The first panel discussion, “Securing India’s Digital Future: From Risk to Resilience,” moderated by Dr. Sahu, featured Maj General (Dr.) Dilawar Singh, Independent Director, Transrail Lightening Ltd.; Deepti Bhatia, CIPP/E, Chair – IAPP New Delhi Chapter; Sarita Padmini, Senior Director, Protiviti; Dr. Harsha Thennarasu (CERT-In Auditor), Chief Cyber Defence Advisor – HKIT Cyber Security Solutions; and Vishal R Soni, Strategic Advisor – Consulting Practice. The discussion focused on strengthening cyber hygiene at scale, building resilient systems and embedding security within organizational DNA.
On how businesses are getting ready for trusted digital identity, Sarita Padmini, Senior Director, Protiviti cited the example of how AI uncovered Rs 70,000 crore tax evasion scam starting with Hyderabad biryani chains. “When AI systems were introduced into monitoring frameworks, they were able to analyse patterns and uncover large-scale scams that had previously gone undetected. I have spoken with several solution providers who say they are ready to implement passwordless authentication.
But the real question is: how many organisations in our country are actually adopting such solutions? In my view, nearly 98% of systems still rely on traditional KYC processes and OTP-based authentication. This highlights a broader issue—we are not yet fully AI- ready as a nation. That readiness must be built urgently, especially as AI-driven threats continue to escalate. To counter increasingly sophisticated attacks, we need to develop and deploy AI-enabled defence mechanisms. At present, however, we are significantly behind where we need to be.”

L to R: Vishal R Soni, Strategic Advisor – Consulting Practice; Dr. Harsha Thennarasu (CERT-In Auditor), Chief Cyber Defence Advisor – HKIT Cyber Security Solutions; Maj General (Dr.) Dilawar Singh, Independent Director, Transrail Lightening Ltd; Sarita Padmini, Senior Director, Protiviti; Deepti Bhatia, CIPP/E, Chair – IAPP New Delhi Chapter and Dr. Sahu, Publisher, VARINDIA
Sharing her views, Deepti Bhatia, CIPP/E, Chair – IAPP New Delhi Chapter said, “My banking journey began with traditional KYC. Over time, we moved to e-KYC and then to video KYC. However, the legal and regulatory frameworks have not evolved at the same pace, and cybercriminals have exploited these gaps.
With the rise of AI-driven deepfakes, it is now essential to upgrade our technological capabilities to detect manipulated videos and impersonation attempts. Video KYC alone is no longer sufficient. We must invest in advanced defence technologies that enable real-time identification and robust biometric verification. Equally important is educating and empowering frontline personnel who operate these systems, ensuring they understand both the technology and the associated risks. While video KYC has gained traction in the fintech ecosystem, its adoption remains limited. In many Tier 2 and Tier 3 regions, paper-based KYC processes are still prevalent, and fraud levels in these areas continue to rise.”
Maj General (Dr.) Dilawar Singh, Independent Director, Transrail Lightening Ltd. stated that we are soon moving to video KYC to other biometric KYCs also. “There is a pressing need for a holistic and up-to- date KYC framework—one that goes beyond AI alone and integrates multiple advanced technologies. The system must be dynamic, adaptive, and continuously evolving, rather than static or one-dimensional. A wide range of solutions has already emerged in this space. For instance, FaceOff, developed by Dr. Deepak Sahu, is one such innovation. When I recently attempted to port my number from Vi to Airtel due to service issues, the executive recorded six separate videos of me, capturing different facial movements each time. While this represents a certain level of verification, it is still only one layer of authentication. Today, we are seeing the development of edge- based KYC, biometric verification, advanced facial recognition, and even dynamic QR code-based validation mechanisms. The real need of the hour is to integrate these various tools into a comprehensive, layered system. By combining multiple technologies into a unified and intelligent framework, we can better address the increasingly sophisticated frauds we are witnessing.”
Dr. Harsha Thennarasu (CERT-In Auditor), Chief Cyber Defence Advisor – HKIT Cyber Security Solutions cited one of the projects that he was auditing. “If you examine the technical architecture of that project, the front end is managed by the state governments, while the back end is controlled at the Union level. Each state relies largely on open-source systems and customizes the front end according to its own approach. This decentralized model creates a significant security risk. In my view, such a system should be far more centralized; otherwise, the digital identity of every Indian citizen could be exposed to serious threats. During my review, I also observed that several states are still operating on outdated technologies. On one hand, we speak about moving at “missile speed” in AI adoption, but on the other, legacy systems continue to be widely used. I have even come across government departments still running on Windows 7. Identifying and documenting these critical vulnerabilities became an important part of my audit findings.”
Vishal R Soni, Strategic Advisor – Consulting Practice suggested, “Drawing from my two decades of experience with two of the world’s largest organisations, there is one critical question we must confront. If you lose the key to your house, you can simply replace it. But if your biometric data-your fingerprint or facial scan-is compromised, can you replace that? As an economy built significantly around Aadhaar, with biometrics placed at the core of identity verification, does this not create a profound long-term risk? Today, vast amounts of personal data are being collected and stored. The real concern is not only the present, but the future—particularly when quantum computing becomes fully mature in the coming years and has the potential to break current cryptographic safeguards. As Benjamin Franklin famously said, “If you fail to plan, you are planning to fail.” We must therefore design and strengthen an ecosystem that is resilient not just for today’s threats, but for tomorrow’s vulnerabilities—especially in a post-quantum world.”
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.
