As enterprises move from experimenting with AI to putting it to work across critical business functions, cybersecurity is facing a new challenge. AI is helping security teams detect threats faster and automate responses, but the same technology is also giving attackers more speed, scale and sophistication. The shift becomes even more significant with agentic AI, where systems can make decisions and take actions with limited human intervention. In this conversation with Tech Achieve Media, Pankit Desai, Co-Founder and CEO, Sequretek, discusses how the security landscape is changing, why enterprises need to rethink traditional security and governance models, and what it will take to secure the AI-first enterprise. He also shares his views on agent lifecycle governance, the future of the SOC, security stack consolidation, and India’s growing role in global cybersecurity innovation.
TAM: AI has fundamentally changed the cybersecurity equation,from improving defenders’ capabilities to also giving attackers new scale and sophistication. From your vantage point, how is the threat landscape evolving, and are enterprises prepared for this new asymmetry?
Pankit Desai: The asymmetry is real. But it is not new in kind, only in speed. AI did not create these gaps; it exposed ones that already existed, quietly and expensively, inside most enterprises. Attackers now use AI to compress timelines that used to take days into hours, whether that is reverse engineering a patch or running a phishing campaign with perfect language and context. What needs to change is patch velocity. Enterprises still operate on cycles designed for a slower threat environment, and a low-severity finding left unaddressed can chain into something critical far faster than before. Most organizations are not prepared for this because their defenses are built around known workflows, not adaptive, AI-driven adversaries. Preparedness now means assuming speed is the default threat, not the exception, and building detection and response that can match that tempo rather than react to it after the damage is visible.
TAM: We are moving from GenAI experimentation to agentic AI, where AI systems can make decisions and take actions autonomously. What does this mean for enterprise security architectures, and what new risks do CISOs need to start planning for today?
Pankit Desai: Agentic AI changes the security conversation from monitoring systems to governing decision-makers. Once an AI agent can act, not just recommend, it becomes a component that needs the same scrutiny as any untrusted actor in your environment. CISOs need to plan for agent lifecycle governance now: knowing what agents exist, what they are permitted to touch, and how their behavior is audited over time. The bigger risk is judgment drift, where an agent trained partly on its own past outputs slowly moves away from its original intent, and because it acts autonomously, that drift can execute before anyone notices. Security architectures need layered guardrails and visibility into the AI supply chain itself, not just the infrastructure around it. The goal is not to slow agents down but to ensure every action is observed, evaluated, and accountable.
TAM: There is considerable pressure on enterprises to deploy AI faster, while security teams are expected to ensure governance, privacy, and resilience. How can organisations strike the right balance between AI innovation and security without turning cybersecurity into a bottleneck for business transformation?
Pankit Desai: The balance comes from where you insert security, not how much of it you apply. If governance shows up only at deployment, it will always feel like a bottleneck because it is reacting to decisions already made. Security needs to sit inside the AI adoption lifecycle from the start, alongside procurement, model selection, and use case design, so it shapes velocity instead of resisting it. This also means rethinking oversight itself. Reviewing every single AI decision creates a bottleneck kind of situation; thus, a tiered approach, where routine, low-consequence actions move freely, and only high-stakes or anomalous ones escalate to a human, letting security scale with the business instead of throttling it. Innovation and governance are not opposing forces; they only feel that way when governance is treated as a final checkpoint instead of a built-in discipline.
TAM: The cybersecurity industry has accumulated multiple layers of tools, platforms, and point solutions over the years. With AI now capable of correlating signals, automating responses, and potentially replacing several manual workflows, do you see the security stack consolidating, and what will the security operations centre of the future look like?
Pankit Desai: Real consolidation means unifying exposure and risk visibility across the stack already in place, not ripping out every point tool. That is exactly what Percept CTEM delivers. It brings assets, infrastructure, and identities into one console, so external, internal, cloud, SaaS, OT/IoT, and human risk are visible together. It maps attack paths and uses AI to prioritize risk by business impact, not just severity, then validates exploitability before anything reaches remediation, so teams act on what matters most. With more than 800 integrations and a coexist-friendly architecture, Percept CTEM works as a force multiplier for the tools teams already rely on. It gives the SOC the context and prioritization it needs to move faster, while keeping people in control of the high-stakes decisions. The future of the SOC is automated, not autonomous.
TAM: For an Indian cybersecurity company competing in an increasingly global market, where do you see Sequretek’s biggest opportunity over the next three to five years? Is the ambition to build for India first and take those capabilities global, or do you see India itself becoming a major cybersecurity innovation hub?
Pankit Desai: Our opportunity is not about choosing between India and global markets. Sequretek is a make-in-India company made for the world, and that is the frame we will continue to operate on. Our products were never built only for India. They have already found acceptance in global markets, which tells us that capability travels. India remains a critical market for us and will keep scaling, but the intent has always been broader: compete everywhere. Our ambition is broad, resilient defense that holds up regardless of geography. Staying relevant means sustained innovation, not a single win we lean on indefinitely. We are deliberate about not becoming a one-trick pony chasing one capability or one market. Our niche is defense in breadth, and that is where we will keep investing.
India is positioned increasingly to be a genuine cybersecurity innovation hub, not just a delivery base, because the talent and problem complexity here rival anywhere else in the world. Over the next three to five years, our biggest opportunity is demonstrating that capability built in India, under real constraints, translates directly into value for enterprises everywhere else.















