Transcript
of technology. I'm your host, Jenny Suzanna, and today we're joined by a very special guest, Leftenant Colonel Seven Sam, for our very first episode of The Strategy Seat. A visionary leader with 22 years of service in the Indian Army, Seven has stood at the front lines of counter-terrorism operations and international diplomacy through his role in the UN peacekeeping mission in DR Congo. Now, beyond the battlefield, he's also battled personal health challenges with the same grit and has emerged stronger as a transformative corporate leader. Today, as a vice president in the corporate world, Seven brings his unmatched military precision, resilience to shaping strategies at the intersection of AI, cybersecurity, and business. It's an absolute honor to have you with us today, Seven. Welcome to The Strategy Seat. Thank you, Jenny, for that wonderful introduction. It's my pleasure to collaborate with Manage Engine on this podcast. Looking forward to discussing strategy on this Strategy Seat. So Seven, you've had a very fascinating journey that spans across military, diplomacy, and business leadership. Now, each of these sections have their own unique challenges, but they have a common unifying theme, which is strategy. So what first drew you to the intersection of technology and cybersecurity at a strategic level? So, Jenny, it all started with my time in the Indian Army. On the ground, I saw how technology could be the difference between life and death. The right intelligence, the right system could change the outcome of a convention or counter-insurgency operation. Now, when I moved into tech strategy and global business growth, I've come to realise that the battlefield has also shifted. It is not physical anymore. It has expanded into cyberspace. And now with the advent of AI, the stakes are even much higher and critical. Now, at a strategic level, cybersecurity isn't just about protecting data. It's about protecting trust, economies, and even national sovereignty in this new AI-powered world. It is a challenge, and I think, Jenny, that is what pushes me to excel, and I keep encouraging everyone to do the same. Thank you, Savin. That's a very strong connection from seeing technology impact outcomes in the Army to identifying and recognising the cyberspace as the latest battlefield. I love how you brought a broader perspective to cybersecurity. You know, it's not just about the security of my organisation or yours, but I believe that each of us have a role in national security, right? Now, Savin, you've always undertaken challenging roles in leadership, and we firmly believe that leadership under pressure is now as crucial as technology. Some of the major attacks have always exposed how leadership decisions have shaped the preparedness and the outcome, final outcome of these attacks. So if you had to capture your leadership philosophy in a single phrase, especially for navigating high stakes and high-pressure environments, what would it be? That's fabulous, actually, Jenny. If I had to capture my leadership philosophy in one phrase, it would be calm is contagious, courage is decisive. In high stakes, high-pressure environments, whether it was the battlefield or the boardroom, I've learned that your own state of mind sets the tone for the entirety. If a leader can stay composed, people find their footing and catapult ahead. If you can combine that calm with courage to take tough calls and calculated risk in uncertain moments, that's when resilience is built and real progress happens. I have experienced it in my 22 years of military service, and I continue to strive on this concept. Right. That's very inspiring. I think your ability to connect calmness and courage reflects on the truth that that's exactly what organizations need today. Now along with this is also growing pressure on leaders to build confidence in how technology and cybersecurity strategies are shaped at a strategic level. How do you see CIOs embedding trust and credibility into broader digital initiatives? So Jenny, that's a very relevant question. I think the first step for any CIO is to embrace humility. When I say humility, let me put it in the correct perspective here. There is no shame in accepting that no system is ever completely secure. I feel cybersecurity is not about claiming invincibility. It's about building trust through transparency and also through preparedness. Those who openly communicate the vulnerabilities and risks with their teams are the ones investing in the right capabilities and also show they are constantly learning and adapting, thus earning a greater credibility than those who pretend to have all the answers. Now this was at a very individualistic level. Now at a strategic level, it's about embedding security into the very design of digital initiatives. And it should not be as an afterthought, but primarily should be part of the foundation itself. And just as in the military, where your plan knowing that uncertainty is a constant, CIOs must design digital strategies that assume disruption will come and demonstrate to stakeholders that their organizations can withstand and recover from it. Trust is not built, I believe, by eliminating risk, but by showing resilience and responsibility in how you actually deal with it. I love how you said that humility and honesty go hand in hand. And it's amazing that you frame cybersecurity as a trust exercise, right, rather than a shield of invincibility. Now another concern that leaders wrestle with today is balancing compliance with innovation. Oftentimes, employees feel that it's compliance that's hampering their productivity. You know, we've seen this challenge time and time again in almost every industry today, right? Fintech faced this when blockchain came into existence. And what is the right approach to ensuring resilience and compliance without slowing down or hampering innovation? It's a very relevant question. So that's a challenge I've lived on both on the battlefield and in business, Jenny. Resilience gives us the discipline, and it's like a standard operating procedure in the Indian Army, right? Without it, you don't have the order, and without order, you can't win. But I believe that resilience in an ever-evolving VUCA world demands more than just following the rulebook. The right approach is to treat compliance as the foundation and not as a ceiling. We need to get the basics right, automate wherever possible, and then give a free hand to your team to innovate boldly. In my experience, when leaders combine discipline structure with a culture of trust and empowerment, innovation doesn't get slowed down by compliance. It gets safeguarded and is accelerated by it. Now that's my take on it. It's absolutely great because I think for us as a company as well, it's embedded in our DNA. Privacy and compliance is a part of who we are, but our founders have always given us the space to innovate. And that's been the birth of some of the most brilliant solutions that we've put out today in the industry. And that is what has built our portfolio, identifying issues or pain points that our customers face, and bringing in your creativity to solve that has basically resulted in the birth of our solutions. So that's a great point. And I also think that no matter how much we strive to keep up with technology and comply with upcoming regulatory mandates or regional mandates, attackers always seem to be one step ahead of us. So with the new type of cyber attacks that are constantly emerging, what do you recommend for organizations to detect and mitigate these attacks before things get out of hand? So thanks for that, Jenny. In the military, we are trained to fight battles we can't always predict. So that's the essence of operating in a VUCA world. We build layers of defense, we run constant drills, we assume that the adversary is always adapting. Cyber security, I believe, is no different. At a strategic level, CIOs need to move beyond a compliance checklist. Primarily, this mindset has to change. And start thinking like, you know, battlefield commanders. Anticipate, prepare, adapt, intercept, and then thereafter mitigate. Practically, I believe that means leveraging artificial intelligence for continuous monitoring and threat hunting. Not just detecting attacks, but predicting patterns before they strike. It also means running cyber war games, much like the military exercises we have to predict enemy plans and brainstorm counter mitigation strategies, primarily to stress test the systems and people who are under pressure. And just as in the army, as what I've learned, that the first thing to collapse is always the plan. In business, we need leaders who are humble enough to admit vulnerabilities, yet be resilient and agile enough to respond, recover, and keep moving forward. So I believe that's a blend of discipline and innovation is what would keep organizations secure and future ready in this ever evolving voca world. Your perspective on anticipation over reaction is absolutely spot on. And the fact that you said that we've always got to assume that the enemy is right at our doorstep, it reminds me of the principles of zero trust. And I'm reminded of Gartner's forecast that most organizations by 2027 would have embedded zero trust in their cybersecurity strategies. And that is coming to pass, right? A lot of organizations are already in their zero trust journey. Now, looking ahead, what do you think will redefine CIO strategies in the next five years, especially in the way technology, risk and security are managed at an enterprise level? So thanks for that question, actually, Jenny. And over the next five years, I believe that CIO strategy will be redefined by three things. First, artificial intelligence architectures, zero trust resilience, and responsible governance. AI will sit at the core of every enterprise system, not on the periphery. Risk will be managed less through perimeter defense and more through adaptive zero trust frameworks. And most importantly, security will move from being an IT function to a board level responsibility. Trust and resilience, shaping every digital initiative. According to me, every mid and senior level need to be flexible and be ready for this transition. Now, when I say trust, I don't just mean trusting the technology. It's about building confidence across all stakeholders, customers, employees, regulators, and even the society. In the present AI era, trust will become the real currency of business. Without it, even the best technology won't win loyalty or resilience. So Colonel Seven, in a world where AI is being called both the biggest enabler and the biggest threat, you've been championing its integration with cybersecurity. How do you see AI shaping the future of cybersecurity? So you're absolutely right. AI today is both our greatest enabler and our most formidable challenge in cybersecurity. On one hand, AI gives us the ability to detect vulnerabilities in real time, predict threats before they materialize, and respond with a speed that humans alone cannot match. It's like having an ever evolving digital force multiplier, much like how advanced battlefield transparency, real-time intelligence has transformed modern warfare. We have witnessed the same in the recently concluded Operation Sindhu. On the other hand, adversaries are using the very same technology from AI-driven phishing campaigns to convincingly fix and fully automated attacks. Which means the cyber battlefield has evolved from a traditional digital space into a highly AI-driven domain. Now let's take the example of the Russia-Ukraine war. It's a real-time example how the digital battlefield over time has evolved. We've seen predictive analytics deployed not just as a cyber weapon to anticipate and disrupt, but also as a defensive shield to absorb and repel attacks. It's amazing. So the future of cyber strategy will not just be about building stronger firewalls or faster tools. It will be about embedding resilience into the very DNA of organizations. The ability to adapt, anticipate, and recover in a VUCA environment is going to be the game changer. Just as in combat where unpredictability is the norm, leaders, I believe, must cultivate a mindset that embraces uncertainty. We have to be ahead of the curve and over the period learn how to leverage AI responsibly. And also ensure that technology becomes a shield and not a weapon against us. It's not an easy task, but yes, genuinely, I believe that is the way forward. Right. And you were also talking about how attackers have been leveraging AI for spear phishing campaigns, deep fakes, right? And this brings us to the conversation that identities will always be the weakest link in our organization. And that's predominantly because the human mind is something that no system can ever control. And this is where I firmly believe that behavioral analytics can play a crucial role in mitigating attacks, right? So do you believe that CIOs should invest in building AI-driven behavioral analytics and baselines for users and systems? Or is it still too early to operationalize this at a large scale? So I believe that the time is now. AI-driven behavioral baselines are no longer a luxury. They are fast becoming a necessity. In the army on the line of control in Jammu and Kashmir, we used to study patterns of enemy movements to anticipate, then intercept, and finally mitigate test infiltrations. On the similar lines in cybersecurity, AI does the same. It learns what normal looks like for users. And systems. And raises an alert when something unusual happens, right? I believe it's a classical tactical textbook strategy. Of course, scaling this across an organization has its own challenges. We have to take care of the CAPEX, the ROI. We need to build the necessary skill sets. And the risk of too many false alarms have to be catered for. But if CIOs wait for a perfect solution, they'll be left behind. The smarter approach is to start small, right? Roll it out in phases. And always keep a human oversight for contextual changes. Now, over the period of time, the system learns better. The alerts, they start getting sharper. And the organization becomes more resilient. So it's not too early. In fact, waiting any longer is going to be playing with fire. Absolutely. I absolutely agree with you with the dual nature of AI, right? It's absolutely undeniable. Now, while it does detect threats, it also fuels new ones. So we definitely need to act right now. The time is now. We need to do it now. And the parallels that you drew between the battlefield and cyberspace has made it all the more relatable, right? So I think this is something that all of our viewers and myself would probably never forget, right? So how do you see the role of generative AI in security operations, especially SOC? Is it a force multiplier or a double-edged sword? Now, that's a game changer here, Jenny. Generative AI in SOC is both a force multiplier and a double-edged sword, as brought out by you. On the positive side, it can take on the repetitive high-volume work that usually burns, you know, analysts out. Things like automatically triaging alerts, summarizing threat intelligence, or even drafting incident responses reports in seconds. It can also learn the normal behavior of your users and systems. So the moment something looks off, it raises a flag. And much like military war games, AI can generate realistic attack scenarios, letting team train under pressure before the real crisis actually hits. But we can't ignore the flip side. Adversaries are using the same technology to create more convincing phishing campaigns, automated malwares, and even defakes to erode the existing trust. And that's why I call it as a double-edged sword, and rightly brought out by you. The smart play for CIOs is not to wait for perfection. But I believe it needs to be rolled out in phases. We need to use automation to cut through the noise and keep human judgment in the loop. Now, Jenny, at the end of the day, there's a lot of talk about whether AI is worth the investment. Now, my view on this, it all comes down to a clear cost and benefit analysis. And an honest assessment of how much you need AI to help you spot, intercept, and adapt to constant threats in this hyper VUCA digital world. That's well said, Seven. I appreciate the balance that you bring. Because it also reinforces the need to always link technology back to outcomes, right? And oftentimes, as organizations, we're so quick to invest in technology and tools. We want to get what is latest in the market. But point number one, are our teams trained to use them very efficiently? Point number two, do we maximize them? And point number three, do we actually see how they translate into business outcomes? I really loved how you pointed out the business outcomes that we should be focusing on when we invest in technology and in AI.