Next cybersecurity opportunity is securing AI itself, not just using AI for defence, says Proofpoint India country manager
AI adoption across enterprises is creating an entirely new category of cybersecurity around governing AI applications, AI agents and enterprise data rather than simply using AI to improve threat detection, according to Proofpoint India country manager Bikramdeep Singh.
AI is creating a new cybersecurity market centred on governing AI applications, AI agents and enterprise data rather than simply detecting AI-powered threats. As enterprises move AI from experimentation into production, partners are finding the next services opportunity lies in securing AI adoption through governance, visibility and forensic controls.
Speaking to CRN India, Proofpoint India country manager Bikramdeep Singh said AI adoption is now being driven from the CEO and board level, requiring cybersecurity teams to enable AI adoption securely rather than slowing it down.
He argued that organisations need greater visibility into AI applications, stronger governance over AI agents and better controls around enterprise data as AI becomes embedded across business operations.
Singh said enterprises have spent years building cybersecurity architectures around users, devices and applications, but AI introduces an entirely new operational layer that existing security controls were not designed to manage.
"Every board is asking whether the organisation is adopting AI," Singh said.
"As a result, the role of cybersecurity is not to act as a barrier to AI adoption but to enable the organisation to adopt it securely."
According to Singh, organisations first need visibility into every AI application being used across the business, including tools employees may be accessing without formal approval.
Beyond identifying sanctioned and unsanctioned AI applications, organisations also need to understand what information employees and AI systems are sharing with those applications and whether AI tools are accessing only the enterprise data they are authorised to use.
He said these capabilities are important as AI moves beyond individual productivity tools and into enterprise workflows.
"If an AI agent is expected to retrieve data from specific databases to generate a response, organisations need to ensure it is accessing only those authorised sources and not going elsewhere," Singh said.
Rather than treating AI security as another technology layer, Singh described it as a governance challenge that requires continuous visibility, policy enforcement and forensic evidence across AI environments.
Security operations moving from automation to AI governance
The expansion of AI is also reshaping how security operations function.
According to Singh, security operations centres have long relied on automation to manage incident triaging because of the volume of security events generated across enterprise environments. AI, however, extends that role from workflow automation to behavioural analysis.
Instead of simply routing alerts based on predefined rules, AI systems can analyse user behaviour, identify abnormal activity and determine whether individuals require additional monitoring or controls.
"As AI takes on more advanced analytical responsibilities, organisations need to establish appropriate guardrails," Singh said.
He said organisations are gradually moving away from deterministic automation towards AI systems capable of making more human-like decisions, making governance significantly more important.
That, according to Singh, requires enterprises to apply the same principles they use for human identities to AI agents by restricting data access, limiting authorised activities and maintaining forensic visibility into AI interactions.
"A maker-checker approach remains important, particularly when AI is being deployed in critical security functions," he said.
Human risk expands into an agentic workplace
Singh also believes organisations need to rethink security models built entirely around human users as AI agents become part of enterprise operations.
He compared traditional social engineering attacks with the emergence of prompt engineering, where attackers manipulate AI systems to expose sensitive information or perform unauthorised actions.
"We are no longer talking only about people interacting with AI," Singh said.
"We are also talking about AI agents interacting with other AI agents."
According to him, organisations therefore need visibility not only into human behaviour but also into interactions taking place across AI applications and autonomous agents.
He said behavioural analysis is becoming important because organisations must identify anomalous intent across both users and AI systems rather than relying solely on rule-based alerts.
AI security investment shifts towards governance and visibility
Looking ahead, Singh expects enterprise cybersecurity investment to move beyond using AI for threat detection towards securing AI itself.
He identified AI application discovery, AI governance, insider threat protection and forensic visibility as areas likely to attract increased investment as organisations scale AI deployments.
According to Singh, organisations need continuous visibility into all AI applications operating across their environments, whether approved by the organisation or introduced independently by employees.
They also need assurance that AI applications access only authorised enterprise data while maintaining forensic records of AI-related activity.
"For us, AI security is not just about using AI to improve threat detection. It is also about securing the use of AI itself," Singh said.
Alongside AI governance, Singh expects organisations to continue investing in email security, insider threat protection and AI infrastructure, including AI data centres, over the next 12 to 18 months.
As AI adoption accelerates across Indian enterprises, he argued that cybersecurity will be measured not by how effectively organisations use AI, but by how securely they govern it.