The Human Edge of AI: ManageEngine’s Subhalakshmi Ganapathy on Redefining Enterprise Security in the Cloud Era

Date:

Trending

Speaking with TechGraph, Subhalakshmi Ganapathy, Chief IT Security Evangelist at ManageEngine (Zoho Corp), discussed how the rapid adoption of hybrid and multi-cloud environments is redefining enterprise security by introducing new layers of complexity and blind spots that traditional defenses often overlook, and how the company’s unified platform is helping organizations bridge these gaps to build more adaptive and resilient security frameworks across distributed infrastructures.

- Advertisement -

She also spoke about ManageEngine’s Human-in-the-Loop model, which combines intelligent automation with human expertise to detect anomalies faster, prevent data manipulation, and ensure that AI-powered security systems operate responsibly within enterprise environments.

Read the interview in detail:

- Advertisement -

TechGraph: With organizations embracing hybrid and multi-cloud environments at scale, what blind spots in IT security do you believe are most underestimated today, and how should enterprises realistically address them?

Subhalakshmi Ganapathy: The shift to hybrid and multi-cloud environments, while accelerating innovation, introduces significant, yet underestimated, security blind spots. The two most critical threats are misconfigurations going unnoticed and inadequate monitoring of user activities.

Misconfigurations arise from the complexity of managing disparate security settings across different cloud providers. The speed of development often outpaces security reviews, leaving countless vulnerabilities. Simultaneously, without a unified view, unmonitored user and service account activities—whether malicious or accidental misconfiguration—can go undetected, allowing for a breach to escalate rapidly.

- Advertisement -

To address these blind spots, enterprises must pivot from a fragmented to a unified security approach. This involves adopting a unified security console across their infrastructure, including on-premises and multi-cloud environment, for continuous, automated misconfiguration detection across all environments. Concurrently, a robust Zero Trust Architecture (ZTA) must be implemented to enforce the principle of least privilege and provide context-based access control, effectively securing the new perimeter—the user identity.

TechGraph: Ransomware has evolved from opportunistic attacks to highly targeted operations. From your vantage point, how are enterprises misstepping in preparation, and what countermeasures actually work beyond the usual playbook of backups and patching? 

Subhalakshmi Ganapathy: As ransomware shifts to sophisticated, agentic AI-driven operations, enterprises are misstepping by over-relying on traditional defenses. The biggest blind spot is failing to recognize that attackers now conduct multi-stage campaigns, including credential-stealing and information theft, before locking data. Relying solely on backups and patching is a reactive strategy against a proactive, decision-making threat.

The key to effective countermeasures lies in building true resilience. Beyond backups, this means adopting AI and behavioral analytics technologies that can detect subtle initial deviations from a baseline—such as anomalous file access patterns or unusual lateral movement—and proactively isolate the threat at its inception. Continuous monitoring and micro-segmentation are crucial to prevent an attacker from moving laterally and escalating privileges. This approach focuses on minimizing the “dwell time” of an attacker, turning a potential disaster into a contained incident by identifying the early warning signs that traditional defenses miss.

TechGraph: Identity has become the new perimeter in security conversations. How do you see the role of Active Directory and IAM solutions shifting in the next three to five years as insider threats and credential misuse grow more sophisticated?

Subhalakshmi Ganapathy: In the next three to five years, the focus will shift from simply controlling human access to a more sophisticated, holistic identity fabric that treats non-human identities—such as bots, service accounts, and API keys—as a primary security concern.

Current IAM technologies often struggle with the ephemeral and autonomous nature of non-human identities. With multi-cloud and hybrid architectures, these identities are frequently created with excessive privileges, have poorly managed lifecycles, and lack the multi-factor authentication (MFA) that human accounts are required to use. Attackers are increasingly targeting these blind spots, exploiting a single over-privileged service account to achieve lateral movement and escalate their privileges across the entire enterprise.

In the next four to five years, machine identity management (MIM), will become one of the core competencies of IAM. We might see the maturation of purpose-built platforms that discover, manage, and secure machine identities. These solutions will focus on automating the entire lifecycle of credentials like certificates and API keys, ensuring they are automatically rotated, have short-lived lifecycles, and are never hard-coded into applications.

TechGraph: Many enterprises still see security as a reactive cost center rather than a business enabler. How do you convince C-level leadership to view IT security as an investment that directly impacts growth, resilience, and customer trust?

Subhalakshmi Ganapathy: The notion of security as a reactive, rules-based exercise is a dangerous relic of a bygone era. In today’s digital economy, IT security is a strategic business enabler—a fundamental investment in resilience, growth, and customer trust. C-level leaders now understand that a proactive security strategy is a form of business insurance that safeguards against the catastrophic financial impacts of downtime, regulatory fines, and reputational damage. When security is embedded into every business process, it becomes the foundation for trust and a powerful competitive differentiator. 

Therefore, even some of the most impactful compliance frameworks—from GDPR to NIST—have evolved far beyond simple audits. They are holistic security mandates that require a proactive posture.

This new reality demands implementing proactive risk frameworks to identify and mitigate threats before they materialize. It requires a clear data breach notification and a robust resilience framework to ensure business continuity in the face of an attack.

Consequently, security can no longer be seen as a separate, isolated cost center. It is an integral business function, inextricably linked to revenue, reputation, and operational longevity. 

TechGraph: With AI-driven cyberattacks becoming more practical, how can enterprises balance leveraging AI for defense while ensuring they don’t end up creating new attack vectors within their own infrastructure?

Subhalakshmi Ganapathy: Enterprises face a dual challenge with AI: leveraging its power for defense while mitigating the new security risks it introduces. The balance lies in treating AI not as a black box, but as a critical infrastructure component that requires stringent governance and human oversight. LLMs, while a formidable technology for anomaly detection, also creates new attack vectors like data poisoning, where adversaries corrupt training data to manipulate a model, or model evasion, where they craft inputs to bypass its defenses.

To counter this, a robust framework is essential. It starts with meticulous data flow management and privacy controls, ensuring that the data used to train AI models is secured and anonymized. You can’t protect what you can’t see; therefore, complete visibility into the data pipeline is crucial to detect any unauthorized tampering.

The most effective strategy, however, is a Human-in-the-Loop (HITL) implementation. This approach ensures a human expert validates the AI’s high-stakes decisions. It’s the necessary balance between AI’s speed and human judgment, significantly reducing the attack surface and preventing catastrophic errors. This controlled approach turns AI from a potential liability into a truly resilient and trustworthy defense mechanism.

TechGraph: Regulations and compliance frameworks are multiplying across regions and industries. How can global enterprises practically balance compliance with actual security priorities without drowning their IT teams in checklists?

Subhalakshmi Ganapathy: The multiplying regulations across the globe threaten to drown IT teams in fragmented checklists. The solution isn’t adding more of them; it’s a fundamental shift from a one-time task to a continuous business function.

Compliance isn’t a destination—it’s an ongoing journey that requires dedicated investment in people and technology. Relying on a static, yearly audit leaves enterprises dangerously exposed to evolving threats.

To ensure true security, organizations must embed compliance as a core, continuous function. 

Global enterprises must adopt  robust frameworks like NIST or ISO 27001 as their security foundation. These frameworks are designed to be comprehensive and risk-based, addressing a wide array of security controls that satisfy multiple regulatory requirements simultaneously. This eliminates redundant effort and frees IT teams to focus on impactful security work.

To make this practical, leverage automation and centralized governance. Use tools and technologies like SIEM  or GRC that continuously monitor compliance posture in real-time, freeing human teams from manual audits. This strategic shift transforms security from a reactive cost center into a business enabler, allowing the enterprise to operate compliantly and securely in any market.

TechGraph: ManageEngine serves a very diverse customer base across industries and geographies. From your experience, what patterns of security challenges cut across sectors, and where do you see the most urgent need for innovation?

Subhalakshmi Ganapathy: Across a diverse global customer base, a universal pattern of security challenge is that the sheer volume of security data, compounded by a severe skills shortage, overwhelms IT teams, leading to high false positives and alert fatigue. The most urgent need for innovation is not more tools, but security tech stack consolidation. We need to move beyond fragmented products to a unified security platform that brings more visibility and context to security data. This single platform should natively integrate core security functions like risk and policy management, data security, monitoring, and XDR, and apply AI layered over it for effective realisation.

This is one of the compelling reasons for us to evolve from a solution-based approach to platformization. Our unified security platform natively combines risk management, policy management, data security, monitoring, and XDR. This eliminates the tool-hopping and siloed data that exhaust security teams, providing a single pane of glass to view and manage threats across your entire hybrid environment.

Another challenge is the overwhelming volume of false alerts, a critical drain on security teams. The solution lies in advanced analytics powered by AI, which enriches security data and intelligently filters out the noise. This transforms a team’s focus from benign alerts to high-priority signals. To ensure a balance between speed and control, a Human-in-the-Loop (HITL) framework is essential. While automation handles the scale of data, human experts retain the final say, turning security from a reactive chore into a strategic, intelligence-driven function that truly protects the business.

THE SNAPSHOTS

Sign up to get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

- Advertisement -

Support our independent journalism PayPal (Outside India) For PayU (For Indian Readers).

Krishna Mali
Krishna Mali
Founder & Group Editor of TechGraph.

More Latest Stories

More Articles

How E-Commerce Growth is Redefining India’s Warehouse Infrastructure

India’s e-commerce sector has rewritten the rules of retail. What began as an urban experiment a decade ago has now evolved into one of...

From Paper Bonds to Digital Yields: The Evolution of Fixed-Income Investing in the Fintech Era

When India dematerialized equities and bonds in 1996, it transformed investing from paper to digital. Yet, while demat accounts fuelled an equity revolution, the bond market remained largely untouched. The reason was entry barriers. The minimum investment size for most bonds then was ₹10...

Empowering Creators: Studiobackdrops’ Archisman Misra on Making Professional Production Accessible Across India

Speaking with TechGraph, Archisman Misra, CEO and Founder of Studiobackdrops, discussed how India’s fast-growing...

Trade Gaia Emerges as a Key Player in Global Altcoin Trading

While Bitcoin continues to dominate headlines, the real growth in 2025 is coming from...

The Conversation Shift: Doceree CRO Thomas Shea on Making Healthcare Marketing More Relevant for Physicians

Speaking with TechGraph, Thomas Shea, Chief Revenue Officer (CRO) at Doceree, discussed how artificial...

Bajaj Financial Securities Acquires Stake in Lemnisk from Early Investors

Bajaj Financial Securities has acquired stakes in Bengaluru-based customer data platform Lemnisk through a...

The Role of Data Observability in Ensuring Operational Excellence

Did you know that a single voice interaction can generate nearly hundreds to thousands of unique data points?

Beyond Exam Scores: Simandhar Education’s Poonam Jain on Preparing Students for Global Finance Careers

Speaking with TechGraph, Poonam Jain, CFO and Co-founder of Simandhar Education, discussed how evolving...

How Fleet Maintenance Scheduling Supports Business Vehicle Performance

Managing a fleet of vehicles can be challenging for any business. From delivery vans to company cars, keeping each vehicle in optimal condition requires...

Exclusive Interview: True Colors CEO Satish Panchani on the ₹128 Crore IPO Plan

Speaking with TechGraph, Satish Panchani, CEO and Co-founder of True Colors, discussed how the...

Driving Financial Flexibility: FINQY’s Sunil Talreja on Closing India’s Credit Gap Through Car-Backed Lending

Speaking with TechGraph, Sunil Talreja, Business Head for Auto Loans and Car Par Loan...

Enduring Edge: Quickinsure’s Shailesh Patil on Strengthening Advisory-Led Insurance Distribution in India’s Heartland

Speaking with TechGraph, Shailesh Patil, Co-founder and CTO of Quickinsure, discussed how the company’s...

Cygnet.One appoints Dr. Pankaj Dikshit as Executive Director to drive AI-first digital transformation

Cygnet.One, a global provider of digital transformation and compliance technology solutions, has appointed Dr....

Roombr Taps Fayyaz Hussain as Chief Growth Officer to Drive Global Expansion

Roombr, an AI-driven digital classroom platform, has named Fayyaz Hussain as Chief Growth Officer to lead business expansion and fundraising. The appointment follows strong company...

Reimagining Parenthood: Dr Umesh Jindal on How AI and Genetics Are Shaping the Future of IVF Care in India

Speaking with TechGraph, Dr. Umesh Jindal, Director and Senior Consultant at Jindal IVF, discussed how genetics and precision diagnostics are shifting IVF from focusing only on conception to prioritising healthier outcomes, as tools such as PGT-M, PGT-SR, and PGT-HLA enable earlier detection of chromosomal...

Intelligent Energy Shift: Havells’ Dipesh Shah on Making Smarter and Affordable Appliances for Modern Indian Homes

Speaking with TechGraph, Dipesh Shah, CTO & Executive President, Havells Center for Research &...

6 Document Retention Policy Best Practices to Avoid Costly Legal Fines

If you can't find the right document when needed, you're not just wasting time....

Beyond Tax Savings: Probus CTO Anand Agarwal on Redefining Insurance for Modern Financial Security

In an interaction with TechGraph, Anand Agarwal, Chief Technology Officer of Probus, outlined how...

Structured STEM Learning: STEMROBO’s Anurag Gupta on Bringing Robotics and AI into India’s K-12 Education System

In an interaction with TechGraph, Anurag Gupta, CEO and Co-Founder of STEMROBO Technologies, outlined...

Proptech in Motion: Qubit’s Ajjay Parge on Bringing Immersive Visualization to the Real Estate Buying Experience

Speaking with TechGraph, Ajjay Parge, Founder of Qubit, discussed how the company’s real-time cinematic...

Staying Ahead of AI Scams: 63SATS Cybertech’s Srinivas L on How CYBX Is Protecting India’s Digital Users

In an interaction with TechGraph, Srinivas L, Joint Managing Director and Joint CEO of...

Beyond the Pitch Deck: Impactful Pitch’s Nikhil Parmar on Helping Founders Build Investor-Ready Narratives

Speaking with TechGraph, Nikhil Parmar, Founder of Impactful Pitch, outlined how India’s startup funding...

The Financial Imperative: Afthonia Labs’ Tanul Mishra on Strengthening India’s Fintech Startup Ecosystem

In an interaction with TechGraph, Tanul Mishra, Founder of Afthonia Labs, outlined how India’s...

The New Screen Economy: CloudTV COO Abhijeet Rajpurohit on Capturing India’s Affordable Smart TV Market

Speaking with TechGraph, Abhijeet Rajpurohit, COO and Co-founder of CloudTV, discussed how the company...

Enduring Edge: Quickinsure’s Shailesh Patil on Strengthening Advisory-Led Insurance Distribution in India’s Heartland

Speaking with TechGraph, Shailesh Patil, Co-founder and CTO of Quickinsure, discussed how the company’s...

India at the Center: The Judge Group’s Abhishek Agarwal on the Future of Global Delivery

Speaking with TechGraph, Abhishek Agarwal, President of Judge India and Global Delivery at The...

Why MSMEs Need High-Tech Learning Environments to Compete in a Digital Manufacturing Era

India’s manufacturing sector is changing faster than ever before. From automated assembly lines to...

Building India’s Financial OS: Prosperr’s Manas Gond on Redefining Personal Tax Management for Affluent Professionals

During an interview with TechGraph, Manas Gond, Co-founder and CEO of Prosperr.io, outlined how...

The Informed Buyer: Homesfy CEO Ashish Kukreja on Redefining the Home-Buying Experience

In an interaction with TechGraph, Ashish Kukreja, Founder and CEO of Homesfy, outlined how...

Cygnet.One appoints Dr. Pankaj Dikshit as Executive Director to drive AI-first digital transformation

Cygnet.One, a global provider of digital transformation and compliance technology solutions, has appointed Dr....

The Financial Imperative: Afthonia Labs’ Tanul Mishra on Strengthening India’s Fintech Startup Ecosystem

In an interaction with TechGraph, Tanul Mishra, Founder of Afthonia Labs, outlined how India’s...

The Data Economy Moment: Saafe’s Venkatesh Krishnamoorti on How Account Aggregation Is Reshaping India’s Financial Landscape

In an interview with TechGraph, Venkatesh Krishnamoorti, CEO and Managing Director of Saafe, discussed...

The New Screen Economy: CloudTV COO Abhijeet Rajpurohit on Capturing India’s Affordable Smart TV Market

Speaking with TechGraph, Abhijeet Rajpurohit, COO and Co-founder of CloudTV, discussed how the company...