Bhavya Bhandari's avatarPerson

Bhavya Bhandari

Cybersecurity Risk Management Leader | Financial ServicesERNST AND YOUNG US LLP

Atlanta, GA

About

Technology and cyber risk leader with 15+ years of experience leading large‑scale security, regulatory, and risk transformation programs for global financial services organizations. Trusted advisor to executive leadership and boards, specializing in cyber strategy, integrated GRC, and exam preparedness across global frameworks and regulations. Proven track record of building and scaling risk programs, leading complex stakeholder ecosystems, and translating regulatory and cyber risk into measurable business and resiliency outcomes.

Published content

Cloud Forensics: How to Prepare Before a Cyber Incident

expert panel

As companies move more critical systems and data into cloud and SaaS environments, investigating a cyber incident can become a complicated exercise in reconstructing events across systems an organization doesn’t fully control. If important evidence is unavailable or incomplete, determining what happened—and demonstrating what did or didn’t happen—can become much harder. NIST’s work on cloud forensics highlights the distinct challenges investigators face when collecting and analyzing evidence in cloud computing environments.Access to that evidence isn’t always a given. In 2024, CISA, OMB and ONCD worked with Microsoft to expand cloud audit logging for federal customers regardless of license tier and increase default retention from 90 to 180 days, part of a broader push to make critical security logs available without added licensing barriers. That highlights a larger business risk: An organization may discover the limits of its forensic visibility only after an incident, when legal teams, regulators and insurers are looking for clear answers.Cybersecurity leaders therefore need to look beyond whether their cloud environments can detect suspicious activity and determine whether those environments can support a credible investigation after a breach or other security incident. Members of the Senior Executive Cybersecurity Think Tank bring deep experience in enterprise security, incident response, risk management, regulatory compliance and cloud security. Below, they examine how leaders can strengthen forensic readiness before an incident occurs and where evidence gaps can create the greatest problems once an investigation is underway.

External AI Agents: How Security Leaders Can Reduce Cyber Risk

expert panel

Cybersecurity teams have always had to distinguish legitimate activity from malicious activity, but external AI agents make that judgment call harder. Unlike a conventional user session or scripted bot, an agent can pursue a goal across multiple steps, adapt as conditions change and operate at a speed and scale that can far exceed human activity.The challenge grows when organizations are interacting with agents they didn’t build, deploy or directly control. Those agents may be acting on behalf of customers, vendors or business partners—or probing systems for an attacker—and their behavior can evolve in real time. In a recent real-world example, AI agents run internally by OpenAI found an unintended path to the internet while trying to complete an evaluation, then breached Hugging Face systems in an effort to obtain information that could help them finish the task. The incident illustrates how quickly an autonomous system can move beyond the boundaries its operators expected.For cybersecurity leaders, that raises a broader question: How do you defend systems when the actor at the other end may be autonomous, adaptive and outside your control? Members of the Senior Executive Cybersecurity Think Tank bring deep expertise in enterprise cybersecurity, risk management, threat detection and modern security architecture. Below, they explore how defensive strategy should evolve as external AI agents become more capable and which protections matter most when agent-driven activity originates beyond the organization.

Beyond Patching: How to Balance CVE Remediation With Real Risk Reduction

expert panel

The technology businesses depend on every day also creates openings for attackers, and the vulnerability queue isn’t getting shorter. CVE submissions to NIST's National Vulnerability Database increased 263% between 2020 and 2025, and submissions in the first three months of 2026 were nearly one-third higher than during the same period a year earlier. For security teams, that volume makes treating every newly disclosed flaw as an isolated problem increasingly difficult—and risks turning vulnerability management into an endless cycle of finding, prioritizing and patching.Security leaders need to look beyond individual CVEs and address the recurring weaknesses that keep generating new vulnerabilities. Recent analysis of more than 39,000 CVE records highlights how identifying recurring root causes can inform security investments and development practices aimed at eliminating entire classes of defects. The challenge for security leaders is doing that longer-term work without losing sight of vulnerabilities that pose an immediate threat to the business.Members of the Senior Executive Cybersecurity Think Tank bring deep experience in enterprise cybersecurity strategy, risk management, threat detection, secure architecture and breach prevention. Below, three of them share how security leaders can balance urgent remediation with a more systemic approach to vulnerability management—reducing today’s risk while working to prevent the same kinds of flaws from resurfacing tomorrow.

How Security Leaders Can Adapt Cyber Defenses for Frontier AI

expert panel

Cybersecurity has long been a race between attackers trying to get in and defenders trying to keep them out. But frontier AI is changing the pace of that race. By helping threat actors discover vulnerabilities, conduct reconnaissance and experiment with attack techniques more quickly and at a greater scale, AI can shrink the time security teams have to recognize a threat and respond before it causes damage. Offensive activities that once took weeks can increasingly be compressed into minutes. That shift also challenges a more fundamental assumption behind traditional detection: that defenders will recognize enough of an attack to know what they’re looking for. Frontier AI can help adversaries vary techniques, combine attack methods and explore unfamiliar paths at a scale that makes relying primarily on established signatures, indicators and playbooks increasingly risky. Cybersecurity guidance is consequently evolving toward models that account for AI-enabled attacks while also using AI to strengthen defense and proactively address emerging threats.Preparing for that environment means looking beyond how quickly an organization can identify an attack to how much room for maneuver its systems leave an attacker in the first place. Members of the Senior Executive Cybersecurity Think Tank share deep expertise in enterprise cybersecurity strategies, data breach prevention, risk management, threat detection and modern security architecture. Below, they explore how security leaders should adapt their defenses for an AI-accelerated threat landscape and which capabilities are becoming most important.

From Siloed Alerts to Unified Action: Moving Beyond Detection-Centric Cybersecurity

expert panel

An attacker who gains access through a stolen credential may quickly move across devices, cloud resources and network systems in search of valuable data or greater control. Each step can generate clues, but when those signals land in separate tools and queues, security teams may struggle to recognize the full attack before the damage spreads.This challenge is becoming harder to tackle as traditional boundaries between users, devices, applications and infrastructure continue to dissolve. NIST’s zero-trust guidance reflects that shift, moving security away from static, network-based perimeters and toward continuous decisions based on users, assets and resources. This same erosion of boundaries is what makes it harder to catch attackers who don’t need to break anything to move around. CISA’s guidance on identifying and mitigating “living off the land” techniques warns that attackers can abuse legitimate, trusted tools and processes to blend in with normal system activity, making isolated alerts harder to interpret without broader context.Yet many organizations still measure security effectiveness largely by how well they detect suspicious activity. Detection remains essential, but alerts alone don’t determine which risks matter most, coordinate action across environments, or help the business continue operating when defenses fail. That requires an approach that connects visibility with timely decisions, enforceable controls and plans for maintaining and restoring critical operations.Moving beyond a detection-centric model means reconsidering how security data, decisions and defenses work together across the enterprise. Below, members of the Senior Executive Cybersecurity Think Tank—with expertise in enterprise cybersecurity strategies, data breach prevention, risk management, threat detection and cybersecurity leadership—explain what a more unified, real-time approach to visibility, control and resilience should look like.

Beyond Vendor Checklists: A Better Approach to Third-Party Cyber Risk

expert panel

Companies rarely operate wholly within their own digital walls anymore. Critical business functions now depend on cloud platforms, software components, contractors, service providers and sprawling networks of suppliers, with each trusted relationship creating another possible route into an organization. And the risk is growing: Verizon’s 2026 Data Breach Investigations Report found that breaches involving third parties had increased 60% from the previous year’s dataset, accounting for 48% of all breaches analyzed.For attackers, compromising a well-connected partner can be faster and more effective than challenging each target’s defenses directly. A 2025 GitHub Action supply chain compromise demonstrated how a tool embedded in development workflows could expose credentials and other sensitive information across downstream users. Yet many organizations still evaluate cyber risk from outside partners primarily through questionnaires and scheduled reviews—methods that document security practices but often fail to reveal how risks, access or dependencies have changed since the assessment was completed.Reducing third-party cyber risk now requires organizations to look beyond whether a vendor passed an assessment and consider how trusted relationships affect their security and resilience over time. Below, members of the Senior Executive Cybersecurity Think Tank—with expertise in enterprise cybersecurity strategy, data breach prevention and risk management—explain what effective third-party risk reduction looks like today and where (and why) companies must move beyond checklist-driven oversight.

Company details

ERNST AND YOUNG US LLP

Industry

Management Consulting

Company size

10,001 plus