Choosing the Right Battles: CISO Leadership in a Time of Constant Disruption
Rishi (CISO · HCL Tech), M. A. K. P. Singh (Visiting Professor and Chief Technical Officer · IIT Kanpur and CyberPeace)
Nullcon Goa 2026 · Day 1
Overview
In an era defined by accelerating digital transformation, rapidly evolving cyber threats, and the pervasive integration of artificial intelligence, the role of the Chief Information Security Officer (CISO) has become increasingly complex and demanding. This Nullcon fireside chat, "Choosing the Right Battles: CISO Leadership in a Time of Constant Disruption," brought together Rishi, CISO for HCL Tech, and M. A. K. P. Singh, Visiting Professor at IIT Kanpur and CTO at CyberPeace, moderated by Abhishek Bansal of Axis Bank Life Insurance, to discuss how security leaders can effectively navigate this turbulent landscape. The core challenge explored is the paradox where if "everything is critical," then, by definition, "nothing is," leading to resource dilution and potential strategic missteps.

Key moments
- 0:00 Speakers' introduction and context for CISO leadership
- 2:40 Addressing the challenge: when everything is critical
- 3:40 Rishi's decision filter: situational and ecosystem awareness
- 5:35 Defining priority in business terms, not just CVSS
- 6:30 M.A.K.P. Singh: Importance of comprehensive log collection
- 7:40 Formation of Caesar for power sector incident response
- 8:40 Moderator asks about what to deprioritize
Choosing the Right Battles: CISO Leadership in a Time of Constant Disruption
Speakers: Rishi, CISO, HCL Tech; M. A. K. P. Singh, Visiting Professor and Chief Technical Officer, IIT Kanpur and CyberPeace
Conference: Nullcon
YouTube: https://www.youtube.com/watch?v=ca6OhwKN9OE
Overview
In an era defined by accelerating digital transformation, rapidly evolving cyber threats, and the pervasive integration of artificial intelligence, the role of the Chief Information Security Officer (CISO) has become increasingly complex and demanding. This Nullcon fireside chat, "Choosing the Right Battles: CISO Leadership in a Time of Constant Disruption," brought together Rishi, CISO for HCL Tech, and M. A. K. P. Singh, Visiting Professor at IIT Kanpur and CTO at CyberPeace, moderated by Abhishek Bansal of Axis Bank Life Insurance, to discuss how security leaders can effectively navigate this turbulent landscape. The core challenge explored is the paradox where if "everything is critical," then, by definition, "nothing is," leading to resource dilution and potential strategic missteps.
The discussion delves into practical strategies for prioritization, fostering shared accountability beyond the security team, and leveraging emerging technologies like AI to enhance defense while managing inherent risks. The speakers emphasize moving beyond reactive firefighting to a proactive, business-aligned security posture. This talk is crucial for current and aspiring CISOs, security architects, and business leaders seeking to understand how to build resilient cybersecurity programs that effectively support organizational objectives amidst relentless disruption, focusing on strategic decision-making and the human element of security.
Background
▶ Watch: Speakers' introduction and context for CISO leadership (0:00)
The contemporary cybersecurity landscape presents an unprecedented array of challenges for organizational leadership. As highlighted by the moderator, Abhishek Bansal, cyber threats are escalating in frequency and sophistication, while technologies like Artificial Intelligence (AI) are advancing at a pace that often outstrips the ability to implement effective governance. New technologies emerge constantly, blurring the lines between development and security, particularly with the rise of cloud security. Simultaneously, regulatory bodies are becoming increasingly prescriptive, imposing stringent guardrails and compliance requirements on technology and business leaders.
This confluence of factors creates immense pressure on CISOs. The pervasive sentiment that "everything is critical" makes it difficult to ascertain genuine priorities, leading to a reactive stance that can overwhelm security teams and exhaust resources. As Rishi succinctly puts it, "if everything is critical, then pretty much nothing is." The traditional approach of addressing every perceived threat equally is unsustainable and ineffective. Furthermore, Mr. Singh points out the perennial challenges faced by CISOs: securing adequate manpower and funding, justifying the Return on Investment (ROI) for security expenditures, and overcoming the perception of security as a cost center rather than an enabler of business value. This backdrop necessitates a fundamental shift in how CISOs approach their role, moving from a purely technical enforcement function to a strategic leadership position focused on informed decision-making and business alignment.
Key Findings
▶ Watch: Rishi's decision filter: situational and ecosystem awareness (3:40)
The fireside chat unveiled several key findings and strategic approaches for CISOs navigating the current landscape:
- Prioritization through Awareness: Rishi introduced a two-pronged framework for effective prioritization:
- Situational Awareness: Understanding external threats (e.g., new AI developments) and, crucially, how the organization intends to use these external elements. This moves beyond fear-based reactions to strategic evaluation of business intent.
- Ecosystem Awareness: Recognizing both the external ecosystem (partners, industry peers) for leveraging collective intelligence, and the internal organizational ecosystem (partner teams, business units). This clarifies who is involved and what capabilities exist, enabling security to be discussed in business terms rather than just technical vulnerabilities (e.g., "CV 9.99").
- Shared Accountability and Business Alignment: A fundamental shift proposed is that security should not be solely the prerogative of the CISO or the cybersecurity team. Instead, it must be a shared accountability across tech teams, business units, and even end-employees. CISOs' responsibility lies in building this understanding by translating technical risks into business impact. For example, instead of just saying "AI is bad," articulate the risk to specific data or business use cases, and propose guardrails that enable business value.
- Strategic Deprioritization via Visibility: Effective prioritization inherently involves deprioritization. Mr. Singh and Rishi both highlighted that robust visibility into the organization's assets and threat landscape is paramount. With good visibility, CISOs can identify and address the most critical "crown jewels" first, allowing other issues to be handled subsequently, rather than attempting to tackle everything simultaneously on day zero.
- Leveraging Automation with Caution (Especially AI in OT): The immense volume of threats necessitates automated solutions. Mr. Singh discussed the role of Security Orchestration, Automation, and Response (SOAR) and agentic AIs in helping SOC teams manage alert fatigue and automate responses. However, he emphasized the need for caution, particularly in Operational Technology (OT) environments within critical sectors like power, where the immediate implementation of AI-driven SOAR is being delayed to build trust and ensure reliability, given the potential for "data poisoning" or unintended consequences.
- Focus on Foundational Security and Continuous Learning:
- Comprehensive Logging: Mr. Singh stressed the absolute necessity of collecting logs from all connected and communicating devices to enable full attack path tracing and early detection.
- Centralized Incident Response: The creation of Caesar (Cyber Security Incident Response Team) for the power sector, acting as a "mother SOC" aggregating logs from 350 utilities, demonstrates a strategic approach to centralized visibility and response using SIEM solutions.
- Identity as the Core: Rishi advised new CISOs to "double down on identity as the focus," highlighting it as a critical vector in modern security.
- Refining from Incidents: Mr. Singh advocated for continuous learning, stating that CISOs must refine their approach every time an incident occurs or new knowledge emerges from others' attacks, emphasizing Mean Time to Detection (MTTD) as a crucial metric.
- Beyond Textbook Approaches: Both speakers agreed that the rapid evolution of the threat landscape demands that CISOs think "beyond the textbook," anticipating attacker intent rather than solely relying on established security doctrines. This requires adaptability, a willingness to seek help, and a focus on fundamental, impactful security controls.
Technical Deep Dive
▶ Watch: Defining priority in business terms, not just CVSS (5:35)
While the talk was a fireside chat focused on leadership, several critical technical and architectural considerations were discussed, underscoring the foundation upon which effective CISO leadership rests.
A cornerstone of effective cybersecurity, as articulated by M. A. K. P. Singh, is comprehensive logging. He stressed the importance of collecting logs from all devices that connect or communicate on the network. Without complete log visibility, tracing an attack path becomes impossible. He provided a concrete example: if an organization fails to detect a login failure on a printer, an attacker might leverage that initial compromise to access a device server, ultimately leading to data exfiltration. The ability to trace such an attack relies entirely on the availability of granular log data from every potential point of compromise. This foundational visibility is essential for detecting impacts and understanding the scope of an incident, regardless of whether the threat originates internally or externally.
Building on the need for visibility, Mr. Singh detailed the strategic initiative within the power sector: the formation of Caesar (Cyber Security Incident Response Team). This entity serves as a "mother SOC," aggregating and monitoring logs from approximately 350 utilities and their associated devices. Currently, this centralized monitoring leverages a Security Information and Event Management (SIEM) solution. The SIEM acts as the central repository and analysis engine for the vast volume of logs collected, enabling correlation and detection of suspicious activities across a critical national infrastructure.
The discussion also touched upon the future of security operations with AI and SOAR (Security Orchestration, Automation, and Response). Mr. Singh acknowledged that agentic AIs could significantly assist SOC teams in automating responses, thereby mitigating the overwhelming alert fatigue caused by the sheer quantum of incoming threats. However, he expressed significant caution regarding the immediate implementation of SOAR, especially in Operational Technology (OT) environments within the critical power sector. The concern stems from the potential for AI to "poison your data" or introduce unforeseen risks in highly sensitive industrial control systems. This highlights a critical technical challenge: building sufficient trust and validating the reliability of AI-driven automation before deploying it in environments where errors could have catastrophic real-world consequences. The current strategy is to first gather comprehensive visibility and then, cautiously, build trust in AI solutions before full SOAR implementation in OT.
Rishi further elaborated on the application of technical controls in the context of emerging technologies, specifically AI use cases. He discussed how to approach Data Loss Prevention (DLP) and risk management for AI solutions. Instead of a blanket ban or generic "bad" assessment, he proposed a tiered risk categorization based on business impact:
- Low-risk use cases: Such as summarizations or extraction of outcomes, which might have minimal data exposure or impact.
- Medium-risk use cases: Involving some decision-making capabilities, requiring more robust controls.
- High-risk use cases: Fully autonomous solutions, which would necessitate the most stringent guardrails and security measures due to their potential for significant business impact if compromised or misused.
This approach demonstrates a technical strategy for aligning security controls with business value, ensuring that appropriate safeguards are implemented without unduly hindering innovation.
The speakers also brought up specific technical failures and their consequences. Mr. Singh cited the Jaguar Land Rover attack as a prime example of how a seemingly minor technical oversight can lead to massive financial losses (1.9 billion pounds). The attack exploited a Jira server compromise, where a password stolen six years prior was still in use. This incident underscores the critical importance of basic but often overlooked security hygiene, such as robust password policies (e.g., regular changes, uniqueness across systems) and continuous vulnerability management.
Finally, Rishi's advice to new CISOs to "hone in double down on identity as the focus" is a profound technical recommendation. In modern, perimeter-less environments, Identity and Access Management (IAM) has become the new control plane. Securing identities, implementing Multi-Factor Authentication (MFA), and managing access privileges effectively are fundamental technical pillars for protecting an organization's assets against an increasingly sophisticated threat landscape.
Demo / Proof of Concept
▶ Watch: Formation of Caesar for power sector incident response (7:40)
This session was a fireside chat, an interactive discussion between the speakers and a moderator. As such, it did not include any live demonstrations, technical walkthroughs, or proofs of concept. The content focused on strategic insights, leadership principles, and theoretical frameworks for navigating cybersecurity challenges.
Defensive Implications
▶ Watch: Moderator asks about what to deprioritize (8:40)
The insights shared by Rishi and M. A. K. P. Singh offer a comprehensive roadmap for strengthening defensive postures in a dynamic threat environment. For defenders, the core message is to move from reactive firefighting to proactive, business-aligned security strategies.
Firstly, prioritization must be strategic and business-driven. Defenders should implement frameworks for situational awareness (understanding both external threats and internal business use cases) and ecosystem awareness (internal teams, external partners). This allows security teams to articulate risks in business language, ensuring that resources are allocated to protect the organization's most critical assets, its "crown jewels," rather than being spread thin across all perceived threats.
Secondly, foundational security hygiene remains paramount. Mr. Singh's emphasis on comprehensive log collection from all connected devices is non-negotiable. Organizations must invest in robust logging infrastructure to ensure that every event, from a printer login failure to a critical server access, is recorded and auditable. This provides the essential data for effective threat detection, incident response, and forensic analysis. Building on this, implementing centralized SIEM solutions, potentially evolving into "mother SOCs" for large enterprises or critical sectors (like the Caesar initiative), is crucial for aggregating, correlating, and analyzing this vast log data to gain holistic visibility.
Thirdly, strategic adoption of automation and AI is critical but requires caution. While SOAR platforms and agentic AIs offer significant potential to combat alert fatigue and automate responses, particularly for high-volume threats, their deployment, especially in Operational Technology (OT) environments, must be approached with deliberate care. Defenders should prioritize building trust, validating AI models, and understanding potential risks like "data poisoning" before full-scale implementation in critical infrastructure. For non-OT environments, phased adoption and rigorous testing can help harness AI's benefits while mitigating risks.
Fourthly, fostering shared accountability is essential for execution. CISOs and security teams must actively engage with business and technology leaders to translate technical risks into business impact. This involves moving beyond simply stating a vulnerability's severity score and instead explaining the potential financial, reputational, or operational consequences. By framing security as an enabler of business value and providing clear guardrails (e.g., for AI use cases categorized by risk), organizations can cultivate a culture where security is a collective responsibility, not just the CISO's problem.
Fifthly, identity management must be a primary focus. Rishi's advice to "double down on identity" highlights its status as the modern security perimeter. Defenders should prioritize robust Identity and Access Management (IAM) programs, including strong authentication mechanisms (MFA), least privilege access principles, and continuous monitoring of user behaviors.
Finally, continuous learning and adaptability are crucial. The example of the Jaguar Land Rover attack (a 6-year-old password in Jira leading to a 1.9 billion pound loss) underscores the need for vigilant enforcement of basic security policies, such as strong and regularly changed password policies. Organizations must constantly refine their security posture based on lessons learned from internal incidents and external attack trends, aiming to reduce Mean Time to Detection (MTTD) as a key performance indicator. This requires CISOs to lead with an open mind, willing to seek help and move "beyond the textbook" to anticipate and counter evolving threats.
Key Takeaways
- Strategic Prioritization is Paramount: CISOs must move beyond treating everything as critical by developing situational and ecosystem awareness to align security efforts with genuine business value and risk tolerance.
- Shared Accountability is Non-Negotiable: Security is a collective organizational responsibility, not solely the domain of the CISO. Leaders must translate technical risks into business language to foster shared ownership and drive effective implementation of security controls.
- Foundational Visibility is Essential: Comprehensive log collection from all network devices, coupled with centralized monitoring via SIEM solutions (and potentially "mother SOCs" in critical sectors like power), forms the bedrock for effective threat detection and incident response.
- Cautious, Strategic AI Adoption: While SOAR and agentic AIs offer significant potential to combat alert fatigue and automate security operations, their implementation, especially in Operational Technology (OT) environments, requires careful validation and trust-building to mitigate risks like "data poisoning."
- Identity as the New Perimeter: In a rapidly evolving threat landscape, focusing intensely on Identity and Access Management (IAM), including strong authentication and access controls, is a critical defensive vector that CISOs should prioritize.
- Continuous Learning and Adaptability: CISOs must constantly refine their security strategies based on lessons learned from incidents (e.g., improving Mean Time to Detection) and external attacks, moving "beyond the textbook" to anticipate attacker intent and effectively defend against emerging threats.
About the Speaker(s)
Rishi serves as the CISO for HCL Tech, a role he has held for over four years. He views his primary responsibility as building trust within the entire ecosystem, encompassing partners, customers, and internal stakeholders. His approach to cybersecurity leadership emphasizes strategic decision-making and business alignment over purely technical enforcement.
M. A. K. P. Singh is a distinguished figure in cybersecurity, having retired in 2024 as the CISO for the Ministry of Power. Following his retirement, he joined IIT Kanpur as a Visiting Professor of Practice and also serves as the Chief Technical Officer with CyberPeace. With extensive experience spanning 7 to 8 years, he has worked closely with power sector utilities, OEMs, and solution providers, playing a crucial role in developing cybersecurity guidelines for critical sectors.
Abhishek Bansal moderated the fireside chat. He is responsible for risk and cybersecurity at Axis Bank Life Insurance, bringing an industry perspective to the discussion on CISO challenges and leadership.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
A fireside chat that stays firmly in the executive/leadership lane — but judged even there, it's thin. The speakers have real credentials and drop a few concrete details (Caesar/mother SOC for 350 power utilities, the Jaguar Land Rover Jira compromise), but the bulk of the session is generic CISO advice dressed in slightly different clothes. Nothing here would change how a peer CISO plans tomorrow.
Heather Calloway (CISO) — SOLID
A competent fireside chat between two experienced practitioners that surfaces real CISO pressures — prioritization, shared accountability, AI governance — without breaking new ground or producing a usable decision framework. The institutional experience is genuine, but the insights land as affirmations for people already in the room, not challenges that change how anyone operates.