As software development accelerates due to artificial intelligence, the cybersecurity landscape is changing. Advanced AI models, such as Mythos, are capable of detecting vulnerabilities with unprecedented speed, while autonomous agents, AI-generated code, geopolitical uncertainty, and shrinking attack windows force organizations to rethink how they protect critical systems.
These topics were central to the round table 'Cyber Resilience in the Mythos Era: Moving at Machine Speed in an Uncertain Digital World,' organized by Rubrik and YourStory Media in Bengaluru on July 10, 2026.
A number of specialists from various sectors participated in the discussion, including fintech, e-commerce, logistics, enterprise software, and education. These included Ananth Nag, Vice President APAC Rubrik; Aditya Chandra, VP of Platform Engineering MoEngage; Anshul Sharma, Director of Engineering Scaler; Apoorva Gaurav, Senior VP of Engineering Clear; Arghya Mukherjee, Head of AI and Data Algonomy; Chidambaran Subramanian, CTO InCred Financial; Gaurav Kapatia, Head of Engineering Newton School and Newton School of Technology; Karthikeyan Ramasamy, Senior Director of Engineering Freshworks; Mohan Devarapalli, Head of Engineering PayU; Navin Kumar, VP of Engineering LeadSquared; Niraj Kumar, Director of Engineering Shadowfax; Prabod Goel, Global Engineering Lead Postman; Rishabh Chhajer, VP of IT and Cybersecurity Allen; Utkarsh Tiwari, Head of Security Engineering (Cloud Technologies) Meesho; and Vikas Roy, Director of Engineering Vahan.ai.
Participants discussed the challenges companies face as AI integrates into products and operations. While concerns covered protecting Personally Identifiable Information (PII), securing AI-generated code, managing AI agents, and minimizing supply chain risks, one message dominated: prevention alone is no longer enough.
Since organizations use AI for faster software creation and deployment, they are simultaneously generating new security threats. Participants pointed to prompt injection attacks, AI-generated code, non-human identifiers, third-party dependencies, and AI agent actions on behalf of users as some of the most serious problems enterprises must solve.
Mukherjee emphasized the risks of using customer data to train Large Language Models (LLMs) and the need to secure agentic AI systems. Kumar spoke about protecting sensitive customer information and preventing cross-tenant data leakage in LeadSquared, while Ramasamy noted the emerging challenge of managing non-human AI identities. Others discussed the growing need for more robust AI guardrails, observability, and governance as AI becomes part of daily business operations.
The very speed of software development creates an additional layer of complexity. As Sharma stated, 'AI expands the attack surface faster than we can defend it.' Although participants agreed that AI has accelerated development and experimentation, they also noted that this same speed increases the likelihood of vulnerabilities that organizations may not notice or immediately understand.
Several participants suggested using AI within a defensive strategy. Roy explained how Vahan.ai employs defensive agents and AI-based detection mechanisms, stating: 'We use AI to fight AI.' He acknowledged that the approach is still evolving because AI agents are often non-deterministic, which complicates their testing and protection using traditional methods.
Meesho focused on securing AI-generated code from the outset. Tiwari noted: 'We start by putting guardrails on the coding agent itself so that the code it writes is secure by default.' Nag strongly urged the group to look beyond prevention and consider what happens after a breach. He referenced recent incidents with Jaguar Land Rover and Marks & Spencer, noting that even large organizations with mature security programs can face prolonged downtime. He argued that companies traditionally invested heavily in prevention, detection, and remediation, whereas resilience—the ability to restore business operations—often received less attention.
Participants agreed that the conversation is shifting as cyberattacks are increasingly viewed as inevitable. Instead of asking, 'Can we stop every attack?', organizations are starting to ask, 'How quickly can we recover systems if an attack succeeds?'
Ramasamy countered that while AI brings new risks, organizations must continue to rely on established security principles, including multi-layered architecture, identity-based access, least privilege rights, and robust guardrails. He stressed that AI agents should only access authorized tools and data on behalf of verified users, thereby limiting potential breach damage.
For Chandra, resilience is also linked to organizational culture. He argued that many companies still view cybersecurity as a compliance exercise rather than an engineering discipline built on continuous monitoring, behavioral threat detection, and operational readiness. He added: 'Culturally Indian organizations are not ready. Many businesses do it just for show, for ticking boxes, for an audit checkmark. We do not realize the depth of the problem.'
The discussion repeatedly returned to one conclusion: in an AI-driven world, preventing attacks remains critically important, but resilience holds equal weight. As software development accelerates and attack cycles continue to shrink, organizations will need to prepare not only to defend their systems but also to recover quickly in the event of a breach.
A constant theme was the distinction between disaster recovery and cyber recovery. Resolving operational outages is relatively straightforward because organizations know their backups remain untouched. Participants noted that cyberattacks are fundamentally different: attackers can compromise both production systems and backups, leaving organizations uncertain about which data copies they can trust.
Explaining this difference, Nag said: 'When we are hacked, it is not operational recovery. Operational recovery is my copy that I just need to get back. Cyber recovery is I have a copy, but I don't know if that copy is infected. If it is infected, what do we need to recover?' He emphasized that true cyber resilience depends not only on maintaining redundant infrastructure. Organizations need clean, isolated recovery environments and verified backups that can be restored with confidence after an attack.
One participant shared a case where a disgruntled database administrator intentionally deleted critical databases. Recovery was only possible because the organization had maintained several isolated copies of its data. This experience, participants noted, reinforced the value of continuous, protected backups and clearly defined recovery strategies capable of countering both external and internal threats.
As enterprises deploy more AI agents, participants agreed that organizations should begin treating them like any other digital identifier—with specific permissions, monitoring, and accountability. Prompt injection attacks, wandering agents, and identity management for non-human users became among the biggest challenges as AI systems become more autonomous. Speakers discussed the importance of policy guardrails, adversarial testing, sandboxing, identity management, and continuous monitoring to ensure the safe operation of AI systems. While no single security system can eliminate all risks, participants agreed that multiple layers of defense significantly reduce the probability of unexpected AI behavior.
The discussion also touched upon how AI-generated code is changing software development itself. Since engineering teams are releasing code faster, developers are increasingly implementing software they may not fully understand, making governance, visibility, and continuous verification more important than ever.
By the end of the discussion, participants agreed that cyber resilience extends far beyond technology. Many organizations still view cybersecurity as a compliance requirement rather than a core business opportunity. Building resilience requires regular incident modeling, recovery drills, and tabletop exercises to ensure teams can quickly resume operations in the event of an incident. Participants also stressed that resilience must become a board-level priority, not solely the responsibility of technology and security teams. They argued that recovery planning should be seen as an investment in business continuity, not just another security initiative.
Throughout the round table, one idea kept surfacing: AI accelerates software development, but it also increases the speed and complexity of cyber threats. As organizations integrate AI into products, engineering, and operations, they are also expanding the number of systems, identifiers, and workflows that need protection. For many present, this changes the very nature of cybersecurity. The goal is no longer to assume that every attack can be prevented. Instead, organizations must be prepared to quickly detect attacks, restore trusted data, resume business operations, and minimize downtime when a breach occurs. In a threatening, AI-driven landscape, resilience ceases to be a backup plan; it becomes an integral part of the cybersecurity strategy.