As India’s digital ecosystem expands, so does its exposure to increasingly sophisticated cyber threats. The rapid adoption of cloud, AI and digital platforms has made cybersecurity a boardroom priority, but the challenge extends beyond technology and compliance. It requires stronger R&D, closer collaboration between industry and regulators, greater consumer awareness and cybersecurity education at the grassroots level. At the GRC India AI Conclave 2026, hosted by Ampcus Cyber, Tech Achieve Media spoke with Deep Chanda, CEO, Ampcus Cyber, on India’s evolving cybersecurity landscape, the need to move beyond checkbox-driven GRC, the role of AI in making security more efficient, and why cybersecurity awareness must begin much earlier in the education system. In this conversation, Chanda suggests that while businesses need to innovate and invest in cybersecurity, the industry must also work more closely with regulators and focus on building a stronger culture of cybersecurity awareness and research.
TAM:What was the intent behind organising an event like GRC India AI Conclave?
Deep Chanda: I’m a businessman. So, when you do this kind of event, naturally, you want to engage with customers. But if you look at our panelists, none of them are our customers. They are regulators and policymakers. You need to understand that India is now the most populous country in the world. Along with that, the number of digital transactions India handles is greater than that of the US and Europe combined. However, digital literacy in India is still relatively low. That is the contrast we are dealing with.
As cybersecurity companies, of course, we want to do business. But it is equally important that we listen to regulators. As companies, we often get frustrated with regulators because there’s always another new law, and another new requirement. But through these discussions, we also get to understand why they are doing it.
Take Digi Yatra, for example. When Digi Yatra first came on the scene, there was a lot of discussion around whether it was storing large amounts of data. There was a lot of public concern and backlash. But the organisation clarified that it does not store such data centrally, which helped address some of those concerns.
So, the whole idea behind this event was to bring different stakeholders together and understand these issues collectively. We wanted to bring together around 600 people, study these challenges, and have these conversations ourselves. We didn’t have any hidden agenda. That was really the agenda behind the event.
TAM: India’s rapid digital and cloud adoption is increasing its exposure to AI-driven cyberattacks. Where are the biggest gaps in India’s cyber defence, and are regulations keeping pace with these threats?
Deep Chanda: Fun fact: As of today, there are very few countries that have specific regulatory frameworks or dedicated laws focused on cybersecurity. For example, is there a dedicated cybersecurity ministry in India? Is there one in the US or in other countries? To my knowledge, only a few countries have taken steps in that direction.
The problem is that we are all working towards addressing individual vulnerabilities. But there are millions of vulnerabilities, and as we speak, malicious actors are finding new ways to exploit them. I always say that the bad guys only need to find one way in, while the good guys have to make sure that all the possible ways in are secured. Earlier, attackers could take months to develop a vulnerability or exploit. Today, they can do it within 24 hours. That is why I believe companies need to invest heavily in R&D.
At Ampcus Cyber, for instance, we now have a team of people focused on R&D. It has to be about research, research and more research. The biggest challenge I see is that companies need to come together and collaborate. We need strong R&D teams, greater collaboration across the industry and regulators working together. Perhaps we also need to think about whether there should be a dedicated institutional framework, or even a ministry, focused on cybersecurity and cybersecurity R&D. That is what I am saying. Private companies can come together and work on solutions, and regulators can collaborate with them. But there also needs to be a larger institutional framework supporting cybersecurity research and development. I think that is still missing.
TAM: Many organisations still view GRC as a compliance exercise. How can boards shift from checkbox-driven compliance to intelligence-led governance and enterprise resilience?
Deep Chanda: If you go and ask everyone here, 90% will say they don’t have a home insurance. But if you ask them whether they have a car insurance, they will say yes. The reason is simple: unless something is enforced, people don’t necessarily follow it. There are laws and regulations around certain things, and that creates compliance.
At the end of the day, we are still learning. If you look at the private sector, companies should continue to adopt better cybersecurity practices. But I don’t want us to lose sight of the larger journey, which is we, as a population, need to understand both the risks of cybersecurity and the potential risks that come with R&D and technology. For example, Alfred Nobel invented dynamite and was later associated with the Nobel Prize. Today, dynamite can also be used to cause destruction. You have to look at both sides of technology, which is the head and the tail. The same applies to cybersecurity. Many companies have cybersecurity measures in place and outsource certain functions to specialists like us. We tell them that cybersecurity is important. But India is also a cost-sensitive market, and every investment is closely evaluated.
So, we need to start asking more questions. For instance, we walk into a shop to buy something, and they ask for our Aadhaar number. We give it to them without necessarily asking where that data is going or how it will be used. Have we ever stopped to ask, ‘Where are you going to store my Aadhaar details? Who will have access to it?’ At least as consumers, we can start asking these questions. That is how awareness begins.
TAM: As GRC moves towards AI-driven, automated platforms such as ComplyX, how is the cybersecurity business model changing, and are enterprises willing to invest in proactive risk management?
Deep Chanda: No enterprise is going to suddenly increase its spending just because we ask for it. We have to be innovative. We have to accept that reality. If a company is using AI, I would expect its production costs to come down. If I say, ‘I’m using AI, so you have to pay me more,’ the answer should be, ‘Go home.’ The whole idea of using AI is to improve efficiency and reduce production costs. For example, companies used to pay $30,000, $40,000 or $50,000 for penetration testing of an application. What we are trying to do now is use technology to increase the efficiency of testers while reducing the overall cost.
TAM: Message for the industry?
Deep Chanda: I have also been very vocal about the need for financial education at the grassroots level. When fresh technology graduates join our organisation, some of them don’t even understand how taxation works in India. That is a red flag. Now, I am equally vocal about bringing cybersecurity education into schools and making it part of the foundational education system. We need to prepare the younger generation. I’m in my 40s. We have lived our lives, and there will come a time when the next generation takes over. They will be the people who will be running the banks, companies and the country. So, while we continue to discuss cybersecurity at conferences and industry forums, we also need to take the conversation to the grassroots: into schools, colleges and educational institutions. That is what I would request everyone to focus on.















