
Rubrik
View Brand PublisherAI is changing cyber threats. Recovery is becoming just as important as prevention
At a Rubrik and YourStory roundtable in Bengaluru, engineering and cybersecurity leaders discussed how AI is expanding the attack surface, creating new security challenges, and shifting the focus from preventing breaches to recovering from them quickly.
As AI accelerates software development, it is also reshaping the cybersecurity landscape. Advanced AI models such as Mythos can identify vulnerabilities at unprecedented speed, while autonomous agents, AI-generated code, geopolitical uncertainty, and shrinking attack windows are forcing organisations to rethink how they protect critical systems.
These themes took center stage at ‘Cyber Resilience in the Era of Mythos: Moving at Machine Speed in an Uncertain Digital World’, a roundtable hosted by Rubrik and YourStory Media in Bengaluru on July 10, 2026.
The discussion brought together Ananth Nag, Vice President APAC, Rubrik; Aditya Chandra, Vice President - Platform Engineering, MoEngage; Anshul Sharma, Director - Engineering, Scaler; Apoorva Gaurav, Senior Vice President of Engineering, Clear; Arghya Mukherjee, Head of AI and Data, Algonomy; Chidambaran Subramanian, Director - Technology, InCred Financial; Gaurav Kapatia, Head of Engineering, Newton School and Newton School of Technology; Karthikeyan Ramasamy, Senior Director of Engineering, Freshworks; Mohan Devarapalli, Head of Engineering, PayU; Navin Kumar, Vice President of Engineering, LeadSquared; Niraj Kumar, Director of Engineering, Shadowfax; Prabod Goel, Global Engineering Leader, Postman; Rishabh Chhajer, Vice President - IT & Cybersecurity, Allen; Utkarsh Tiwari, Head - Security Engineering (Cloud Tech), Meesho; and Vikas Roy, Director of Engineering, Vahan.ai.
Representing sectors including fintech, ecommerce, logistics, enterprise software and education, the participants discussed the challenges organizations face as AI becomes embedded across products and operations. While concerns ranged from protecting personally identifiable information (PII) and securing AI-generated code to governing AI agents and managing supply-chain risks, one message stood out: prevention alone is no longer enough.
AI is expanding the attack surface
As organizations adopt AI to build and ship software faster, they are also introducing new security risks.
Participants pointed to prompt injection attacks, AI-generated code, non-human identities, third-party dependencies, and AI agents acting on behalf of users as some of the biggest challenges enterprises must now address.
Mukherjee highlighted the risks of using customer data in large language model (LLM) training and the need to secure agentic AI systems. Kumar spoke about protecting sensitive customer information and preventing cross-tenant exposure at LeadSquared, while Ramasamy pointed to the emerging challenge of governing non-human AI identities. Others discussed the growing need for stronger AI guardrails, observability, and governance as AI becomes part of day-to-day business operations.
The pace of software development itself is creating another layer of complexity.
“AI is expanding the surface area faster than we can secure it,” Sharma said.
While participants agreed that AI has accelerated software development and experimentation, they also noted that the same speed increases the likelihood of introducing vulnerabilities that organizations may not immediately detect or fully understand.
Several participants said the response is to use AI as part of the defense strategy as well.
“We use AI to fight AI,” said Roy, describing how Vahan.ai deploys AI-driven defensive agents and detection mechanisms. At the same time, he acknowledged that the approach is still evolving because AI agents are often non-deterministic, making them harder to test and secure using conventional methods.
Meesho has focused on securing AI-generated code at the source. “We start as early as putting guardrails on the coding agent itself, so that the code it writes is secure by default,” Tiwari said.
From preventing attacks to recovering from them
Nag urged the group to think beyond prevention and consider what happens after a breach.
Referring to recent cyber incidents involving Jaguar Land Rover and Marks & Spencer, he noted that even large organizations with mature security programs can experience prolonged business disruption. He argued that companies have traditionally invested heavily in prevention, detection and remediation, while resilience, the ability to recover and restore business operations, has often received less attention.
Participants agreed that the conversation is changing because cyber breaches are increasingly viewed as inevitable.
Instead of asking, ‘Can every attack be stopped?’, organizations are beginning to ask: How quickly can systems be restored when an attack succeeds?
Ramasamy argued that while AI introduces new risks, organizations should continue to rely on established security principles, including layered architecture, identity-based access, least-privilege permissions and robust guardrails. AI agents, he said, should access only authorised tools and data on behalf of verified users, limiting the impact of a potential breach.
For Chandra, resilience is also about organizational culture.
He argued that many companies continue to approach cybersecurity as a compliance exercise instead of treating it as an engineering discipline built around continuous monitoring, behavioural threat detection and operational readiness.
“Culturally, Indian organizations are not ready. A lot of enterprises do things for just mere eyewash, for a checkbox, for a tick mark on the security audit. We do not fathom the depth of the problem,” he said.
The discussion repeatedly returned to the same conclusion: in an AI-driven world, preventing attacks remains critical, but resilience is becoming just as important. As software development accelerates and attack cycles continue to shrink, organizations will need to prepare not only to defend their systems, but also to recover quickly when those defences are breached.
Recovery begins with trusted data
A recurring theme throughout the discussion was the difference between disaster recovery and cyber recovery.
Operational outages are relatively straightforward because organizations know their backup systems remain intact. Cyberattacks, participants noted, are fundamentally different. Attackers can compromise both production systems and backups, leaving organizations unsure which copies of their data can still be trusted.
Explaining the distinction, Nag said: “When we get breached, it's not operational recovery. Operational recovery is a copy of mine that I just need to bring back. Cyber recovery is, I have a copy, but I don't know if that copy is infected. If it's infected, what does it take for us to recover?”
He said true cyber resilience depends on more than maintaining duplicate infrastructure. Organizations need clean, isolated recovery environments and verified backups that can be restored with confidence after an attack.
One participant shared an incident involving a disgruntled database administrator who deliberately deleted critical databases. Recovery was possible only because the organization had maintained multiple isolated copies of its data. The experience, participants noted, reinforced the value of permanent, secure backups, and clearly defined recovery strategies that can withstand both external attacks and insider threats.
Building guardrails for AI agents
As enterprises deploy more AI agents, participants agreed that organizations must start treating them like any other digital identity—with defined permissions, monitoring, and accountability.
Prompt injection attacks, rogue agents, and identity management for non-human users emerged as some of the biggest concerns as AI systems become more autonomous.
Speakers discussed the importance of policy guardrails, adversarial testing, sandboxing, identity management, and continuous monitoring to ensure AI systems operate safely. While no security framework can eliminate every risk, participants agreed that multiple layers of protection significantly reduce the chances of AI behaving in unexpected ways.
The discussion also touched on how AI-generated code is changing software development itself. As engineering teams ship code faster, developers are increasingly deploying software they may not fully understand, making governance, visibility, and continuous validation more important than ever.
Cyber resilience is a business issue
As the discussion drew to a close, participants agreed that cyber resilience extends well beyond technology.
Many organizations, they said, still approach cybersecurity as a compliance requirement rather than a core business capability. Building resilience requires regular breach simulations, recovery drills, and tabletop exercises to ensure teams can restore operations quickly when an incident occurs.
Participants also stressed that resilience must become a board-level priority rather than remaining solely the responsibility of technology and security teams. Recovery planning, they argued, should be treated as an investment in business continuity, not simply another security initiative.
Throughout the roundtable, one idea continued to surface. AI is making software development faster, but it is also increasing the speed and sophistication of cyber threats. As organizations adopt AI across products, engineering and operations, they are also expanding the number of systems, identities and workflows that need to be secured.
For many in the room, that changes the nature of cybersecurity itself.
The goal is no longer to assume every attack can be prevented. Instead, organizations must be prepared to detect attacks quickly, recover trusted data, restore business operations and minimize disruption when a breach occurs.
In an AI-driven threat landscape, resilience is no longer a fallback plan. It is becoming a core part of cybersecurity strategy.

