'AI has Turned Cybersecurity into a Machine-Speed Battle': Indusface's Ashish Tandon
Artificial intelligence is redefining cybersecurity, empowering both defenders and attackers with unprecedented speed and scale. While organizations are leveraging AI to strengthen threat detection and automate security operations, cybercriminals are using the same technology to launch more sophisticated phishing campaigns, discover vulnerabilities faster, and bypass traditional defenses.
As AI-powered applications and APIs become central to modern enterprises, security teams face an increasingly complex challenge. Organizations must not only identify vulnerabilities in real time but also reduce exposure windows through automated remediation, continuous monitoring, and intelligent threat detection to stay ahead of evolving attacks.
Ashish Tandon, Founder & CEO of Indusface, believes cybersecurity has entered a machine-speed era where success depends on combining AI-driven automation with human judgment. In an exclusive interview with Analytics Insight, he discusses the rise of AI-powered cyberattacks, API security risks, cyber resilience, and the strategies organizations must adopt to defend against the next generation of AI-driven threats.
How are AI-Powered Cyberattacks Evolving?
AI-driven attacks are becoming single-minded: models now chain vulnerabilities to reach an objective, with no regard for boundaries. A few days back, OpenAI disclosed that its own models escaped a sandboxed test and breached systems just to win a benchmark. It is the second such documented incident, after Anthropic disrupted a Claude-driven espionage campaign earlier. With similar tooling now in hackers' hands, many more are likely happening undetected.
How Can Organizations Stay Ahead of AI-Driven Threats?
Attackers now scan for vulnerabilities at machine speed. Defenders must match that by deploying AI-driven testing internally or through a specialized partner. But finding vulnerabilities faster only helps if remediation moves just as fast. Finding ways to close the vulnerability exposure window autonomously is now hygiene.
What are Today's Biggest API Security Risks?
The biggest API security challenge is the unknown attack surface. In our experience, enterprises typically have 30 to 40 percent more APIs in production than their internal inventories reflect: shadow APIs spun up by other teams, zombie APIs left running after deprecation, and endpoints that never made it into documentation. More recently, we are seeing AI endpoints that can be tricked by plain text malicious commands, which are also called prompt injections.
How Can Enterprises Build AI-Driven Cyber Resilience?
Resilience and speed don't have to trade off if defence moves at the same pace as development. Continuous monitoring and threat intelligence find the gaps; autonomous virtual patching closes them at machine speed. Adopting edge-based protections therefore buys much-needed time for code-level interventions without compromising release cadence. Security stops being the brake and becomes the guardrail that runs alongside the build.
What will Define Cybersecurity in AI Era?
The core challenge won't change: it's still attackers versus defenders, just running at machine speed on both sides, as Hugging Face showed. CISOs need AI running discovery and remediation continuously, with a human-in-the-loop process for exceptions. Speed without judgment creates new risk; judgment without speed loses the race.
.png)
