10th Cyber & Data Security Summit 2026: Charting India’s Roadmap “From Data to Defenceâ€
The 10th edition of the Cyber and Data Security Summit (CDS) 2026, hosted by VARINDIA, convened policymakers, law enforcement officials, CIOs, CISOs, legal experts and global technology leaders under the theme “From Data to Defence” in New Delhi on February 20. Held at Hotel Pride Plaza in Aerocity, the full-day industry summit presented a structured roadmap linking governance, enterprise transformation and cyber defence innovation.
The summit commenced with an auspicious lamp-lighting ceremony, graced by leading dignitaries from government and industry, signalling the start of a comprehensive exploration of India’s evolving cybersecurity landscape. Dr. Deepak Kumar Sahu, Editor-in-Chief of VARINDIA, welcomed attendees and underscored the importance of collaboration across policy, technology and governance. “We have gathered at a platform where industry, OEMs, and VARs converge to address critical challenges in cybersecurity and data protection,” he remarked, setting a collaborative tone for the day.
Delivering the industry address, Dr. Pavan Duggal, Chairman of the International Commission on Cyber Security Law, highlighted the growing need for a regulatory framework that balances security with innovation. He underscored that cybersecurity is not just a technical issue but a societal imperative requiring proactive governance and legal preparedness.
The Chief Guest, Padma Jaiswal, Secretary, Government of National Capital Territory of Delhi (GNCTD), addressed the audience on the government’s role in securing digital infrastructure. She emphasized the need for progressive policies that enable innovation while safeguarding citizen data, reinforcing India’s commitment to building a secure and trusted cyber ecosystem.
L to R: Dr. Sahu, Publisher, VARINDIA; Dr. Harsha Thennarasu (CERT-In Auditor), Chief Cyber Defence Advisor – HKIT Cyber Security Solutions; Dr. Arindam Sarkar, Chief Architect, Faceoff Technologies Inc.; Maj General (Dr.) Dilawar Singh, Independent Director, Transrail Lightening Ltd.; Dr. Pawan Duggal, Chairman- International Commission on Cyber Security law; Padma Jaiswal, IAS, Secretary, GNCTD - Govt. Of Delhi; S Mohini Ratna, Editor, VARINDIA; Adv. (Dr.) Prashant Mali, PhD, Cyber Law ExpertBombay High Court and Pankaj Mittal, Founder & CEO, Digizen Consulting
Presenting the corporate perspective, Ankit Wasnik, Lead Security Solutions Architect at Qualys, showcased enterprise security solutions and emphasized the importance of automated risk detection in cloud and hybrid environments to strengthen cyber resilience.
Guest speaker Adv. (Dr.) Prashant Mali, Cyber Law Expert, Bombay High Court, elaborated on evolving legal frameworks for cybercrime mitigation. He stressed that law must evolve alongside technology to ensure accountability, transparency and trust in the digital economy.
POLICY, GOVERNANCE AND NATIONAL CYBER PREPAREDNESS
The first panel discussion, “Securing India’s Digital Future: From Risk to Resilience,” moderated by Dr. Sahu, featured Maj General (Dr.) Dilawar Singh, Independent Director, Transrail Lightening Ltd.; Deepti Bhatia, CIPP/E, Chair – IAPP New Delhi Chapter; Sarita Padmini, Senior Director, Protiviti; Dr. Harsha Thennarasu (CERT-In Auditor), Chief Cyber Defence Advisor – HKIT Cyber Security Solutions; and Vishal R Soni, Strategic Advisor – Consulting Practice. The discussion focused on strengthening cyber hygiene at scale, building resilient systems and embedding security within organizational DNA.
In his keynote address, Dr. Pronab Mohanty, DGP – ICT & Cybercrime, Government of Karnataka, addressed emerging threats in AI-driven cybercrime. He highlighted the need for predictive analytics, coordinated enforcement mechanisms and robust threat intelligence to protect critical and citizen-facing infrastructure.
Post-lunch sessions shifted toward enterprise execution and technology deployment. Sumith Satheesan, Head – Enterprise Solution Consulting, TP-Link, spoke about secure connectivity and enterprise networking solutions, emphasizing, “In the AI era, network security is the foundation of digital trust; any weak link can compromise the entire system.”
The second panel discussion, “Ready to Secure Your AI Transformation?”, moderated by Mohini Ratna, Editor, VARINDIA, featured Bharat B Anand, Group Chief Information & Technology Officer, Contec Global Ltd.; Anandaday Misshra, Founder & Managing Partner, AMLEGALS; Pankaj Mittal, Founder & CEO, Digizen Consulting; and Chetandeep S Batra, Senior Security Consultant, EY Global Consulting Services. The panel explored AI-driven data protection strategies, governance mechanisms and enterprise risk frameworks.
Pankaj Mittal, Founder & CEO of Digizen Consulting, highlighted risk management in AI-enabled enterprises. “AI can only learn from the data you provide. Misuse or incorrect configurations can turn innovation into a liability,” he warned.
The third panel discussion, “From Cyber Warfare to Data Protection: Building a Secure Viksit Bharat,” was moderated by Gyana Ranjan Swain, Consulting Editor, VARINDIA. Panellists included Vijay Sethi, Chairman, Mentorkart & Crafsol Technologies; Puneet Kaur Kohli, Chief Technology & Innovation Officer, Generali Central Life Insurance; Arvind Koul, Global Head – Digital & Cybersecurity, Uno Minda; Prof. (Dr.) J S Sodhi, Group Chief Information Officer & Senior Vice President, Amity Education Group; and Sujoy Brahmachari, Chief Information Officer & Chief Information Security Officer, Rosmerta Technology Ltd. The discussion underscored sectoral resilience, board-level cyber accountability and the strategic role of leadership in national cyber preparedness.
ENTERPRISE SECURITY INNOVATION AND INDUSTRY LEADERSHIP
Delivering his corporate presentation, Sandeep Bhambure, VP & MD (India & SAARC) at Veeam Software, underscored the importance of data continuity and resilience. “Backups are not just a compliance checkbox—they are critical to maintaining trust and operational continuity,” he said.
Ayush Mehan, Senior Sales Engineer at ForcePoint, presented insights on insider threats and behavioural analytics. “People often bypass rules unintentionally. Security must anticipate human behaviour, not just system vulnerabilities,” he observed.
Dr. Rajendra Kumar, Group Chief Technology Officer at RAH Infotech, emphasized the importance of end-to-end cybersecurity solutions. “A secure product isn’t complete unless it accounts for real- world threats at scale,” he stated, reinforcing population-scale security as a fundamental design principle.
The evening session formally began with a welcome address by Mohini Ratna, who greeted attendees and set the tone for the concluding segment of the summit. “It’s inspiring to see policymakers, industry leaders, and cybersecurity professionals gathered under one roof. Today’s discussions will not just highlight risks, but also actionable solutions for a secure Digital India,” she remarked.
In his opening address, Dr. Harold Dcosta, President of Cyber Security Corporation, highlighted the evolving threat landscape. “Cyber-attacks are no longer isolated events—they are persistent and adaptive. Organizations must build proactive defenses, not reactive responses,” he emphasized.
Dr. Arindam Sarkar, Chief Architect of FaceOff Technologies Inc., showcased innovative multi-layered threat detection solutions. “Our platform anticipates attacks before they occur by analyzing behavioural patterns across networks. Prevention, not just detection, is the key to resilience,” he explained.
Ankur Patial, Senior Consultant Information & Data Security at Varonis, highlighted the growing importance of access governance in the AI era, stating, “AI tools inherit my access rights. Without proper guardrails, sensitive data can be unintentionally exposed.”
S N Tripathi, Former Secretary, GOI & DG – IIPA, in his keynote speech, stressed citizen-centric cybersecurity and the need for trust in digital governance, asserting, “More data means more vulnerability, more fear, and more suspicion… unless I prove that you are not you, no data is secure.”
INDUSTRY EXCELLENCE RECOGNISED AT OEM AWARDS CEREMONY
The summit culminated in an OEM Awards Ceremony recognizing excellence in cybersecurity, data protection and privacy innovation. The winners were announced across key categories:
Best Company into Cloud Security Solution – Qualys Security Techservices Pvt. Ltd.;
Best Data Loss Prevention (DLP) Product – ForcePoint Software Consulting India Pvt. Ltd.;
Best Unified Endpoint Management – ManageEngine (Zoho Corporation);
Best Threat Intelligence Platform – Cyble Solutions Pvt. Ltd.;
Best SD-WAN Solution Provider – Fortinet Technologies India Pvt. Ltd.;
Best Unified Endpoint Management – SOTI India Pvt. Ltd.;
Best Company into Network Security – Cisco Systems India Pvt. Ltd.;
Best Company into Data Security – Varonis Systems Inc.;
Best Company into Data Privacy – Data Safeguard India Pvt. Ltd.; and
Best Company into IT & OT Security – Check Point Software Technologies India Pvt. Ltd.
The formal proceedings concluded with the Vote of Thanks delivered by Mohini Ratna, followed by networking and a cocktail dinner, marking the close of the event.
As India accelerates toward a digitally empowered future, the 10th Cyber & Data Security Summit 2026 demonstrated that cybersecurity now firmly sits at the intersection of governance, enterprise strategy and national resilience—signalling a decisive shift from managing data to defending it.
------------------------------------------------------------------------------------------------------------------------------------------------------
India should place equal emphasis on building and sustaining public trust on AI
PADMA JAISWAL, IAS,
SECRETARY, GNCTD - GOVT. OF DELHI
“Over the past decade, the government has actively advanced e-governance and driven digital transformation in public service delivery. This shift has led to the significant accumulation of data within government systems. At the same time, the country has developed extensive digital public infrastructure, including platforms such as Aadhaar, DigiLocker, and Unified Payments Interface (UPI), along with supporting digital networks. The rollout and widespread adoption of this digital public infrastructure have positioned the nation where it now engages in substantial discussions around artificial intelligence. Globally as well, the country has already gained considerable traction and recognition in the AI space. We often speak about the scale and speed of AI, and we are understandably impressed by how rapidly it is transforming service delivery and enabling better outcomes for citizens. But are we giving equal attention to trust? Are we considering the level of confidence citizens place in these AI-driven systems? Numerous incidents have occurred where malicious actors misused technology, leading to phishing attacks, ransomware incidents, and other forms of cybercrime. Such events have gradually eroded trust in digital networks and in the systems operated by both government and the private sector.
Amid all these things, the government has introduced the DPDP Act. It is also discussing sovereign AI. When discussing sovereign AI, we are talking about data ownership—the data for which I am the Principal and for which I am responsible. I will know how to manage it and I will be the one to give permission to the person holding my data in a fiduciary capacity, or for that matter, determine how long they can keep this data.”
----------------------------------------------------------------------------------------------------------------------------------------------
We must build cyber-safe citizens through trust, privacy, and security
S N TRIPATHI
FORMER SECRETARY, GOI, & DG – IIPA
“I am one of those who believe that data privacy and security are part of the techno-legal framework India is now building. Some organizations assume the government will make a law, or technology like Varonis or FaceOff will secure them, and they can relax. Friends, more data brings more vulnerability, more vulnerability brings more fear, and more fear brings suspicion. No data is truly secure unless proven. Data is used by creators and users, and in between, cyber theft occurs.
Regulation and innovation must go hand in hand. We don’t want European-style overregulation nor the American extreme where innovation is prioritized over security. Local technology companies must be supported to grow and set global standards. Cybersecurity must move from back office to front office, back end to product end. Citizens have a fundamental right to safe cyberspace. Organizations must provide foolproof solutions. If cyber fraud happens in a lax environment, companies must compensate and maintain citizens’ trust. Hit-and-run may work in vehicles, but not in IT. AI is emerging, but intelligence is human. Machines learn only from data and can misinterpret it. Designers and executives must think ahead—make the impossible possible. Buyers must imagine beyond what developers foresee. Only then can we create cyber-safe citizens and secure systems at population scale. Tools like FaceOff help achieve this by enabling trust, accountability, and innovation to coexist in India and globally.”
-------------------------------------------------------------------------------------------------------------------------------------------------
Addressing synthetic fraud has led to a complex and challenging legal landscape
DR. PAWAN DUGGAL
CHAIRMAN- INTERNATIONAL COMMISSION ON CYBER SECURITY LAW
“In today’s world, artificial intelligence, data, and cyber security have become critically important subjects. Just six days before the AI Impact Summit, the Government of India made a significant move by notifying the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026. With these new rules, India signaled its intention to chart its own regulatory path, while also introducing a comparatively soft approach toward the regulation of deepfakes and synthetically generated content. However, challenges remain. The rules, which came into effect on 20 February 2026, have already triggered widespread discussion about compliance. The primary concern is the requirement to remove synthetic or fake content within three hours. Service providers are uncertain about how they can realistically meet this tight deadline. From the Indian regulatory perspective, intermediaries are expected to exercise due diligence in fulfilling their legal obligations. Accordingly, they must ensure compliance with the new framework. A significant consequence of non-compliance is the potential loss of statutory safe harbour protections, meaning intermediaries could forfeit their legal immunity.
India’s Information Technology Act, 2000 (IT Act) regulates the use of seven core digital elements: computers, computer systems, computer networks, computer resources, communication devices, as well as data and information in electronic form. However, this 26-year- old legislation was never designed to address artificial intelligence or deepfakes. Technology has evolved so rapidly that today deepfakes can be created using easily accessible, often free, online tools. This technological leap has made it imperative to introduce specific regulations to tackle the growing challenge of synthetic and manipulated data.
The 2024 Pakistan general election had one notable feature—the widespread use of deepfakes. Similarly, the 2024 Indian general election was marked by the significant presence of deepfake content. By 2026, the landscape has changed even more dramatically, turning the issue into an entirely different ball game. As a result, when examining the legal consequences within today’s data ecosystem, one finds themselves confronting a deeply complex and challenging situation. One is expected to jump into molten lava, of trying to protect oneself from the exposure and the heat of molten lava, and also to swim along with the molten lava. That, in a nutshell, encapsulates your current position in the current data ecosystem. It took us a long time in India to come up with a law on data protection. Even today, the data protection law pertaining to protecting my data is still not operational. It comes into operation from 13th November 2026, and final operation from 13th of May 2027.”
-----------------------------------------------------------------------------------------------------------------------------------------------
Resilient data governance and risk control are key to accelerating safe AI at scale
SANDEEP BHAMBURE
VP & MD (INDIA & SAARC), VEEAM SOFTWARE
“AI is in the air, everyone is just talking AI. While nearly 50% of large enterprises already have AI use cases live, what really lacks is corporate governance. That’s why I’m talking about Accelerating Safe AI at Scale. The intent is huge — India Inc. is going to spend $200 billion over the next three years - but there is definitely an execution risk. If organizations can control governance, security, and resilience, AI projects can really be successful.
In the AI era, whatever technologies and solutions were adopted to implement resilience no longer work. Organizations need to look at resilience and security with a completely different lens. The top risks are data privacy, legal compliance, governance capabilities, and the quality, consistency, and observability of data. Most of these risks are data-centric. Observability is critical — you need to know what kind of data is where in your organization, whether it is sensitive, who can access it, how it will be analyzed, and whether you are breaching regulatory compliance like DPDP. As long as these are taken care of, you can have confidence in driving your AI projects. India has the potential to be not just a consumer of AI but also someone who can build its own AI initiatives. Talent is abundant, young professionals are engaging, and many businesses are being started by them. But here comes the AI paradox — the friction between innovation and risk. There is pressure to accelerate AI, but the speed of innovation gets slowed down by the risks associated with AI products.
Safe AI at scale is built on three pillars. First, a resilient data foundation — immutable backups, zero-trust architecture, and multi-cloud protection cannot be afterthoughts. Second, intelligent protection — anomaly detection, behavioural threat monitoring, and AI itself helping uncover threats proactively. Third, responsible and compliant AI — real-time governance, continuous audits, and recoverability of AI workloads. You need to understand your data, secure it for AI, build resilience in your AI infrastructure, and activate your AI agents responsibly. Preparation for DPDP compliance aligns closely with feeding data into AI models. By integrating data resilience, governance, and compliance, enterprises can accelerate AI initiatives while managing risk. If your data is resilient, you can confidently accelerate your AI initiative, knowing your AI is in safe hands.”
----------------------------------------------------------------------------------------------------------------------------------------------
From minimal information, AI systems can infer a person’s preferences and personality traits
ADV. (DR.) PRASHANT MALI, PHD,
CYBER LAW EXPERT- BOMBAY HIGH COURT
“There is an unprecedented wave of AI-driven innovation unfolding today. However, despite the rapid advancements, more than 90% of people still lack a clear understanding of AI’s true capabilities. While nearly 73% of Indian enterprises report adopting AI in some form, many are yet to meaningfully integrate or operationalize it. In effect, several organizations are either in the early adoption stage or simply engaging in conversations about AI without fully leveraging its potential. The AI market in India is projected to reach ₹1.4 lakh crore by 2027, reflecting the immense economic promise of the sector. At the India AI Impact Summit, several leaders described AI as a “five-layered cake,” emphasizing the multiple foundational components required for its development. Data lies at the core of this ecosystem, and India's vast volumes of it make the country an attractive destination for global AI players.
The same dynamic applies to emerging corporates as well. Their data-intensive AI systems rely on collecting, processing, and analyzing massive amounts of personal information. While companies may disclose that they collect a limited number of data points-say, ten fields in a form—the insights derived from those inputs can be far more expansive. From seemingly minimal information, AI systems can infer a person’s preferences, behavior patterns, aspirations, and even personality traits. So the issue is how do we innovate while protecting fundamental privacy rights. When an entity collects personal data, it is generally required to obtain clear, specific, and informed consent from the individual. However, in the context of AI systems, this principle becomes far more complicated. In many cases, individuals may not fully understand what aspects of their data will be processed, how long it will be retained, or how it may be used in future iterations of the system.”
------------------------------------------------------------------------------------------------------------------------------------------------
Compliance is not security, proactive readiness is the only sustainable defence
DR. HAROLD D’COSTA,
PRESIDENT, CYBER SECURITY CORPORATION
“While we speak extensively about data security and defense, the real question is what remedial measures exist from a techno-legal perspective when a breach actually occurs. In India, electronic evidence is still rarely tested decisively in courts, and many breaches pass without legal consequence. Incident response plans often look polished on paper but collapse under real adversary pressure. Organizations remain compliance-driven— focused on satisfying auditors rather than surviving breaches. There are no cyber drills, no tabletop exercises, no stress testing. Teams freeze due to lack of rehearsal, unclear chains of command, and absence of decision authority. Under Section 85 of the Information Technology Act, 2000, directors can be held liable, and under the DPDP Act, penalties may reach ₹250 crore. Yet awareness of these techno-legal implications remains limited.
When breaches occur, panic overrides process—systems are isolated without preserving forensic evidence, PR reacts late, leadership overrides technical judgment, and legal teams stall decisions. Evidence preservation is crucial to identify bad actors and ensure admissibility in court. Incidents must be reported within six hours to CERT-In and within seventy-two hours to the Data Protection Board under DPDP.
Organizations need structured playbooks-clear escalation matrices, defined containment thresholds, independent CISO and DPO roles, measurable KPIs such as mean time to detect and contain, threat intelligence integration, and resilient backup strategies including immutable, isolated storage. Compliance without execution is shelfware. Proactive readiness—not reactive response—is the only sustainable path to cyber- attack mitigation.”
--------------------------------------------------------------------------------------------------------------------------------------------
Cyber-related offences have increasingly become a prominent feature in news coverage
DR. PRONAB MOHANTY, IPS,
DIRECTOR GENERAL OF POLICE, CYBER COMMAND, GOVERNMENT OF KARNATAKA
“We are currently living in what can rightly be described as the age of cyber fraud. The phenomenon of so- called “digital arrests” has become so prevalent that clear guidelines were issued just last month by the Hon’ble Supreme Court. Beyond this, numerous other forms of cyber fraud are causing losses amounting to tens of thousands of crores every year. A striking feature of today’s cyber fraud landscape is the profile of those most frequently targeted: the middle class—salaried individuals, retirees, and young earners with disposable income. This marks a distinct shift in how fraud schemes are designed and executed.
Another emerging dimension is the use of AI- and machine learning-enabled tools—such as deepfakes and voice cloning—which have significantly enhanced the sophistication and believability of fraudulent schemes. This represents a new and troubling chapter in the evolution of cybercrime. It is important to stress that cybercrime is not limited to attacks involving technology products alone. In recent years, cyber- related offences have increasingly dominated headlines. Security professionals and cybercrime investigators typically classify cybercrimes into three broad categories. The first category comprises cyber frauds, which are rapidly proliferating. The second includes crimes against women and children, particularly the circulation of online Child Sexual Abuse Material—an issue of grave concern for society at large. The third encompasses what are often described as conventional cybercrimes, such as phishing schemes, hacking, data theft, identity theft, credit card fraud, ransomware attacks, and distributed denial-of-service (DDoS) attacks. These crimes have been around for a long time, but they have been relegated to the background, thanks to the proliferation of all other sophisticated cyber frauds.”
----------------------------------------------------------------------------------------------------------------------------------------------
Role of vulnerability management as a core component has grown both in scope and impact
ANKIT WASNIK
LEAD SECURITY SOLUTIONS ARCHITECT, QUALYS
“There is a well-known observation by Peter Drucker that you cannot manage what you cannot measure. In today’s context, that idea goes even further: you cannot measure what you cannot see, and you cannot secure what you cannot manage. This has become especially relevant as organizational attack surfaces expand at an unprecedented pace. A few years ago, when defining an enterprise asset, the answer was relatively straightforward-servers, network devices, and endpoints. Today, that definition has broadened significantly. Organizations operate across multiple infrastructure layers and technologies. Large language models (LLMs) introduce their own unique attack surfaces. Cloud environments come with distinct exposure points. Containers, Docker, Kubernetes clusters, digital certificates-each of these components represents an independent attack surface that must be monitored and protected.
To address this growing complexity, organizations deploy numerous security solutions. On average, enterprises now use more than 30 different security tools to safeguard their infrastructure. However, this creates another challenge: each tool measures risk differently. Some assess risk on a scale of 1 to 10, others 1 to 100, and still others 1 to 1000. There is no standardized framework for risk measurement, resulting in fragmented visibility and inconsistent prioritization. At the same time, the role of vulnerability management within overall risk management has evolved dramatically. The days of conducting vulnerability scans once a year—or even once a quarter—are long gone. Today, many organizations perform vulnerability scanning on a near real-time basis. Consequently, vulnerability management programs must mature and adapt at the same pace as the threat landscape. The scale of the challenge is evident in recent data. In 2024 alone, more than 40,000 vulnerabilities were disclosed.
Approximately 39% of these had publicly known exploit exposures worldwide, and over 78% were categorized as high or critical severity. Attempting to remediate every single vulnerability is an overwhelming task. The sheer volume makes it impractical for any organization to address all of them simultaneously, underscoring the need for intelligent prioritization and risk-based remediation strategies.
So what is the current state of cyber security risk management? We have 30 different tools, 30 different dashboards, 30 different reports and 30 different ways to measure this risk. There is no centralized SPM (Security Posture Management). That is where the concept of Risk Operation Center (ROC) comes into play, which is basically where all your SPM data are combined into a unified orchestration solution. Now we all might have heard of the term SOC (Security Operation Center) that most of the organizations deploy. SOC is something where you feed data from all the various tools that you have deployed in the company - be it your firewall, your Active Directory, or your network devices. When something goes wrong, or when an incident happens in the organization, you look at the SOC data to do a post mortem analysis and identify what has gone wrong.”
-----------------------------------------------------------------------------------------------------------------------------------------------
Enterprises must shift from threat- centric to data-centric security
ANKUR PATIAL
SR. CONSULTANT INFORMATION & DATA SECURITY, VARONIS
“You see, in the last 5–10 years, organizations have onboarded multiple technologies, but the question is—are breaches really being stopped? If you look at last year, a couple of big customers got compromised—Uber, MGM—and it’s not because of lack of technology. The issue is that attackers are innovating faster than traditional defenses. Firewalls, DLPs, EDRs— they know what malware is, they know what threats are, but they don’t understand your data, your crown jewels. Most breaches occur due to credential compromise—86% of attacks, according to reports. Once an attacker has your credentials, logging in triggers no alarms from these systems. Combine that with a growing blast radius—cloud adoption, collaboration platforms, sharing files openly-and exposure multiplies. AI tools, like Microsoft Copilot or ChatGPT, inherit user access rights, surfacing data across this blast radius, often without anyone realizing the risk.
Our approach at Varonis is data-centric and automation-driven. First, we give visibility—organizations need to know where their data lives, whether on-prem, in the cloud, or in third-party SaaS applications, and identify overexposed content. Second, we fix risks automatically. For example, if a folder has 2,000 people with access but only five actively use it, our platform can revoke the excess permissions automatically. We also classify and label sensitive data in line with DPDP and Microsoft Information Protection, ensuring that files retain their classification wherever they go. Stale data is another major risk-files untouched for years often contain confidential information. We automate lifecycle management, moving or deleting old files securely, which can mitigate over 80% of risk with minimal manual effort.
Finally, continuous monitoring is key. We build behavioural baselines for users and detect anomalies, misbehaviour, or suspicious activity in real time. Business email compromise, password spray attempts, and insider threats are all detected before they escalate. Our MDR team investigates and fixes these risks immediately. We also provide access governance automation, so data owners can approve or revoke access quickly, ensuring policies are always enforced. Everything we do-from discovery, classification, remediation, to monitoring-is automated and auditable. We work hand-in-hand with customers, providing TAM support to ensure deployments succeed and ROI is realized. For organizations looking to understand their data health, we even offer a free Data Risk Assessment, helping them see and secure their environment proactively.”
-----------------------------------------------------------------------------------------------------------------------------------------------
TP-Link committed to shaping the next era of connectivity
SUMITH SATHEESAN
HEAD – ENTERPRISE SOLUTION CONSULTING, TP-LINK
“TP-Link is a global innovator and provider of consumer and SMB networking products and the world's No.1 provider of WLAN and broadband CPE devices*, with products available in over 170 countries to tens of millions of customers. Omada” represents our enterprise networking portfolio, and the word itself means “team.” The idea behind the name reflects the concept of software-defined networking-where every networking component works together seamlessly. Whether it is wired data networks, wireless infrastructure, switches, routers, or gateways, all elements can be centrally managed through a single unified dashboard. One of TP-Link’s strongest endorsements is its consistent recognition in Gartner’s Magic Quadrant for seven consecutive years. This reflects both the completeness of our vision and the maturity of our enterprise-ready solutions, as well as our sustained market growth. TP-Link has been operating in the enterprise segment for over a decade, steadily expanding its footprint.
Our current Omada portfolio includes both cloud-based controllers and software controllers. These controllers do more than simply manage network components—they also incorporate advanced capabilities, including AI-driven features. We offer a comprehensive range of access points, including ceiling-mounted, wall-plate, and outdoor models, and we have recently expanded into fiber and GPON access points as well. On the switching side, our portfolio has advanced significantly-we now support speeds up to 100G, a substantial leap from the 20G capacity we offered as recently as last year.
Nowadays we also talk about high-density access points. So in a big conference hall, where many people are connected to a single device, that device can cater to all the users. So that is a high density access point. TP-Link is also the first to get WiFi 7 routers. While WiFi 6 was built in response to the growing number of devices in the world, WiFi 7's goal is to deliver astounding speeds for every device with greater efficiency. In India, the 6 GHz band was not allowed as the government wanted to control it as a spectrum. In January 2026, India's Department of Telecommunications officially de-licensed the lower 6 GHz band (MHz) for indoor and low-power outdoor Wi-Fi 6E and Wi- Fi 7 use. So by the end of February, we will receive the first lot of Wi-Fi 7, which will have the higher band disabled for the 6 GHz band and the lower band enabled. Through ongoing collaboration with ecosystem partners, TP-Link is dedicated to advancing the technologies that will shape the next era of connectivity, offering users unprecedented speed, stability and reliability.”
--------------------------------------------------------------------------------------------------------------------------------------------
Enterprises must build sovereign and resilient data security architectures
DR. RAJENDRA KUMAR
GROUP CTO, RAH INFOTECH
“When we talk about sovereign cloud or sovereign infrastructure, at RAH Infotech we call it the ‘Sovereign Shield’ — a bundled security architecture designed to create resilience for today’s borderless enterprises. Over the past two decades in cybersecurity, one thing has become very clear — infrastructure today has multiple blind spots, especially with the way data moves across hybrid and multi-cloud environments. With regulatory shifts like the DPDP Act 2023, this is no longer just a technology concern; it’s a governance shift. DPDP is data-centric — it touches HR data, processor data, customer data, strategic business information — everything. The challenge is that data travels in ways organizations often don’t see. Replication, multi- region SLAs, SaaS backends - these create invisible data flows that sometimes cross borders without enterprises even realizing it. That is where geo-fencing, consent control, cross-border transfer validation, and vendor assurances become absolutely critical.
When we look at compliance, there is often a gap between what is written in policy and what is happening operationally. Consent misuse, broken data lifecycles, improper retention, unverified third-party processors - these are real risk areas under DPDP. At RAH Infotech, we address this through a structured operational framework backed by our managed SOC services. We operate a full-fledged SOC in Delhi, certified under SOC 2 Type 2, PCI DSS, ISO 27001 and 27701. Our focus is unified visibility - correlating anomaly data across endpoints, networks, gateways, and cloud layers. We ensure real-time contextual detection, automated orchestration, proactive isolation of compromised hosts, and 24/7 incident triage and response. We also leverage AI-driven efficiencies to reduce MTTR and operational overhead while delivering customized executive reporting aligned to CISO priorities.
Beyond monitoring, we emphasize data security hardening and closing the gap between detection and remediation. That includes forensic root cause analysis, structured playbooks, expert-led incident response, and attack simulation labs to ensure IR readiness. We build internal data lakes, machine learning models, and threat intelligence capabilities to deliver predictive insights, not just reactive alerts. For us, compliance should not be viewed as a regulatory burden; it should be treated as a business catalyst. We are a solution-driven organization — architecture and outcomes come first, and products follow customer requirements. The objective is to help enterprises build sovereign, compliant, and resilient data security ecosystems.”
--------------------------------------------------------------------------------------------------------------------------------------------------
Digital trust must be engineered, not assumed in the age of deepfakes
DR. ARINDAM SARKAR
CHIEF ARCHITECT, FACEOFF TECHNOLOGIES INC.
“Defending against deepfakes and synthetic identity fraud begins with confronting a difficult reality: most enterprise AI systems fail because they are not architected with privacy by design. Privacy today is not about concealing data; it is about embedding trust mathematically and structurally into digital systems. When organizations deploy AI without integrating differential privacy, tokenization, anonymization, secure multi-party computation, and edge-native controls, they create invisible vulnerabilities. As quantum computing advances, the risk multiplies. Encryption standards such as RSA and ECC, which underpin global digital infrastructure, will gradually weaken. The ‘harvest now, decrypt later’ model is already a strategic threat, making post-quantum cryptography an urgent requirement rather than a theoretical upgrade.
At FaceOff, our approach to digital trust is engineering-led and evidence-driven. Through our Adaptive Cognito Engine, we combine multimodal behavioural biometrics, contextual intelligence, federated privacy frameworks, and quantum-safe cryptographic standards including CRYSTALS-Kyber and CRYSTALS-Dilithium. We have introduced adaptive neural cryptography that dynamically adjusts encryption strength depending on attacker capability and computational risk. Our Deepfake Finder platform performs granular frame- by-frame video inspection, GAN fingerprint tracing, spatial and frequency domain forensics, temporal anomaly detection, and voice inconsistency analysis. We believe security systems must be explainable. That is why we follow a glass-box AI model where every decision is auditable, traceable, and supported by intermediate forensic evidence rather than opaque algorithmic outputs.
With evolving IT regulations mandating the labelling of AI-generated media and strict compliance timelines for takedown, detection must be precise, transparent, and fast. Our verification engine evaluates 468 facial parameters, identifies forged identity artifacts, measures physiological indicators such as heart rate and oxygen saturation through standard cameras, and strengthens digital onboarding and payment authentication using behavioural biometrics. We also enable encrypted machine learning so sensitive information can be processed without exposing plaintext. The future of cybersecurity lies in responsible AI, quantum resilience, and privacy-enhancing computation. Digital trust must be proactive, adaptive, and cryptographically prepared for the challenges of tomorrow.”
---------------------------------------------------------------------------------------------------------------------------------------------------
Protecting data is the key to safe and scalable AI adoption
AYUSH MEHAN
SENIOR SALES ENGINEER, FORCEPOINT
“AI is everywhere today — everyone is talking about AI. But at its core, AI relies on the data going into it. If sensitive data is being processed, it matters immensely for the organization. The question is, how do we protect this data in an AI-driven world? The environment has shifted from traditional on-premises infrastructure to a hybrid model, where sensitive information moves to SharePoint, SaaS drives, and multi-cloud platforms. Organizations are not just adopting AI applications; they are building AI into existing systems, using public AI models, and developing their own AI on top, including LLMs and copilots. With this, challenges multiply: data sprawl, regulatory pressures such as DPDP, security fatigue from managing multiple cybersecurity tools, and insider risks. Identifying potentially risky users before breaches occur is critical, because traditional approaches to resilience and security no longer suffice.
At ForcePoint, we address this with a unified data security approach. First, we discover where sensitive data resides - on-prem, in the cloud, or on BYOD devices. Next, we classify and label it, prioritize its business value, and remediate by enforcing proper permissions. Once this data hygiene is in place, protection layers ensure that sensitive information is not misused or exfiltrated. Continuous monitoring tracks behavioural deviations over time, escalating risk scores proactively. When adopting AI, proper guardrails are essential. Enterprises must determine what data can safely be ingested, what is restricted, and how AI interacts with it responsibly. Our patented SLM models analyze datasets, generate persistent labels, and ensure data remains secure as it moves across systems. For example, we can prevent sensitive information from being uploaded to AI tools like ChatGPT, or revoke access in real time if risky prompts are detected.
By integrating discovery, classification, remediation, protection, and AI governance, enterprises can safely accelerate AI initiatives. It’s not just about visibility; it’s about control, resilience, and compliance. Organizations can leverage AI effectively while mitigating insider risks, regulatory exposure, and potential data breaches. With proper security measures and AI-specific guardrails in place, AI adoption can be fast, safe, and reliable, enabling businesses to realize real value without creating new vulnerabilities.”
-----------------------------------------------------------------------------------------------------------------------------------------------
AI is not optional anymore, it is strategic
PANKAJ MITTAL
FOUNDER & CEO, DIGIZEN CONSULTING
“AI is the new buzzword, but let’s be clear — much of this isn’t entirely new. We’ve already lived through digital transformation, automation, RPA and intelligent automation. What we now call agentic AI, generative AI, ChatGPT and Copilot is an evolution of that journey. The real shift is in predictive capability — not just learning from historical data, but responding to configurable parameters and delivering intelligent outcomes. The AI stack today spans infrastructure, foundation models and the interface layer, including ChatGPT-style tools, and it is expanding at unprecedented speed.
AI is not a lift-and-shift exercise. It requires root-and-branch changes in architecture, operating models and enterprise thinking. Boards and CXOs are asking the same old question again — build versus buy. Should we develop proprietary models on our own datasets or depend on external vendors? Successful AI implementation demands clarity of outcome, high-quality datasets and a dedicated AI project leader. Capture value, not just usage. Don’t blindly trust AI outputs or assume productivity gains without governance. Collaboration across product, platform, engineering and domain teams is critical before making the AI shift.
AI may disrupt certain jobs, but it is already creating new ones — from data annotation and prompt engineering to AI security and forensic roles. Data is a strategic asset, but without AI-enabled refinement it lacks actionable intelligence. Enterprises must invest in infrastructure, ethical guardrails and regulatory alignment. AI is not optional anymore — it is strategic. Start small, scale fast and think long term.”
-------------------------------------------------------------------------------------------------------------------------------------------------
India is charting a “Third Way” in AI, balancing U.S. innovation and EU regulations
DR. DEEPAK KUMAR SAHU
PUBLISHER, VARINDIA
“New Delhi has momentarily become the epicenter of the global artificial intelligence debate. As the India AI Impact Summit unfolds at Bharat Mandapam, the gathering feels less like a technology exhibition and more like a strategic declaration of intent. The guiding motto, “Sarvajana Hitaya, Sarvajana Sukhaya” (Welfare for All, Happiness for All), underscores India’s view of AI not as elite infrastructure but as public utility.
On January 3, 2025, MeitY unveiled the draft Digital Personal Data Protection Rules, inviting feedback until February 18. With that window closing just two days ago, today—February 20, 2026—will be remembered as a historic day in India’s tech landscape. For the first time, a major AI summit is being hosted in the Global South-symbolically shifting the centre of gravity in global tech governance. With Prime Minister Narendra Modi Ji at the helm, the event projects a confident narrative - the Global South is no longer an observer in the AI revolution—it is shaping its direction.
India is charting a “Third Way” in AI—balancing U.S. innovation and EU regulation—advocating inclusive, accountable scale. Viewing compute and data as global public goods, India positions AI as central to governance, growth, and national competitiveness. Friends, we are thriving in the era of agentic AI, digital resilience goes far beyond uptime or recovery. It demands the ability to manage dynamic environments and govern autonomous systems that continuously make and act on independent decisions. The interesting change is quietly visible - the hyperscaler grip is being challenged. In 2025, global AI infrastructure commitments are projected to reach $616 billion—with hyperscalers such as Amazon Web Services, Google, Meta and Microsoft accounting for about $361 billion, while neocloud providers are set to deploy $181 billion, and sovereign AI initiatives add another $75 billion. Platforms from OpenAI, Google’s Gemini, Microsoft, Perplexity AI, DeepSeek and Anthropic are rapidly redefining how people search, write, code, analyze and automate.
India has emerged as a global digital powerhouse, with nearly one billion internet users and the distinction of being the world’s largest mobile data consumer. Affordable data and reliable connectivity extend seamlessly from major cities to the remotest villages. Aadhaar, covering over 1.4 billion people, powers inclusive digital identity, while UPI processes more than 12 billion transactions monthly. Ranked among the top startup ecosystems, India’s Digital Public Infrastructure now serves as a trusted global model.”
------------------------------------------------------------------------------------------------------------------------------------------------
AI is now the first line of defence in India’s digital transformation
S. MOHINI RATNA
EDITOR, VARINDIA
“The 10th Edition of the Cyber & Data Security Summit marked a defining moment in India’s digital security journey. Within that larger vision, the Global AI Impact Summit reinforced that AI is no longer just technology—it has evolved into a new intelligence layer that enables systems to learn, think, and act autonomously. Its rapid rise reflects a global movement driven by collaboration and partnerships, with India uniquely positioned as a bridge between the Global South and the Global North in shaping inclusive innovation. AI has now become the first line of defence. As spam, fraud, and digital impersonation surge, telecom operators are deploying AI-driven network systems that detect and block threats in near real time. At the same time, enterprises face AI-driven hardware shortages, cloud dependence, latency realities, and growing data sovereignty demands. Cybersecurity has entered the era of machine-speed threats, compelling organizations to move from traditional detect-and-respond models to prevention-first strategies anchored in deep visibility, automation, and platform-led security architectures.
With the rollout of the DPDP Act, compliance must go beyond surface-level consent toward operational data visibility and governance reform. The sharp rise in deepfakes and synthetic media further underscores the urgency for AI-powered forensics and end-to-end AI capabilities across discovery, threat detection, attack detection, and risk monitoring. The path forward demands collaboration, vigilance, and trust to build sovereign, resilient, and accountable digital ecosystems for a future-ready India.”
--------------------------------------------------------------------------------------------------------------------------------------------------------
AWARD WINNERS IN 10TH CDS 2026

| CATEGORIES | COMPANY |
| BEST COMPANY INTO CLOUD SECURITY SOLUTION | QUALYS SECURITY TECHSERVICES PVT. LTD. |
| BEST DATA LOSS PREVENTION (DLP) PRODUCT | FORCEPOINT SOFTWARE CONSULTING INDIA PVT. LTD. |
| BEST UNIFIED ENDPOINT MANAGEMENT | MANAGEENGINE (ZOHO CORPORATION) |
| BEST THREAT INTELLIGENCE PLATFORM | CYBLE SOLUTIONS PVT. LTD. |
| BEST SD-WAN SOLUTION PROVIDER | FORTINET TECHNOLOGIES INDIA PVT. LTD. |
| BEST UNIFIED ENDPOINT MANAGEMENT | SOTI INDIA PVT. LTD. |
| BEST COMPANY INTO NETWORK SECURITY | CISCO SYSTEMS INDIA PVT. LTD. |
| BEST COMPANY INTO DATA SECURITY | VARONIS SYSTEMS INC. |
| BEST COMPANY INTO DATA PRIVACY | DATA SAFEGUARD INDIA PVT. LTD. |
| BEST COMPANY INTO IT & OT SECURITY | CHECK POINT SOFTWARE TECHNOLOGIES INDIA PVT. LTD. |
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.
