Security breaches are inevitable, your response is not
https://etimg.etb2bimg.com/thumb/msid-132555659,imgsize-124819,width-1200,height=627,overlay-etciso,resizemode-75/data-breaches/security-breaches-are-inevitable-your-response-is-not.jpg
Enterprise security leaders have tried to prevent attacks for years. Boards invested in firewalls, perimeter defenses and access restrictions while measuring success by the absence of breaches. Yet, AI is increasing the speed and scale of attacks, causing organizations in India and around the world to reevaluate how they define security effectiveness.
As rapid digital adoption increases the risk of breaches and threats across India, organizations must plan for when, not if, a breach occurs. They must quickly recognize threats, develop protocols to contain them and act when necessary to protect confidential information. Successful organizations won’t rely on outdated practices; instead, they’ll plan for new challenges and use their tools, including AI-based protections.
Preparing for Attacks in an AI World
Artificial Intelligence (AI) has opened up numerous opportunities for organizations. It enhances efficiency, addresses complex problems and fosters innovation that caters to client needs. However, AI has also introduced new challenges, including industrial-scale phishing campaigns and deepfake technology that can deceive even the most tech-savvy users.
Yet, the defenders have powerful tools too. IBM’s 2025 Cost of a Data Breach Report found that the global average cost of a data breach fell to $4.44 million, down from $4.38 million the year prior, driven largely by faster AI-powered detection and response. The same report found that among organizations reporting breaches of AI models or applications, 97% reported lacking proper AI access controls. The issue is not technology but governance.
Furthermore, Gartner has projected continued growth in global information security spending, with cloud security, managed security services and AI-related security priorities contributing to that expansion. As AI advances, IT and business leaders must keep pace or face increased security breaches.
Recovery Speed is the New Security Metric
In today’s business landscape, measuring security success by the absence of breaches is no longer realistic. Attacks occur constantly, and the breach lifecycle, from identification to containment, has shortened to 241 days, the lowest in nine years. However, containment is not the same as business recovery; many organizations still require separate operational, application, data and third-party recovery work after containment occurs.
Organizations that prioritize immutable backups, practice failovers and have clean-room rebuild capabilities will outperform those that focus solely on prevention. For CIOs and CISOs in India’s rapidly expanding enterprise technology sector, where regulatory expectations are becoming stricter, including overlapping cybersecurity incident reporting, data protection and sector-specific obligations, this is an urgent necessity. The most effective way to prepare is to incorporate the right security measures into systems from the beginning rather than waiting until later.
Zero Trust is Necessary but Being Tested
To combat new, sophisticated threats, Zero Trust has become a widely adopted framework for reducing implicit trust, segmenting access and continuously verifying users, devices, workloads and services. This framework works because it removes implicit trust, requires verification and minimizes access across systems.
However, AI agents are creating new attack surfaces that traditional identity and access management (IAM) frameworks were not designed for. New vectors in identity registration, credential governance and access chains are emerging that conventional Zero Trust implementations do not account for.
To make matters worse, a 2025 study found that more than 57% of employees used personal AI accounts for work, and 33% entered sensitive information into unapproved tools. This use of shadow AI undermines existing safeguards like Zero Trust and quietly expands an enterprise’s attack surface. Education is necessary, but leaders also need policy, approved alternatives, discovery controls, data-loss prevention, identity governance, logging and enforcement mechanisms to reduce shadow AI risk and protect sensitive information.
The Quantum Clock is Ticking
The threats organizations face from improper AI use are serious, but another challenge looms. Quantum computing will eventually make the encryption methods that protect many systems obsolete. When this happens, criminals who have already stolen sensitive data may be able to decrypt data protected by vulnerable public-key cryptography, depending on the algorithms used, key sizes, implementation details and the availability of cryptographically relevant quantum computing capability.
Cybercriminals are engaging in “harvest now, decrypt later” schemes, collecting encrypted data now to crack once the technology matures. For organizations worldwide, this means their valuable, confidential information is at risk, including banking and healthcare records.
Post-quantum readiness needs more than simple cryptographic changes. A successful approach requires building a crypto-agility strategy and mapping cryptographic dependencies across applications, identity systems, certificates, key management, software supply chains, endpoints, cloud services, embedded systems and network infrastructure to prepare all environments for potential attacks.
These steps cannot occur overnight. Migrating to a post-quantum readiness infrastructure requires cryptographic dependency mapping, long-lead infrastructure modernization and phased implementation, which is why organizations must act now.
Security is a Foundation, Not a Function
Today’s cybersecurity challenges signify a fundamental shift in how enterprise risk is understood and managed. AI has transformed the nature of threats, regulatory pressures have increased the costs of failures, and quantum computing is rapidly changing the rules of encryption, often outpacing the readiness of most organizations.
In India, the enterprises that will excel in this transition are not necessarily those that focus on the number of breaches they experience. Rather, the leaders will be the ones who recover swiftly, govern their AI methods rigorously and integrate security into their systems from the outset.
The author is Philip Swarbrick, Vice President of Cybersecurity Solutions, Unisys.
Disclaimer: The views expressed are solely of the author and ETCISO does not necessarily subscribe to it. ETCISO shall not be responsible for any damage caused to any person/organization directly or indirectly.
Firewall Security Company India Complete Firewall Security Solutions Provider Company in India












