New Delhi, Sept. 17 -- As AI agents move from generating content to taking actions across enterprise systems, security is shifting from protecting infrastructure to governing machine-led decisions. For Indian enterprises, this places greater emphasis on visibility, identity and resilience as cloud environments become more distributed and AI adoption expands, said Ninad Katkar, Leader, Security, Cisco India & South Asia, in an exclusive interview. Edited excerpts.

Q. How is AI changing enterprise security priorities, and where are CIOs underestimating the risk?

AI is both a major driver of security risk and a powerful tool for defence. Cisco's Cybersecurity Readiness Index found that 95% of organisations had experienced AI-related security incidents in the past year, while 96% were using AI to understand threats and 88% for threat detection.

Many CIOs still treat AI as another application rather than a new operating model. We have moved from AI that generates content to AI that takes action. Agents can access systems, move data, trigger workflows and make decisions autonomously. The risk is no longer a wrong answer, but a wrong action.

Organisations need to focus on both AI for security and security for AI. This includes securing models, data and agents, alongside using AI for threat detection.

Q. Why are networking and security converging, and how is this changing enterprise architecture?

The traditional enterprise perimeter has effectively disappeared. Applications are distributed across clouds, employees work from anywhere, and AI agents are becoming active participants in business processes.

According to Cisco's index, 90% of organisations face increased security risks from employees accessing networks through unmanaged devices. Security must travel with the data. Connectivity and protection need to operate through a shared context and policy framework.

As AI workloads scale, networks must also be intelligent, low-latency and secure by design.

Q. What is driving the shift from point security products to integrated platforms in India?

Customers are no longer asking for more security tools. They want simpler security operations. Cisco's research found that 84% of organisations in India reported that managing more than ten point security solutions was slowing their response to threats.

Customers increasingly want integrated architectures that bring together networking, security, observability, identity and AI-driven operations. The demand is strong across secure access, identity-driven security, AI security, cloud security and threat detection and response.

Q. Which sectors offer the strongest opportunities for security growth?

Financial services remains one of the strongest sectors, driven by fraud prevention, identity security, data protection and regulatory compliance. Telecommunications, government, healthcare and large enterprises are also investing as they modernise infrastructure.

As AI deployment expands, organisations face new challenges around agent governance, application security, model protection, runtime controls and visibility. Manufacturing is another sector to watch as AI accelerates IT-OT convergence and expands the attack surface.

Q. Where is the biggest security gap as enterprises connect cloud, AI and edge environments?

The biggest gap is visibility. Organisations are connecting more clouds, edge locations, applications and AI systems, yet many lack end-to-end visibility. Shadow AI adds further blind spots.

The second gap is data. Machine data across networks, applications, endpoints and security systems remains fragmented. Organisations need to correlate machine, operational and business data to move from collecting information to taking informed action.

Q. Are enterprises investing sufficiently in security resilience?

Ninad Katkar: Many organisations still focus primarily on prevention and compliance. These remain important, but enterprises must assume attacks will happen. The differentiator is how quickly they detect, respond and recover.

The window between vulnerability and exploitation has collapsed from weeks to minutes. Reactive defence is no longer enough when adversaries operate at machine speed. Resilience requires continuous visibility, automation and rapid response.

Q. As AI agents gain access to systems and data, is identity becoming the new security perimeter?

Identity is becoming a defining control point of the AI era. Enterprises must govern AI agents, APIs, machine accounts and autonomous workflows alongside human users.

Every agent must be identified, mapped to a human owner and held accountable for its actions. Organisations should apply Zero Trust principles, including least-privilege access, continuous behavioural verification and comprehensive audit logs.

Q. What three security investments should CIOs prioritise before scaling AI?

First, visibility across users, devices, applications, models and agents. You cannot govern what you cannot see.

Second, identity, with clear ownership, defined permissions, continuous monitoring and accountability for every agent.

Third, secure infrastructure by design. Security cannot be bolted on afterwards; it must be embedded directly into infrastructure. The organisations that lead in AI will be those that build the trust, visibility and resilience required to operate it safely at scale.

Published by HT Digital Content Services with permission from TechCircle.