
Cyber Security
The Rise Of AI-Led Cybersecurity Operations In Indian Enterprises
Overview
Here is a brief introduction to Diwakar:
Diwakar Dayal is the Managing Director & Area Vice President for India & SAARC at SentinelOne. A CISSP-certified cybersecurity leader and UC Berkeley Haas alumnus, he brings over 27 years of experience building and scaling security businesses across India and Asia-Pacific. He has held leadership roles at Cisco, Juniper, Tenable, Qualys, Wipro, and Sify/VeriSign, and currently leads SentinelOne’s regional operations, strategy, and go-to-market execution.
He also highlights how AI will change the day-to-day responsibilities of security teams without replacing human expertise. The result is a clear roadmap for enterprises seeking unified visibility, stronger AI governance, faster response, and a cybersecurity posture built for prevention rather than reaction.
TD Editor: Indian enterprises are rethinking traditional SOC models today. What are the biggest operational changes you’re seeing as organizations integrate AI and automation into security operations?
The biggest shift is that SOCs are moving from human‑paced, tool‑hopping work to AI‑led, data‑driven operations, because traditional alert‑chasing simply can’t keep up with the speed and volume of attacks on large Indian enterprises.
Practically, that means three things: bringing security data from endpoints, cloud, identities, and applications into one place; handing more routine tasks like sorting alerts and triggering standard responses to automation; and treating data quality and automation design as core to the operating model, not back‑office IT because with messy data and ad‑hoc processes, you can’t run a truly modern SOC in India.
TD Editor: The industry is increasingly talking about Autonomous SOCs and agentic AI. In practical terms, how do you see these capabilities changing the day-to-day responsibilities of security teams over the next few years?
AI won’t replace security teams, but it will fundamentally change how they spend their day. In an autonomous‑style SOC, AI systems constantly watch activity across systems, join the dots, and, within defined guardrails, can take first‑line action in seconds. That means far less time spent on checking individual alerts and far more time spent on deciding what to do about real incidents.
For analysts, the job becomes more about supervising what the AI is doing, digging into complex cases, and improving playbooks and policies over time. You’ll see new responsibilities emerge around data quality, AI governance, and model behaviour, because someone has to ensure these systems stay aligned with business risk. In a market like India, where the cyber talent gap is real, this “humans plus AI” model is the only way to defend at the same speed as attackers are operating.
TD Editor: As enterprises continue to expand across cloud, edge, and remote environments, why has unified visibility become such a critical challenge for modern cybersecurity strategies?
Most Indian enterprises are running a mix of everything: legacy data centres, multiple public clouds, SaaS apps, UPI and payments systems, remote work, and in some cases OT or branch
environments. Each of these brings its own tools and logs. When that information sits in separate places, you inevitably end up with blind spots.
Unified visibility is really about answering a simple question: “Do we know what’s happening across our entire technology estate, quickly enough to act?” If you can’t see devices, users, cloud workloads, and critical applications together, you’re always one step behind the attacker. That’s why more leaders are trying to get security‑relevant data into a common layer and using AI to highlight what matters most. It’s less about a single dashboard and more about having one trusted view of risk that security, IT, and business teams can act on together.
TD Editor: Cyber threats in India are evolving rapidly, especially with the rise of AI-driven attacks and identity-focused breaches. Which emerging threat patterns concern you the most right now?
Two shifts worry me the most. First, attacks are now happening at “machine speed.” AI lets attackers scan, learn, and exploit weaknesses much faster than before, so the time between a small mistake and a major breach is shrinking. Traditional, manual defences struggle when the other side is using automation and AI by default.
Second, attacks are increasingly targeting people and trust, not just systems. We’ve seen deepfake‑based scams where fraudsters use AI‑generated video to bypass identity checks, including Aadhaar verification. Digital payments are being hit by highly convincing phishing, fake QR codes, and “digital arrest” scams, where people are coerced over video calls by attackers impersonating officials. For India’s critical sectors like banks, telecom, government, and energy, that mix of AI‑driven speed and identity‑based attacks is especially dangerous. It means we must invest more in protecting identities, monitoring behaviour, and verifying that the person or system on the other side is genuine before we trust them.
TD Editor: Despite growing interest in AI-led cybersecurity, many organizations still struggle with implementation. Where do you think the biggest readiness gaps exist today across technology, processes, or talent?
The first gap is technology debt. Many SOCs are still built on older tools and fragmented stacks that were never designed with AI in mind. They produce a lot of alerts but not enough insight, which makes it hard to plug in AI and get meaningful outcomes. Without better‑integrated platforms and cleaner data, AI risks becoming a side project.
The second gap is process and governance. In many AI projects, security comes in at the end rather than being part of the design. Basic questions are still unclear in a lot of organisations: which AI tools are allowed, what data can they see, how long is it kept, and who owns the risk? The third gap is skills. Teams increasingly need people who understand both security and data/AI, how models work, where they can fail, and how to keep them aligned with business and regulatory expectations. India has strong cyber talent, but we need structured upskilling to prepare teams for this new blend of responsibilities.
TD Editor: For organizations looking to move beyond reactive defense models, what foundational changes are necessary to build a more predictive and prevention-first security posture?
The biggest change is mindset: accepting that security built for yesterday’s threats will not hold up against AI‑enabled attackers. Organisations have to move from “waiting for alerts” to continuously looking for weak spots and unusual behaviour across their environment, with AI and automation doing the first pass and humans focusing on what’s truly risky.
Make sure your key data: endpoints, cloud, identities, and applications can be analysed in near real time, and automate more investigation and response so teams act at the speed of the attack, not email. When security is built in early to AI projects, products, partners, and board discussions and treated as part of growth and customer trust, not just compliance, so you genuinely start moving from reactive firefighting to a prevention‑first posture.
Thu, Jun 25, 2026
Enjoyed what you read? Great news – there’s a lot more to explore!
Dive into our content repository of the latest tech news, a diverse range of articles spanning introductory guides, product reviews, trends and more, along with engaging interviews, up-to-date AI blogs and hilarious tech memes!
Also explore our collection of branded insights via informative white papers, enlightening case studies, in-depth reports, educational videos and exciting events and webinars from leading global brands.
Head to the TechDogs homepage to Know Your World of technology today!
Disclaimer - Reference to any specific product, software or entity does not constitute an endorsement or recommendation by TechDogs nor should any data or content published be relied upon. The views expressed by TechDogs' members and guests are their own and their appearance on our site does not imply an endorsement of them or any entity they represent. Views and opinions expressed by TechDogs' Authors are those of the Authors and do not necessarily reflect the view of TechDogs or any of its officials. While we aim to provide valuable and helpful information, some content on TechDogs' site may not have been thoroughly reviewed for every detail or aspect. We encourage users to verify any information independently where necessary.
Loading comments...
