The Critical Role of Application and Data Security, ETCISO
Artificial intelligence (AI) is rapidly transforming India’s next phase of digital growth. From financial services and healthcare to manufacturing and public services, AI, IoT, cloud computing and Digital Public Infrastructure are fundamentally reshaping how businesses operate, deliver services and engage with customers. At the same time, the digital ecosystem is becoming increasingly machine-driven, with AI systems, APIs and automated workflows interacting continuously with enterprise applications and sensitive data. As India emerges as a global hub for digital innovation, engineering talent and next-generation technologies, AI is expected to contribute over $500 billion to India’s economy by 2030 as per industry estimates.
However, the growth in digital innovation must be matched by the growth in cyber resilience. As applications, identities, APIs and data become increasingly distributed across multiple clouds, devices and AI ecosystems, the traditional perimeter-based approach to cybersecurity is no longer sufficient. The focus must therefore shift to securing the applications and data that power India’s digital future.
How AI adoption and cloud migration are reshaping cybersecurity
AI is fundamentally changing enterprise architecture. Modern AI systems are deeply integrated into business workflows, continuously interacting with enterprise applications, APIs and sensitive data. This creates unprecedented opportunities for automation and productivity but also introduces new pathways for cyberattacks.
Today, attackers are harnessing AI for sophisticated phishing campaigns, deepfakes and identity-based attacks. The 2026 Thales Data Threat Report found that 64% of organisations in India rank AI-enabled attacks among their top data security concerns, while 65% have already experienced deepfake-driven attacks. As organisations embed AI into critical business processes, gaps in identity governance, application security and data protection can be amplified at machine speed, making AI resilience a business imperative rather than simply another cybersecurity challenge.
Data visibility is the foundation of digital trust
As AI systems gain broader access to enterprise data, visibility has become the cornerstone of effective cybersecurity. Sensitive data today resides across hybrid and multi-cloud environments, SaaS platforms, APIs and AI ecosystems. However, many organisations continue to face challenges to understand where critical data resides and how it is being accessed.
According to the 2026 Thales Data Threat Report, only 35% of organisations in India know where all their data resides, while just 36% can fully classify their data. Without this foundational understanding, organisations cannot consistently enforce security policies, identify risks or respond effectively to emerging cyber threats.
However, visibility alone is not enough. It’s also important to understand the risk associated with their data and continuously protect it throughout its lifecycle. Data discovery, classification, encryption and continuous monitoring are becoming essential capabilities for safeguarding data throughout its lifecycle.
This shift is also reflected in India’s evolving regulatory landscape. The Digital Personal Data Protection (DPDP) Act encourages organisations to strengthen governance over personal data, making compliance not only a regulatory requirement but also an opportunity to build digital trust. At the same time, digital sovereignty is becoming crucial as organisations navigate cross-border data flows and evolving geopolitical scenarios.
Need for application security
In an AI-driven enterprise, applications have become the primary gateway to business operations, customer interactions and enterprise data. Every cloud-native application, API and AI-enabled workflow expands the digital ecosystem and with it, the potential attack surface.
According to the 2026 Thales Data Threat Report, 44% of organisations rank secrets management among their top application security challenges in India, reflecting the growing complexity of governing machine identities, API (application programming interface) keys, and tokens at scale. As siloed application security methods fail to track data at scale, centralise secret management, or secure sensitive data beyond access points alone, there is a growing need for an integrated approach where application and data security can no longer be treated as separate disciplines.
Building trust for the post-quantum cryptography era
As organisations increase AI adoption, preparing for emerging challenges such as quantum computing, evolving regulations and increasing demands for digital sovereignty is becoming more critical than ever before. Building cryptographic agility and adopting future-ready encryption for data in transit will enable organisations to transition more smoothly to post-quantum security while reducing the risk of “harvest now, decrypt later” attacks, where encrypted data intercepted today could be decrypted once quantum computing becomes viable. The evolving cybersecurity environment is also driving a growing trend toward vendor consolidation, as enterprises look to reduce complexity, improve data management and adopt unified platforms that simplify security operations.
As India progresses towards its vision of Viksit Bharat by 2047, organisations must prioritise data security, integrated application security, and cryptographic agility to harness AI responsibly, meet evolving regulatory expectations and build a secure and trusted future.
The author is Aditya Agarwal, Area Vice President of Application and Data Security (India), Thales.
Disclaimer: The views expressed are solely of the author and ETCISO does not necessarily subscribe to it. ETCISO shall not be responsible for any damage caused to any person/organization directly or indirectly.
Firewall Security Company India Complete Firewall Security Solutions Provider Company in India












