliver.
CISO Forum: Manufacturing and BFSI together represent over half of our survey respondents, and OT/IoT integration remains a structurally risky domain in both sectors. With Tenable’s new VM-Native OT Discovery now embedded in Tenable One, what is the realistic starting point for a CISO trying to bring OT into their security program — and how do you address the organisational challenge, not just the technical one?
Rajnish Gupta: The realistic starting point for OT security is not a technology deployment. It is a conversation between the CISO and the plant manager, or the head of operations, or whoever owns the production floor. In most Indian manufacturing organisations and banks with physical infrastructure, OT systems have operated for years without IT security involvement. The engineers who run those systems have legitimate concerns about availability. An IT security scan that disrupts a production line or a SWIFT messaging system is not acceptable, and OT teams will resist any security program that threatens uptime.
CISOs who successfully bring OT into their security program do so by earning OT team trust before deploying any technology. That means sitting in the same room, understanding the operational priorities, and committing to a non-disruptive approach. VM-Native OT Discovery within Tenable One uses passive network monitoring to discover OT and IoT assets without sending active probes into fragile industrial systems. That is a credible starting position for an OT team that is sceptical about IT security involvement.
The organisational argument builds from there. When you give an OT team a complete, accurate inventory of every device on their network, including assets they did not know existed, you deliver value without disrupting anything. When you map how an IT vulnerability in a connected workstation creates an attack path into the operational technology network, you make the business case for joint accountability. Exposure management bridges the IT/OT divide by showing both teams the same risk picture in a shared language.
For Indian manufacturers facing Industry 4.0 integration pressures and BFSI institutions managing ATM networks and branch infrastructure, that unified visibility is the foundation of a credible OT security program. The technology is available. The harder work is building the governance model that makes IT and OT teams co-owners of cyber risk rather than adversaries in a budget dispute.
CISO Forum: DPDP Act enforcement is the highest-impact regulatory factor in our survey, with 60% of respondents citing it as high or extreme impact. But our data shows documentation readiness is outpacing technical readiness. How does continuous exposure management help Indian CISOs build genuine defensibility for DPDP compliance—and where does Tenable’s platform directly support it?
Rajnish Gupta: The DPDP Act poses a specific challenge for CISOs, as it requires organisations to demonstrate that personal data is subject to appropriate technical and organisational protection. Documentation that says the right things satisfies a regulator’s first question. A breach that exposes personal data raises a second question that the documentation cannot answer: whether the controls actually worked.
Technical readiness for DPDP compliance requires knowing where personal data lives, which systems process it, who has access to it, and what vulnerabilities or misconfigurations could expose it to unauthorised access. Most Indian organisations that have built documentation frameworks have probably not yet completed that asset and exposure inventory, which means data maps won’t reflect how data actually flows across a complex, hybrid environment with cloud services, SaaS platforms, and AI integrations.
Continuous threat exposure management closes that gap. Tenable One provides continuous asset discovery across on-premises systems, cloud environments, and OT infrastructure, identifying where sensitive data assets reside and what exposures connect to them. It maps the misconfigurations, excessive permissions, and unpatched vulnerabilities that would give an attacker a path to personal data. That attack path mapping translates directly into defensibility under DPDP. When a regulator asks how you protect personal data, you can show a continuous monitoring program with evidence of prioritised remediation, not just a policy document dated last quarter.
For Indian CISOs navigating DPDP rule enforcement, the practical recommendation is to align the reporting cadence of your exposure management program with your data protection impact assessments. Use the platform to generate evidence of continuous control, not just point-in-time snapshots. That is what genuine technical readiness looks like.
CISO Forum: Indian organisations are measurably stronger at detecting incidents than recovering from them — resilience capabilities consistently lag behind perimeter and detection investments. With enterprise-wide cyber resilience ranked the #1 CISO priority by 44% of respondents, what does a credible resilience program look like operationally, and how does exposure management change incident response readiness?
Rajnish Gupta: Detection strength without recovery capability is a half-built program. Indian enterprises have invested in SIEM platforms, SOC operations, and endpoint detection tools. They can identify an intrusion. The challenge surfaces in the hours and days that follow. Incident response teams face environments they do not fully understand, attack paths they did not anticipate, and remediation workflows that depend on manual effort across siloed teams.
A credible resilience program is preventive and starts with knowing your environment before an incident occurs. That sounds obvious, but most organisations discover significant gaps in their asset inventory during an incident response, not before it. Exposure management builds the foundational knowledge base that enables faster, more precise incident response. When your team knows the complete attack surface, understands which assets are most critical, and has mapped the attack paths that connect your exposures to those assets, you enter an incident with a response advantage.
Operationally, resilience programs that work combine three capabilities. The first is pre-incident exposure reduction, using continuous assessment to shrink the attack surface before adversaries exploit it. The second is attack path awareness, so responders know immediately which other systems are at risk when one system is compromised. The third is automated remediation orchestration, so the response moves at machine speed rather than waiting for manual ticket queues to clear.
The volume of vulnerabilities entering enterprise environments has grown beyond what manual processes can manage. Exposure management with AI-driven prioritisation and agentic remediation gives Indian CISOs the operating model their resilience programs actually need, one that addresses the flood of findings without requiring proportional headcount growth.
CISO Forum: The talent shortage has overtaken budget as the top internal barrier, while AI-powered SOC automation is the top investment priority. Tenable’s Hexa AI offers agentic remediation orchestration. How do you guide Indian CISOs to deploy automation as a force multiplier rather than a headcount substitute — and where does over-automation become a risk in itself?
Rajnish Gupta: The framing matters enormously here. CISOs who deploy automation as a headcount substitute create two problems. They reduce the human judgment required for security decisions and remove the training pipeline for the next generation of analysts. Automation becomes a force multiplier when it eliminates repetitive, low-judgment work that consumes analysts’ time, allowing the analysts who remain to focus on the decisions that actually require security expertise.
Hexa AI, Tenable’s agentic AI capability within the Tenable One platform, operates on this principle. It automates attack path mapping, exposure prioritisation, and remediation orchestration across the hybrid attack surface. The workflows it executes are the ones that would otherwise require an analyst to correlate findings from multiple tools manually, determine which vulnerability matters most in context, and route the remediation ticket to the right team. That work is time-consuming, error-prone, and does not require irreplaceable human judgment. Automating it frees analysts to focus on threat hunting, incident response strategy, and stakeholder communication.
The risk of over-automation is real and worth naming directly. Automated remediation without appropriate guardrails can cause availability incidents, especially in OT environments or production systems where patch deployment requires change management. Agentic AI workflows require human oversight checkpoints at decisions that carry meaningful operational risk. The correct model is automation with escalation, not automation as a replacement for judgment.
For Indian CISOs building AI-powered SOC programs, the governance question is as important as the technology selection. Define which remediation actions are safe to automate fully, which require human approval, and which require dual authorisation. Build that governance into the platform configuration, not as an afterthought.
CISO Forum: Only 49% of Indian boards view cybersecurity as a component of enterprise resilience and brand trust—7% still treat it as a cost centre. CISOs are increasingly expected to speak in business-impact terms, not in terms of vulnerability counts. What narrative or evidence has proven most effective in elevating CISO credibility at the board level in Indian enterprises?
Rajnish Gupta: The narratives that fail at the board level share a common structure. They report on security activity: vulnerabilities patched, alerts investigated, tools deployed. Boards that manage public companies, shareholder obligations, and regulatory exposure do not think in those terms. They think about risk to revenue, brand, customer trust, and operational continuity.
The narratives that succeed translate security posture into business risk. The most effective framing I have seen is the attack path briefing. A CISO who can stand in front of a board and say, ‘Here are the three paths an attacker would most likely use right now to reach our customer payment data, here is our current exposure on each path, and here is what closing these paths requires in terms of investment and prioritisation,’ has shifted the conversation from security activity to business decision-making.
Instead of reporting that ‘we patched 80% of critical CVEs,’ effective communication with a board calls for framing that speaks to outcomes. Say, ‘we eliminated three attack paths that led directly to our core banking infrastructure, reducing our estimated breach probability for that system by X per cent.’ That is the language boards act upon.
For Indian CISOs, the additional context is regulatory. Under DPDP and RBI cybersecurity frameworks, a board that treats security as a cost centre carries liability risk. Framing cybersecurity investment as regulatory risk mitigation with quantified exposure reduction gives board members a business reason, not just a technical one, to engage seriously with security programs.
CISO Forum: If you could prescribe one structural change for Indian enterprise CISOs in 2026 — not a technology investment, but a governance or organisational shift — what would it be, and why does it matter more than any tool they could deploy?
Rajnish Gupta: In most large Indian enterprises, the CISO participates in technology steering committees, vendor reviews, and IT governance forums. These are useful but insufficient. Cyber risk does not live in the technology layer. It lives in every business decision that determines what data the organisation processes, which third parties it connects to, which markets it enters, and how quickly it digitises operations. CISOs who sit outside those business decisions inherit risk they have no opportunity to influence.
The structural change is to give the CISO a defined seat and voice on enterprise risk committees, M&A due diligence processes, major product launches, and digital transformation program boards, not as a reviewer who approves technology choices, but as a risk partner who shapes how the business evaluates the security implications of business decisions before they are made.
This matters more than any tool because tools address the security posture of the existing environment. Governance access addresses the security posture of the environment being built. The most expensive security problems Indian enterprises face, including Shadow AI proliferation, OT integration risk, and third-party data exposure, are not technology failures. They are governance failures. Decisions were made without adequate input from security, and the security team inherited the consequences.
CISOs who want this change need to build the business case, not the technical case. They need to document, with specific examples from their own organisation, instances where early security involvement would have changed a business decision and reduced downstream risk. They need to speak the language of enterprise risk, not cybersecurity risk. And they need board sponsors who understand that, in 2026, cyber and business risk are not on parallel tracks.
