Proofpoint doubles down on India amid rising cybercrimes, calls AI agents the new insider risk
Proofpoint is stepping up its India focus as AI adoption accelerates and cyber threats become more sophisticated. In an interview with ET, Bikramdeep Singh discusses the growing risks from autonomous AI agents, the shift towards intent-based threa...

Bikramdeep Singh, Vice President, India & SAARC, Proofpoint
Cybersecurity firm Proofpoint recently expanded its security portfolio with two new agentic systems designed to automate risk detection, investigation and remediation across AI, enterprise data and collaboration tools. The company is also stepping up its focus on India, where its business has tripled over the past year and it plans to hire more than 200 engineers for an AI Security Engineering Centre of Excellence in Hyderabad.
On the sidelines of the company's flagship event, Proofpoint Protect 2026 in San Diego, California, Bikramdeep Singh, Vice President, India & SAARC, Proofpoint, spoke to The Economic Times about the evolving threat landscape, the risks posed by agentic AI and the company's strategy for India. Edited excerpts:
Q1. With some AI leaders calling for a slowdown in development, do you believe AI is moving faster than companies can govern and secure it? Where do you see the biggest gap today — regulation, enterprise controls or security?
The calls for a slowdown are about frontier model development — a handful of AI labs weighing how fast to push the next generation of models. That's a separate conversation from enterprise AI adoption, which is not slowing down and shouldn't.
We've been here before. Cybersecurity has always had to move alongside new waves of technology — the shift to cloud, the shift to remote work. Each one carried new risks, and each time, the answer wasn't to slow the business down, but to build governance and security in step with adoption.
Q2. Most enterprise AI use today is still AI-assisted, but agentic AI is moving towards autonomous action. What changes when AI agents start acting on their own inside an enterprise?
The simplest way to put it: AI agents are your insider risk, amplified by machine speed. Insider risk has always existed: a person with access who makes a mistake or gets compromised. What agentic AI does is remove the human pace limit on that risk. An agent with standing access to your systems can search, combine and act across data at a speed no person ever could, which means a single bad prompt or manipulated instruction can trigger consequences across connected systems almost instantly.
That means the access controls and forensic visibility we've always built for human identities now have to extend to every AI agent in the enterprise. If it can act on its own, it needs to be governed like an identity, not just deployed like software.
Q3. AI is also making attacks more sophisticated and personalised. How is it changing the way attackers operate?
An attacker can now generate a flawless, context-aware phishing email, mimic a specific colleague's writing style for a business email compromise attempt, or map an organisation's structure, all in minutes.
Q4. As attacks increasingly use legitimate accounts and trusted identities, how difficult is it for companies to distinguish between a genuine user and an attacker?
It comes down to one word: Intent. When an attacker is operating through valid, legitimate credentials, authentication tells you nothing — the login checks out every time, the account is real, the conversation looks familiar. Behaviour alone can even look normal.
That's why the industry is having to move past rule-based and even purely behavioural detection, towards reasoning about intent — what is this interaction actually trying to accomplish, and is that plausible given the context? That's a much harder problem to solve than checking whether someone has the right password, but it's the only thing that still works once the credentials themselves can't be trusted.
Q5. Proofpoint talks about securing AI and data together. Why do you think those two areas now need to be treated as one security problem?
As companies speed up AI adoption, one problem keeps surfacing: data exposure risk. And the challenge isn’t just finding where sensitive information lives — it's controlling who, and what, can access it. Today, that data is sprawled across SaaS, cloud and on-premises systems, and the identities touching it aren't just people anymore — they include service accounts and AI agents too.
Historically, security tools were built to see one half of that picture. An AI security tool can see what an agent is trying to do, but not the sensitive data behind that action. A data security tool can see where sensitive data lives, but not what the AI's intent is. Once you have AI agents pulling from live systems constantly, that gap is exactly the blind spot that gets exploited — whether by an attacker or by an AI agent accessing something it shouldn't.
That's why we don't treat AI security and data security as two adjacent products. If an AI agent is meant to retrieve information from a specific system to generate a response, you need to know, in real time, that it’s touching only what it's authorised for, not reconstruct that after the fact from two disconnected tools. You cannot secure AI without securing the data it acts on, and you cannot secure data without understanding how AI is using it.
Q6. Proofpoint has increased its focus on India. What's driving that focus, how much are you investing here, and how important is India to your global AI-security strategy?
Three things are converging in India at once: rapid AI adoption, an increasingly sophisticated threat landscape, and a new era of data protection through the DPDPA. That combination is exactly where our approach to securing data and AI together matters most, and it's why we're doubling down here.
Proofpoint's India business has tripled year-on-year, with double-digit growth in new customer acquisition and seats protected up more than 600% over the past 18 months. We've recently opened a new Delhi office to bring sales, customer success and partner support closer to customers, and we're building an AI Security Engineering Centre of Excellence in Hyderabad, with plans to hire more than 200 engineers over the next 12 to 24 months — to advance capabilities from our recent Acuvity acquisition in AI governance and runtime protection.
India isn't a satellite market for us. It's a strategic location for the next generation of AI security innovation, and it's one of the fastest-growing cybersecurity markets in the world, so it plays a central role in our global AI security strategy.
Q7. As companies rush to adopt AI, are you seeing security spending rise alongside that adoption, or are companies having to work within existing cybersecurity budgets?
For most CISOs, that spend still isn't keeping pace with the mandate they've been handed. Our own 2026 Voice of the CISO report found that 92% of Indian CISOs are expected to manage AI-related risks over the next two years without a proportional increase in resources or expertise. Security leaders are being asked to secure and champion AI adoption at the same time, largely within the budget and headcount they already have.
And we are also seeing consolidation in security spending, which has been underway for several years, but AI is accelerating the need for it. Organisations running large numbers of security vendors are finding that every additional tool adds vulnerabilities and patching overhead — the more security tools an organisation has, the more vulnerabilities and patches it has to manage. So instead of continuing to expand their security estates, enterprises are standardising around a smaller number of strategic pillars: XDR, security operations, identity, SASE and finally human and agent-centric security.
The Economic Times Business News App for the Latest News in Business, Sensex, Stock Market Updates & More.