As enterprises accelerate the adoption of artificial intelligence across business functions, the technology is simultaneously reshaping the cybersecurity threat landscape. The growing use of AI models, applications, APIs, data pipelines and autonomous agents is expanding the attack surface, while enabling threat actors to execute attacks with greater speed and sophistication. For organisations, this is creating an urgent need to balance AI-driven innovation with security, governance and resilience.
Against this backdrop, secure-by-design approaches and structured AI governance are becoming increasingly important. Frameworks such as ISO/IEC 42001 can help organisations establish accountability, assess AI-related risks and implement controls across the AI lifecycle, while cybersecurity technologies such as AI-driven analytics, automation and threat intelligence can strengthen detection and response capabilities.
In this interview with AI Spectrum, Atul Luthra, CEO, Zeroday Ops and Co-Founder, 5Tattva, discusses the evolving cybersecurity risks associated with enterprise AI adoption, the importance of AI governance and secure-by-design principles, and how organisations can protect increasingly autonomous AI environments. He also shares his views on the role of AI and automation in SOC operations, vulnerability management and digital forensics, as well as the key cybersecurity trends Indian enterprises should prepare for over the next two to three years.
As enterprises accelerate AI adoption, how is the growing use of AI changing the cybersecurity threat landscape, and what are the key risks organisations need to address?
AI is creating a fundamental shift in the cybersecurity landscape. It is giving enterprises new capabilities to automate decisions and improve productivity, but it is also giving cybercriminals the ability to launch attacks faster, at greater scale and with far greater sophistication.
We are seeing the attack surface expand beyond traditional infrastructure to include AI models, applications, APIs, data pipelines, third-party AI platforms and autonomous agents. Risks such as sensitive-data leakage, prompt injection, insecure AI integrations, identity abuse and AI supply-chain vulnerabilities therefore need to be taken seriously.
The bigger concern is the speed of adoption. In many organisations, AI is being deployed faster than security and governance frameworks are evolving. Enterprises need to adopt a secure-by-design approach to AI, with security, privacy, governance and resilience built into the AI lifecycle from day one.
This is where a structured governance standard becomes essential. ISO/IEC 42001, the international standard for AI management systems, gives enterprises a formal framework to govern AI responsibly. It defines accountability and ownership for AI systems, requires risk and impact assessments before deployment, mandates controls across the full AI lifecycle from data sourcing to model retirement, and establishes continuous monitoring and improvement. Aligning AI programmes with ISO 42001, alongside existing ISO 27001 controls, allows organisations to move from ad-hoc AI experimentation to auditable, board-level governance, and to demonstrate that assurance to regulators, customers and partners.
At the CIO500 event series, 5Tattva is engaging with technology leaders on delivering measurable business value from AI and digital investments. What factors should enterprises consider to ensure their AI investments translate into tangible business outcomes?
The starting point should always be the business problem, rather than the technology. Enterprises need to identify clearly defined use cases where AI or digital transformation can improve revenue, productivity, customer experience, operational efficiency, risk management or decision-making.
Three factors are particularly important. First, organisations need measurable outcomes and KPIs before embarking on an AI initiative. Second, they need high-quality, accessible and governed data because AI outcomes are only as strong as the data and processes supporting them. Third, AI initiatives need to be integrated into business workflows so that employees can actually act on the intelligence generated.
Enterprises should also evaluate the total cost of ownership, scalability, security, regulatory requirements and change-management implications. Successful AI adoption is not about deploying the maximum number of models or tools; it is about creating repeatable, secure and scalable capabilities that deliver demonstrable business value.
How can organisations build security into AI deployments from the design and development stages, particularly as AI applications become increasingly integrated with enterprise systems and sensitive data?
Security cannot be an afterthought when AI is connected to enterprise data and business-critical systems. It has to be part of the architecture from the beginning.
Organisations should adopt a secure-by-design approach, beginning with understanding what data an AI application can access, what actions it can perform and who or what is authorised to access it. Strong identity controls, least-privilege access, data protection, encryption and continuous monitoring become particularly important when AI agents are able to interact with enterprise applications.
AI systems should also undergo threat modelling, secure development reviews, vulnerability assessments, penetration testing and adversarial testing before they enter production.
As AI becomes more autonomous, organisations will need to secure not just applications and users, but also AI identities, agents and machine-to-machine interactions. This makes AI security a continuous discipline rather than a one-time compliance exercise.
With AI also being used by threat actors to make cyberattacks more sophisticated, how should enterprises evolve their security strategies to detect and respond to AI-driven threats?
The speed of AI-enabled attacks means that traditional, predominantly reactive security models will increasingly struggle to keep pace. Enterprises need to become more proactive, intelligence-led and automated.
This means improving visibility across identities, endpoints, cloud environments, applications and data, while using modern security analytics to identify behavioural anomalies and emerging attack patterns. Threat intelligence can add context, while AI and automation can help security teams prioritise alerts, accelerate investigations and automate appropriate response actions.
At the same time, we should not assume that AI can replace security professionals. Human judgement remains critical, particularly when organisations are dealing with complex incidents or decisions with significant business impact.
The goal should be a security operation where machines handle speed and scale, while people provide context, judgement and accountability.
What role can technologies such as AI, automation and threat intelligence play in strengthening capabilities such as SOC operations, vulnerability assessment, penetration testing and digital forensics?
AI and automation can fundamentally improve the efficiency and effectiveness of cybersecurity operations by helping security teams deal with the sheer scale and complexity of today's threat environment.
In the SOC, AI can correlate large volumes of events, identify anomalies, reduce alert fatigue and accelerate investigation. Automation can take repetitive actions out of the hands of analysts, allowing them to focus on higher-value investigations.
In vulnerability management, AI can help organisations move beyond simply counting vulnerabilities to understanding which vulnerabilities present the greatest business risk. In penetration testing, AI can accelerate reconnaissance and test-case generation, while experienced security professionals continue to validate findings and identify complex attack paths.
Similarly, AI-assisted forensics can help investigators analyse large datasets and identify patterns faster.
The opportunity is not simply to automate cybersecurity. It is to create smarter, faster and more context-aware security operations, with human expertise remaining at the centre.
Looking ahead, what are the key cybersecurity and AI trends that Indian enterprises should prepare for over the next two to three years, and how can organisations build greater cyber resilience while continuing to innovate?
Over the next two to three years, we expect the convergence of AI and cybersecurity to accelerate significantly. AI agents and autonomous workflows will become increasingly common, creating both new business opportunities and new categories of cyber risk.
Identity will become a particularly important battleground—not only for employees and customers, but also for machines, APIs and AI agents. We will also see greater focus on AI supply-chain security, data protection, cloud and API security, continuous exposure management and AI-assisted security operations.
For Indian enterprises, resilience will come from building security into digital transformation rather than treating it as a separate function. Organisations need strong foundations around identity, data protection, vulnerability management, continuous monitoring and incident response, combined with secure-by-design principles for AI.
Ultimately, the organisations that innovate with confidence will be those that make cybersecurity an enabler of AI adoption, not a barrier to it.

