MITB Banner

India Inc Levelling Up Cybersecurity Game: Cloudflare Chief Technologist

To gain a deeper insight into how the cybersecurity landscape is evolving in India, AIM got in touch with Fernando Serto, the Chief Technologist and Evangelist, APJC, at Cloudflare

Share

Listen to this story

India’s cybersecurity preparedness is nothing to be proud of. The country is ranked 17 out of 20 on MIT’s CyberDefense Index and is often considered the capital of cyberattacks. However, with a renewed focus on data regulation, privacy, and cybersecurity from lawmakers in the country, we are seeing a rapid shift in the cybersecurity attitude from companies and service providers alike.

Analytics India Magazine got in touch with Fernando Serto, chief technologist and evangelist, APJC, at Cloudflare, to gain a deeper insight into how the landscape is evolving in India. Over the course of this interaction, Serto not only delved into the unique problems faced by Indian companies, but also how they are adapting to the change in cybersecurity regulation. 

A better cybersecurity attitude

The Indian government has been hard at work creating regulations to keep up with the rest of the world. Building on the legislation established the Information Technology Act 2000, the IT rules 2021 has made Indian regulation stronger when dealing with matters of cybersecurity. “It’s been interesting to see from a policy perspective how much India is maturing on this. India now requires that organisations report a breach within six hours. To give you an idea, in Australia, the requirement is 72 hours,” Serto remarked.

Regulators aren’t the only ones staying ahead of the cybersecurity code. According to Serto, even companies are becoming more aware of the importance of cybersecurity. He said, “We were talking about the level of cybersecurity awareness; how much that’s increased in India over the last 12 to 18 months. People are aware of the threat and the need to do something.”

Due to the population density in the country, Indian companies face very unique problems when deploying cybersecurity solutions. This also extends to the tools deployed for internal use. Companies face a challenge when dealing with the sheer volume of people, says Serto, especially when considering the number of assets, networks, and employees that need to be secured.  

“The problem isn’t connectivity to Tier 1 cities, but what we are doing for Tier 2 and Tier 3 cities. If you go a little bit outside of Mumbai you’re going to start having challenges. It becomes really challenging from a user experience perspective,” Serto explains.

Notably, Serto picked up on a relationship between user experience and eagerness to adopt cybersecurity solutions. He drew on the example of remote working during COVID, which forced a lot of companies to rethink their security in favour of allowing people to connect from their homes. He mentioned a scenario where a company deployed a split tunnelling service for their internal VPN, wherein sensitive company data was shared through the VPN, and other, less sensitive applications were funnelled out of the VPN to favour user experience. 

This then resulted in companies sacrificing visibility and security for user experience. However, Serto hit upon the solution, stating, “If you don’t break the user experience, users are not tempted to try and bypass security controls. If you combine a better user experience with better security controls, your users will adopt all the tools you put in front of them. “ 

Advice for enterprises and startups

Indian tech giants have been the silent backbone of many companies all over the world. The enterprise landscape in India also provides contrast to the vibrant startup ecosystem in the country, with Serto stating, “India is a really interesting market because we have very large and very old organisations, and we have very large organisations from a market cap perspective, but they’ve only been around for a couple of years.” 

He also mentioned how big organisations need to break the mindset that security solutions must be procured in the same manner that they have been procuring IT. Serto urged companies to break away from multimillion dollar purchases and tenders, instead move towards making small purchases in hundreds of thousands of dollars while keeping up with the latest security advancements. 

India is also well-known for its burgeoning startup ecosystem. Many have even resorted to calling Bengaluru the Silicon Valley of India. When we asked what his cybersecurity advice to Indian startups would be, Serto elaborated, “The advantage to the startups is that it’s not as difficult for them to adopt better security controls. My biggest recommendation for them is, they should be looking into how they can do the orchestration of [security] tools in the same way they do software development, because then it becomes very natural for them.”

Share
Picture of Anirudh VK

Anirudh VK

I am an AI enthusiast and love keeping up with the latest events in the space. I love video games and pizza.
Related Posts

CORPORATE TRAINING PROGRAMS ON GENERATIVE AI

Generative AI Skilling for Enterprises

Our customized corporate training program on Generative AI provides a unique opportunity to empower, retain, and advance your talent.

Upcoming Large format Conference

May 30 and 31, 2024 | 📍 Bangalore, India

Download the easiest way to
stay informed

Subscribe to The Belamy: Our Weekly Newsletter

Biggest AI stories, delivered to your inbox every week.

AI Forum for India

Our Discord Community for AI Ecosystem, In collaboration with NVIDIA. 

Flagship Events

Rising 2024 | DE&I in Tech Summit

April 4 and 5, 2024 | 📍 Hilton Convention Center, Manyata Tech Park, Bangalore

MachineCon GCC Summit 2024

June 28 2024 | 📍Bangalore, India

MachineCon USA 2024

26 July 2024 | 583 Park Avenue, New York

Cypher India 2024

September 25-27, 2024 | 📍Bangalore, India

Cypher USA 2024

Nov 21-22 2024 | 📍Santa Clara Convention Center, California, USA

Data Engineering Summit 2024

May 30 and 31, 2024 | 📍 Bangalore, India