Sign in to view Indus’ full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Indus’ full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
San Francisco Bay Area
Sign in to view Indus’ full profile
Indus can introduce you to 10+ people at Redblock
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
28K followers
500+ connections
Sign in to view Indus’ full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Indus
Indus can introduce you to 10+ people at Redblock
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Indus
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Indus’ full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Articles by Indus
-
Why Identity Has a Machine Now
Why Identity Has a Machine Now
If you walk into almost any enterprise today, identity security still runs on tickets and spreadsheets. Not because the…
25
4 Comments -
AGI and Identity Security: Why “Figure Things Out” Isn’t EnoughJan 27, 2026
AGI and Identity Security: Why “Figure Things Out” Isn’t Enough
Sequoia’s Pat Grady and Sonya Huang recently offered a clean functional definition: AGI is the ability to figure things…
14
-
Identity’s Real Problem Isn’t Tools. It’s the Semi-Async Middle Layer.Dec 6, 2025
Identity’s Real Problem Isn’t Tools. It’s the Semi-Async Middle Layer.
Every year, identity gets more tools, more standards, more “platforms,” more pretty diagrams. And yet, inside most…
24
2 Comments -
The Rise of Open Source LLMs: A Trip Down Memory Lane of Open Source WebserversMar 28, 2023
The Rise of Open Source LLMs: A Trip Down Memory Lane of Open Source Webservers
Elad Gil asked the question of open source LLMs (and indirectly, the destiny of commercial LLMs). The answer lies in…
31
2 Comments -
What does a great board look like for a tech startup?Oct 16, 2018
What does a great board look like for a tech startup?
Building a startup is an iterative, learning process, sprinkled with feedback from people who have a perspective on…
66
3 Comments -
Always close loop — Irrespective of the outcomeOct 3, 2017
Always close loop — Irrespective of the outcome
In summer of 2010, Sameer, Nandini and I, along with Shashank, and Abhinav caught up and mulled Practo’s seed round…
48
5 Comments -
Error Log — Decision Journal for exceptionsSep 28, 2017
Error Log — Decision Journal for exceptions
I started reading Ray Dalio’s new book Principles, where he beautifully chronicles his work, life, his decision making…
14
-
Internal scorecard of a ProductJun 5, 2017
Internal scorecard of a Product
A product’s success hinges on both, the happy engineers who write code, and the customers whose one or more pain points…
70
3 Comments -
Systems of Intelligence--The new enterprise software moatApr 26, 2017
Systems of Intelligence--The new enterprise software moat
Jerry Chen of Greylock wrote a fantastic piece on moats. He gave a refresher on traditional defensible moats used by…
16
-
SaaS: Where are you in this 2×2?Mar 16, 2017
SaaS: Where are you in this 2×2?
Some SaaS ventures lead to category leadership while some lead to imaginary frozen quadrants. Here’s a little 2X2 to…
54
12 Comments
Activity
28K followers
-
Indus Khaitan shared thisMaybe security needs worse UX. For years identity has optimized for fewer clicks. - SSO - Passwordless - Seamless access Click here, click there and you get access. This is great for employees and also great for attackers once they convince one employee to click. If the reporting on McKesson is accurate, two employees were voice-phished. Later their IdP identities opened Salesforce and Snowflake, and roughly 1TB of data was exfoliated over four days. We need deliberate friction when blast-radius changes. There should be a category of account that says, “No SSO for you. Run two mikes on a company supplied treadmill before your credentials are accepted.” And lastly how does 1TB leave without someone noticing? APIs have failed us and this topic doesn’t get any love when you submit a session at industry conferences. I feel that as an industry we disproportionately spend time on shiny objects, a la AI Security, while ignoring the basics. PS> If you are at Identity Week in DC in the next few days, hmu to riff on the politics of SSO. Puneet Bhatnagar Steve Zalewski Suresh Batchu
-
Indus Khaitan shared thisMore than a decade living in America, and I have somehow never been to Washington DC. That changes next week. I’ll be there for IdentityWeek. Outside the conference, my ambitions are modest: - See the Capitol - Sit at the Lincoln Memorial late at night - Get lost in one Smithsonian Walk around a city I’ve mostly known through history books, action movies, and news. Looking forward to this bigly.
-
Indus Khaitan shared thisI don't think you can separate the agent from the harness yet. Most open source agent harnesses I investigated are basically building the walls of the barrel. Sandboxing, permissions, tool allowlists, and maybe kill switches. All useful, but that is containment. It keeps the motorcycle or the Maruti 800 DX inside the barrel. It does not keep them from falling off the wall. I grew up seeing the Well of Death during Durga Puja. The annual festivities build out would start just around this time. Back then I was mostly wondering how the guy did not fall off. More than just physics, that is also a useful question for agent systems. The harder problem is execution reliability. State, retries, validation, idempotency, recovery, aborts, evidence. Those have to be designed with the agent because the system needs to understand what the agent is trying to do, what state it is in, and what success or failure actually means. It is a bit like saying transaction processing can be completely separated from the database and some external layer will guarantee ACID. You cannot put a transaction manager in front of an arbitrary database and suddenly get ACID. The database itself has to implement the primitives for commit, rollback, isolation, recovery, etc. Agents are still figuring out the equivalent primitives. We haven't even agreed on what BEGIN, COMMIT, ROLLBACK, and ABORT mean for an agent. We are in the very early innings of figuring this out. PS> If you are building an agent harness and disagree with me, I’d love to partner. Let’s see how much of the Redblock agent runtime we can actually externalize.
-
Indus Khaitan shared thisI hope AI fastracks the path towards AGI so I no longer need to drive on the expensive roads of the Bay Area. I can live in the Sierra foothills on a patch of land, power a flour mill with the kinetic energy of a stream, grow my own food, and have a few AI agents deal with civilization on my behalf. Maybe the ultimate promise of technology is not abundance. Maybe it is finally earning the right to opt out. No commute. No toll lanes. No badge swipes. No Calendly to give out. Just me, the stream, and an autonomous agent periodically explaining to DMV that yes, I am still alive. And maybe 2,000 feet of grass to land a 172 when the stream gets boring. We spent a trillion dollars building artificial intelligence so all of us could eventually return to the 1800s.
-
Indus Khaitan shared thisWhen I was learning to fly, flying from Livermore Airport to the Sausalito VOR and back was a favorite route with views of Golden Gate Bridge. I flew visually and did not file a flight plan. My flight instructor and I were the only ones that knew where I intended to go. The aviation system could observe our state, but not our intent. That old flight is how I think about intent-based security for AI agents today: directionally right, but not mature yet. Modern commercial aviation has evolved and externalizes both intent & state. A flight plan states where an aircraft intends to go. ADS-B Out continuously broadcasts its identity, position, and altitude. But, AI agents do not yet have the equivalent of a standardized flight plan. Their intent remains buried across API triggers, prompts, context, memory, policies, and a plan that can change during execution.
-
Indus Khaitan reposted thisManaging access across apps that don't integrate with standard IAM stacks is a pain point almost every enterprise faces. Love seeing how Redblock is tackling this problem head-on with AI execution. Come and meet the team onsite at Identity Week America - Stand S32 - September 2-3, 2026, Washington D.C.! Are you building something innovative in the identity space? Drop me a PM to find out more about getting involved in our Start-Up CityIndus Khaitan reposted thisWe're excited to welcome Redblock to Identity Week America 2026. Redblock is a cybersecurity company using Agentic AI to secure the 80–90% of business applications that sit outside traditional IAM coverage. Their platform automates complex identity decisions - such as Joiner-Mover-Leaver updates, access provisioning, and entitlement aggregation - directly inside legacy, disconnected, or custom apps. Designed to close the "last-mile" identity gap without requiring multi-year custom connector projects, Redblock eliminates the need for manual tickets and spreadsheets, helping organizations instantly remove access and halt entitlement creep. Meet the team in the start-up city at Stand S32 at Identity Week America 2026 and discover how they're bringing continuous, automated governance to the entire application estate. Get your pass now: https://lnkd.in/eEcCMN-j #IdentityWeekAmerica #StartUpCity #IAM #IdentitySecurity #AgenticAI #IdentityGovernance #Cybersecurity #Innovation
-
Indus Khaitan reposted thisIndus Khaitan reposted thisBlackhat wraps today. I went back through the Briefings agenda looking for identity security and came up nearly empty. Indus Khaitan flagged the same gap, and once you both notice it independently, it stops looking like a coincidence. AI dominated almost every track, autonomous fuzzing, LLM exploit agents, agentic offense. Identity got a passing mention here and there. No track. No real weight in the program. I don't think that's an oversight, and honestly I think it's a mistake the industry keeps making. Briefings reward a good zero-day. Identity misconfiguration doesn't produce one. It produces something slower and more dangerous: standing access nobody remembers granting, service accounts that outlived the project they were built for, permissions piling up quietly until the day they're the reason a breach went from "contained" to "catastrophic." That's not a research paper. That's just Tuesday in most enterprise environments, and it's exactly why most breaches that make headlines had a boring identity failure sitting underneath the exciting exploit everyone wrote about. Here's the part nobody wants to say out loud: SOCs aren't failing because they lack tooling or headcount. They're failing because the denominator keeps growing. Every standing entitlement, every unused permission, every identity nobody's revisited since onboarding adds to the pile of things worth watching. You cannot hire your way out of a denominator problem. And every session on that same agenda about agentic AI is about to make the denominator problem exponentially worse. Every agent spun up gets an identity. Every agent that calls another agent creates a permission relationship nobody provisioned by hand and nobody's reviewing on a quarterly cycle. A human joins a company once and leaves once. An agent can be instantiated a thousand times a day, each instance inheriting scopes, each one a new line item in the denominator, and most of them will outlive whatever task justified creating them. The math that already didn't work for human identity governance is about to run at machine speed. That's not a future risk. That's the actual subject of half the talks on this agenda, and almost none of them are naming it as an identity problem. The only lever that scales is shrinking the denominator itself, collapsing blast radius by tying access to real-time context instead of a provisioning decision made eight months ago and never revisited. That's true for humans. It's non-negotiable for agents. This is the exact gap ACP was built to close. Identity, permission, intent, and context aren't four bolted-together controls, they're one authority decision, made well or made badly. A5 of the series drops soon, going deeper into where context and the SOC's blind spots actually meet. Identity is the control plane. Agentic AI just made ignoring that unsustainable. #AuthorityAsControlPlane #IdentitySecurity #BlackHat2026 #AgenticAI #SOC
-
Indus Khaitan shared thisIn 2023, a team of 10 and I set out to see whether Agents can automate manual cybersecurity tasks. Remove IT Tickets & CSVs. We were bootstrapped for the first 8-9 months. We did not even know that such a thing was possible. Could Agents even predictably perform these mission critical tasks? We were very very nichely focused on Identity governance use cases. Such as, aggregating user/entitlements for rapid access reviews, full-lifecycle operations when APIs or SCIM were not available in web applications. But what ended up happening was that we created Agents that deterministically execute enterprise tasks across IT and Cybersecurity. - Agents that execute based on a policy - Agents that perform tasks, and capture every moment - Agents that are never autonomous - Agents that are meticulous and step-by-step - Agents that recover or fail graciously with forensic evidence What we thought would be a simple contraption for automating any imaginable last-mile task requiring human intervention--took us on a wild-goose chase. We had to build the underlying technology and infrastructure required to make Agents predictable. The niche in Identity governance was the proving ground. And a very lucky proving ground because when the agent is deactivating a user account, there is no margin of failure. We started by automating disconnected identity workflows, but ended up building the execution infrastructure required for agents to perform real enterprise work predictably. Today, the enterprise agent opportunity is about harnessing & constraining the models enough to be trusted with consequential work. In 2023, we did not know whether agents could perform mission-critical work predictably. 24 months later, that question has become the company’s core technical conviction. And a lot more to be done beyond our early adoption. Steve Zalewski Ashok Kakani Puneet Bhatnagar Archit Lohokare Suresh Batchu Manoj Apte Francis Odum Redblock
-
Indus Khaitan posted thisWhile 99% of AI-pilled security practitioners are talking about agents escaping the sandbox, two weeks ago, hackers convinced a Brinks home security employee to convert an attacker into a trusted enterprise identity. Salesforce and Cresta then accepted that trust and exposed everything the identity was authorized to see. They stole more than 4.9 million Salesforce records with PII. Once the adversaries were in, they most likely ran a mass export of these records. Yes, AI is dangerous. Agents should not escape. But the human chain is still a weak link. We should run for fixing the basics, boring, and b'ugly, rather than chasing the asymmetrically lower volume of agent related security. I'm more an more convinced that SaaS is going to be the wild wild west where there are no controls other than guarding the front-door with SSO. In this case even the front-door was compromised! In most SaaS apps, there is little to no monitoring of what happens in the backend, and what data is moving via APIs. When I look back, becomes more and more scary about the overall security weakness of SaaS and how long we have allowed this to exist.
-
Indus Khaitan liked thisIndus Khaitan liked thisUpdate: Samarth P. and I have joined OpenAI. We started Kairos with a dream that felt too big to say out loud: a personal AGI for everyone. Excited to keep chasing that dream inside Codex and ChatGPT.
-
Indus Khaitan liked thisIndus Khaitan liked thisMinimus raised $51 million. Last week, they handed that money back. The original Twistlock crew built secure-by-default, and Echo just picked up the pieces from the fire sale. I talk to security founders every week. Most think better product means you survive. It doesn’t. The market doesn’t care about your codebase. Look at the market. Failing security startups all leave the same ugly autopsy report. - They try to boil the ocean. Five founders, three markets, and zero focus. They want to build an all-in-one platform for GRC, SecOps, and AppSec. You should pick one or get buried. - They bloat fast. Suddenly there’s a 20-person GTM team selling a product nobody’s buying. Enterprise budgets don’t care about your headcount. - They build on someone else’s rails. Distribution deals are fine, but if your core product lives on another vendor’s stack, good luck convincing buyers you’re not just a feature. - They pitch in buzzwords. If you can’t explain your value in 30 seconds, minus the buzzwords, buyers tune out and mock your deck in Slack. - They ship more alerts, not action. Detection-only is dead. If your product just adds noise instead of enforcing decisions, nobody cares. If your enterprise pipeline is stuck, it’s not the product. It’s your positioning. Wrong message, wrong buyer. Are you building something that actually makes decisions, or just another tool dumping alerts on a CISO’s desk?
-
Indus Khaitan liked thisIndus Khaitan liked thisSeeing more and more $50M-$100M seed (!) rounds lately. These founders don't understand what they're signing up for. Every time you raise money, you close the door to exit opportunities. If you raise at a $100M valuation, you can no longer sell for $80M - which, for you personally, might have been a life-changing amount of money. Yes, with capex-heavy industries like robotics you need more capital. But you can work your way up. There is rarely a situation where you need $100M from the jump. A great example is SpaceX. In 2002, they raised a $12.1M Series A. Seems shockingly low now, but it's a sensible amount for that stage. Start with the capital you need, then work your way up. You keep more optionality on the table this way.
-
Indus Khaitan liked thisIndus Khaitan liked thisBen's movie The Last Man in Tower is finally releasing in India on September 11th. He bought the rights to Arvind Adiga's book more than ten years ago. He was able to secure financing and sign stars like Manoj Bajpai and Boman Irani. A true labor of love and persistence! Proud of you Ben Rekhi!Last Man in Tower - Teaser Release | Manoj Bajpayee | Divya Dutta | Boman IraniLast Man in Tower - Teaser Release | Manoj Bajpayee | Divya Dutta | Boman Irani
-
Indus Khaitan reacted on thisIndus Khaitan reacted on thisIn 1982, Bill Gates, Paul Allen, and Steve Ballmer offered me a job at Microsoft with 4,000 shares (worth ~$570M today). I said no. I was finishing business school at Stanford University Graduate School of Business. Steve had been a year ahead of me, and I'd met Bill at the West Coast Computer Faire. A word processor I’d built for the Apple II was on my résumé. Dave Marquardt, Microsoft’s venture investor and a board member, noticed it and asked me to meet the team. Microsoft flew my wife and me to Seattle, where I interviewed with the team for three days. She was five months pregnant with twins. Steve told me Microsoft would go from $12 million in revenue that year to $50 million the next. I asked Bill if he planned to become CEO. He said no. Microsoft hired Jim Towne instead. A year later, Bill took over and did pretty well. I understood Microsoft could become a very big company. I didn't understand what going from $12 million to $50 million meant for a software company in 1982. Digital Research was recruiting me too, so I heard both sides of how IBM chose Microsoft for the PC operating system, almost in real time. The famous version says Gary Kildall was out flying when IBM arrived. The full story is more complicated, but the decision changed the industry. Both companies made me offers. I passed on both. Two things kept me from taking either job. I wanted to stay near family when the twins were born. I also didn’t want to leave the relationships I’d built in the networking industry, before Ethernet became the standard. I don’t regret putting family first. But that decision has followed me through every investment committee since. You can understand the technology, know the people, and still underestimate the upside. I eventually became managing partner at Mayfield, and Dave and I became friends through the venture business. I missed Microsoft, but the introduction still changed the direction of my life.
Experience & Education
-
Redblock
******* *** ***
-
******
*** *** *******
-
*********
***** ** ******
-
***** ********* ** *********** *****
** undefined undefined
View Indus’s full experience
See their title, tenure and more.
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
or
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Volunteer Experience
-
Mentor, Guest Lecturer
University of California, Berkeley, Haas School of Business
- 3 years
Education
-
Program co-chair / Black-shirt
nasscom
- 2 years 1 month
Science and Technology
Co-chaired NASSCOM Product Conclave, an annual melee of 1500 entrepreneurs, VCs and product professionals in Bangalore. Worked in a team which created the event, curated the program and played host to hundreds of speakers including Guy Kawasaki, Naveen Jain, Ram Shriram, Vinod Khosla and others.
Publications
-
Building a Web directory & a Search engine using Open Directory and Java
Session at JavaOne
Recommendations received
12 people have recommended Indus
Join now to viewView Indus’ full profile
-
See who you know in common
-
Get introduced
-
Contact Indus directly
Other similar profiles
-
Jason Westland
Jason Westland
8Dflow - Quality Management Software for Manufacturing
15K followersSunshine Coast, QLD
Explore more posts
-
DQ CHANNELS
3K followers
Veeam Software hosted the Bharat Cyber Suraksha Summit in Guwahati, launching a North-East Cyber Resilience Report, university partnerships and the “Main Hoon Saksham” AI skilling drive to strengthen digital trust and cybersecurity readiness. SANDEEP BHAMBURE Chaitra Vedullapalli Read More: https://lnkd.in/gX-7Xeis #DQChannel #Veeam #cyberresilience #news
2
1 Comment -
Yogesh Jadhav
Choice TechLab • 25K followers
Markets run on speed but they rest on trust. At CNBC’s Global Leadership Summit, the SEBI Chair’s remarks on cybersecurity weren’t dramatic but they were quietly urgent. “SEBI is emphasizing cyber security preparedness… incident response, business continuity and cyber resilience.” And it couldn’t come at a more critical time. The recent 𝗦𝗘𝗕𝗜 𝘃𝘀 𝗦𝗖𝗔𝗠 𝗵𝗲𝗮𝗱𝗹𝗶𝗻𝗲𝘀 𝗮𝗿𝗲 𝗮 𝗿𝗲𝗺𝗶𝗻𝗱𝗲𝗿 𝘁𝗵𝗮𝘁 𝗳𝗶𝗻𝗮𝗻𝗰𝗶𝗮𝗹 𝘁𝗿𝘂𝘀𝘁 𝗶𝘀 𝗻𝗼𝘁 𝗷𝘂𝘀𝘁 𝗮𝗯𝗼𝘂𝘁 𝗯𝗮𝗱 𝗮𝗰𝘁𝗼𝗿𝘀 𝗶𝘁’𝘀 𝗮𝗯𝗼𝘂𝘁 𝗯𝗿𝗼𝗸𝗲𝗻 𝗴𝘂𝗮𝗿𝗱𝗿𝗮𝗶𝗹𝘀. Whether it’s insider fraud, coordinated manipulation, or data leaks, the system suffers when resilience is reactive, not proactive. Three reflections I’m taking back: • 𝗖𝘆𝗯𝗲𝗿𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗶𝘀𝗻’𝘁 𝗷𝘂𝘀𝘁 𝘁𝗲𝗰𝗵 𝗶𝗻𝗳𝗿𝗮 𝗶𝘁’𝘀 𝗰𝗼𝗻𝘁𝗶𝗻𝘂𝗶𝘁𝘆 𝗱𝗲𝘀𝗶𝗴𝗻. Will your system pause cleanly when breached? Will users know what’s happening without panic? • 𝗥𝗲𝘀𝗽𝗼𝗻𝘀𝗲 𝗶𝘀 𝗮𝘀 𝗰𝗿𝗶𝘁𝗶𝗰𝗮𝗹 𝗮𝘀 𝗽𝗿𝗲𝘃𝗲𝗻𝘁𝗶𝗼𝗻. You can’t stop every breach. But your playbook decides whether you lose confidence or gain long-term trust. • 𝗥𝗲𝘀𝗶𝗹𝗶𝗲𝗻𝗰𝗲 𝗺𝘂𝘀𝘁 𝗯𝗲 𝗱𝗲𝘀𝗶𝗴𝗻𝗲𝗱, 𝗻𝗼𝘁 𝗯𝗼𝗹𝘁𝗲𝗱 𝗼𝗻. Recovery shouldn’t rely on luck. It needs to be traceable, repeatable, and calm under pressure. We don’t need fear to drive better systems we just need better defaults. And leadership that doesn’t wait for the headlines to act. HSBC Embassy Group SEBI ITC Limited CNBC-TV18 #CNBCGLS #SEBI #CyberSecurity #SEBIvsSCAM #DigitalTrust #MarketResilience #IncidentResponse #BFSI #FinTech #GlobalLeadershipSummit #CNBCTV18GLS2025 #TheIndiaAdvantage #ProductLeadership #YogeshReflects #YogeshWrites #YogeshJadhavInsights
48
-
Ajay Mehta
Protaxology Advisors Private… • 2K followers
🔐 SEBI Issues Technical Clarifications to CSCRF (Aug 28, 2025) SEBI has strengthened its Cybersecurity & Cyber Resilience Framework (CSCRF) with new clarifications impacting all regulated entities (REs) – from AIFs, brokers, AMCs, PMS, KRAs, to custodians and depositories. ✨ Key Highlights: 1️⃣ Exclusivity vs. Equivalence Principle If REs are regulated by multiple regulators (e.g., SEBI + RBI), CSCRF applies only to SEBI-regulated systems (Exclusivity). Where equivalent controls exist under another regulator, compliance with that framework counts towards CSCRF (Equivalence). 2️⃣ Critical Systems Redefined Ancillary systems on the same network segment as critical systems are now also classified as critical. 3️⃣ Zero Trust & Security Posture Mandatory adoption of Zero-Trust strategies, segmentation, high availability – all to be IT Committee-approved. 4️⃣ Incident Communication Press releases not mandatory for every attack. Entities must act per their Cyber Crisis Management Plan (CCMP). 5️⃣ Market-SOC Onboarding Small-size & Self-certified REs must onboard to Market-SOC. If they already run their own SOC, they may continue – but must file annual SOC efficacy reports. 6️⃣ Business Continuity Benchmarks RTO = 2 hours (resume critical operations). RPO = 15 minutes (data recovery). 7️⃣ Audit & VAPT Only summary reports to be submitted (not raw vulnerabilities). Must follow CERT-In’s new Cyber Security Audit Policy Guidelines. 8️⃣ ISO 27001 for Qualified REs Now recommended, not mandatory. 9️⃣ Re-Categorisation Portfolio Managers: Mid-size = ₹3,000 – ₹10,000 cr AUM Small = ≤ ₹3,000 cr Merchant Bankers: Active = Small-size RE Inactive = Exempt from CSCRF. #SEBI #Cybersecurity #CyberResilience #FinancialServices #CISA #RiskManagement #infosec #Compliance #India #FinTech #ITSecurity #RegulatoryUpdate
18
-
Pat Clawson
CheckRed • 5K followers
Trust is becoming architectural — not just procedural. The RBI’s new “bank.in” mandate is a strong signal that regulators are moving closer to infrastructure-level controls. For financial institutions, this is bigger than a domain change. It’s a shift toward continuous trust validation. Worth the read. 👇
7
-
Bhavin Bhansali
PROGIST • 5K followers
We often focus on the latest tech buzz, but sometimes the real risks are hiding in plain sight. At the ETCISO Annual Conference, was humbled to share my perspective on why people security and supply chain risk remain two of the most underestimated threats today. The real challenge isn’t just protecting our own house, but extending security awareness and continuous, automated risk assessment to every part of our ecosystem. PROGIST Chaithanya Rao (CISSP,CEH) Savio Fernandes Lakshmi Prasath Priyanka Sehgal Kadam Naman Patel Abhishek Sawant Vinisha Olga Mendonca Charles Lawrence #ETCISOAC25 #LeadTheNext #Cybersecurity #Leadership #PeopleSecurity #SupplyChain #ProgIST
28
4 Comments -
Sarat Lingamallu
Flyingduck • 5K followers
👨💻 Had some interesting conversations at the Quantic DevSec event in Bangalore this week where CISOs and engineering leaders came together to discuss the future of AppSec in the AI era. Here are some highlights from the CISO panel discussions: 🚀 Code & Security Velocity Code generation is faster than ever — but code reviews and security checks haven’t caught up. Shipping velocity remains the business goal, but security cannot become the bottleneck. 🤖 AI in the Security Pipeline AI is now expected to help review code and accelerate security processes. But trust is a big challenge — do we know what AI is doing with our data? Guardrails are critical: - Coding standards embedded into prompts. - Policies on prompts & model usage. - Monitoring outputs of AI tools. - Human-in-the-loop remains essential. Devs can be trusted to some extent, but AI-generated code still needs quality control before PR and deployment. ⚡ Challenges & Pressures - At scale, teams are shipping code faster — but also shipping vulnerabilities faster. - AppSec teams face increasing pressure to keep up. - Runtime detection is “too late” — issues must be caught earlier in pipelines. - Agents themselves (security or AI) could be tampered with internally — new attack surfaces. 🔑 Key Takeaways - AI-powered security solutions must integrate seamlessly into pipelines — speed with precision. - Precise planning and prioritization matter more than blind auto-patching. - AI governance is not optional: policy, monitoring, and accountability are required. - The rise in 0-day attacks means intelligence products to detect and prioritize are urgently needed. - Focus on Shift Left security looking at packages and dependencies in the code, dependency pinning is important. - Train employees with on how to utilize AI powered security solutions #DevSecOps #AppSec #Cybersecurity #AI #EngineeringLeadership #QuanticDevSecShow #QuanticAwards Sivakumar Krishnamurthy Prathap R Jason J. Sulabh Jain Piyush Maharishi Jayateerth Mirji Madhav Rangaswamy Gaurav Singh Sujay Ramachandra Navaneethan M Abhishek Gaurav Vinay Peramana Ashok Kumar G Anvesh Y. Sriram Krishnan Dibya Pattnaik Sunil P Vikas Anand
21
-
Ruchin Kumar PhD (Vice President - South Asia, Futurex)
Futurex • 9K followers
Futurex provides solutions that help organizations align with the technical demands of the RBI Cyber Security Framework and the DPDP Act, 2023. Our integrated approach enables high-performance payment processing without compromising transaction integrity. Organizations can deploy hardened hardware while maintaining the agility required for hyperscale growth
7
Explore top content on LinkedIn
Find curated posts and insights for relevant topics all in one place.
View top contentAdd new skills with these courses
-
2h 19m
AI Product Security: Secure Architecture, Deployment, and Infrastructure
-
13m
A Standalone Project: Build a Program to Encrypt and Decrypt Text Messages Using an Encryption Algorithm to Protect Data from Unauthorized Access
-
40m
AI in Cybersecurity: The Future of Red Teaming and Blue Teaming