Artificial intelligence is transforming the field of cybersecurity for both companies and attackers. While enterprises use AI to strengthen their defenses and automate processes, hackers are applying the same technology to find vulnerabilities, conduct more sophisticated attacks, and achieve significantly greater speed.
According to Anant Naga, Vice President of Rubrik for the Asia-Pacific region, this shift forces companies to rethink their long-standing cybersecurity strategy. The question is no longer whether an attack can be stopped, but how to prepare for the consequences of its successful execution.
In an interview with YourStory, Naga explains why boards of directors are shifting focus from prevention to resilience, why recovery has become a business priority, and how AI will change corporate cybersecurity in the coming years.
The speed at which a cyberattack occurs is shrinking from weeks to seconds, leaving organizations with very little time to react. Naga notes: 'I have never seen technology develop so fast. AI has only been in our lives for a couple of years, but the pace of innovation and adoption has been astonishing.'
This speed is changing the threat landscape. Enterprises have long relied on a traditional cybersecurity model based on prevention, detection, and remediation. Security teams assessed weaknesses, identified the most critical risks, and responded before attackers could inflict serious damage.
However, Naga argues that this approach was designed for an era when attacks happened at human speed. AI has changed this paradigm. Attackers can now automate reconnaissance, find weaknesses, and exploit them in mere seconds. As attacks become increasingly autonomous, organizations can no longer assume they can stop every intrusion before damage is done.
As a result, conversations in boardrooms are changing. Instead of asking about the possibility of preventing a breach, executives are increasingly asking how quickly critical business operations can be restored after one occurs. Naga cites recent incidents involving global brands such as Jaguar Land Rover and Marks & Spencer, where outages lasted for weeks, demonstrating that business continuity has become as important as prevention.
The security standard that was used for a long time—detecting an intrusion within a minute, localizing it within 10 minutes, and remediating within 60 minutes—may prove insufficient when attacks happen almost instantaneously. Naga emphasizes: 'It took us 20 years to refine our philosophy of prevention, detection, and remediation. Resilience is the next stage we are in.'
This does not mean that prevention becomes less important. Rather, enterprises must find a balance between investing in stopping attacks and the ability to recover quickly when systems are compromised. For many organizations, backup strategies are still focused on protecting individual systems or applications, but Naga believes this approach is no longer enough.
Modern enterprises operate through deeply interconnected cloud platforms, on-premises infrastructure, applications, identities, endpoints, and data environments. Restoring one database or application has little value if the rest of the business remains unavailable. Instead, organizations need to understand what is required for a full restoration of business operations.
This includes restoring identity services, business applications, cloud workloads, infrastructure, and corporate data—in the correct sequence. A comprehensive understanding of where trusted data resides and how systems depend on each other is also required so that recovery does not create additional risks.
Naga advises companies to stop viewing backups solely as a storage function and instead treat recovery as a core capability for ensuring business continuity. For him, cyber resilience begins long before an attack. Organizations must continuously identify clean recovery points, test recovery processes, and ensure that critical systems can be restored without reintroducing compromised data or malware.
He concludes: 'You will be breached. The ability to prevent is important, but the ability to recover is becoming even more critical for any business.' This requires preparation in peacetime, not attempts to develop recovery plans in the middle of an incident.
As corporate environments become more distributed across cloud infrastructure, on-premises systems, applications, and endpoints, the attack surface continues to grow. These environments also contain the organization's most valuable assets, making them attractive targets for ransomware and other sophisticated attacks. For Naga, the goal is no longer just preventing attacks; it is recovering from them at machine speed.
AI can accelerate and complicate cyberattacks, but Naga believes it will be equally important for defenders. Security teams are already using AI to automate routine tasks, analyze large volumes of security data, and improve response times. Over time, he expects AI to take on a much larger role, helping organizations detect anomalies, prioritize threats, and automate recovery workflows.
However, this transition will take time. Most enterprises operate complex IT environments built over decades, encompassing legacy infrastructure, cloud platforms, business applications, and numerous security tools. Integrating AI into all these environments requires both investment and operational maturity.
Nevertheless, Naga believes the direction is clear. As AI models become more capable and accessible, enterprises will increasingly rely on intelligent automation to strengthen resilience while reducing the burden on security teams. Naga sees the next stage of cybersecurity as an autonomous resilience agent—an AI-based system capable of orchestrating recovery across the entire organization with minimal human intervention.
The goal is simple: if an incident occurs, business leaders must be able to trigger an intelligent recovery mechanism that restores applications, infrastructure, identities, and data in the correct sequence. Instead of manually coordinating multiple teams during a crisis, enterprises will rely on AI to launch recovery workflows almost instantly. Rubrik is already moving in this direction, helping customers automate cloud recovery and orchestrate the recovery of critical business systems, reducing downtime and increasing organizational confidence in their recovery processes.
The speed of AI innovation forces organizations to rethink not only cybersecurity. As AI agents integrate into software development, customer operations, and enterprise applications, enterprise environments are becoming increasingly autonomous—and significantly more complex. This complexity expands the attack surface and raises the stakes for business continuity.
Naga believes that resilience is transforming from a purely IT issue into a business issue. He cites recent incidents resolved before becoming public knowledge as proof that rapid, coordinated recovery can protect not only operations but also revenue, reputation, and customer trust. In sectors like financial services, the consequences extend beyond individual enterprises. The ability to recover quickly can have broader implications for the stability of financial systems and the economy as a whole. This is why he believes that boards of directors should prepare for the assumption that breaches will occur.
As AI continues to change both attacks and defense, Naga expects resilience to become the defining metric of corporate cybersecurity. Organizations that invest in recovery, automate critical processes, and regularly test their resilience will be better prepared to manage next-generation, AI-driven threats.
