Skills
About
Over the past two decades, I’ve contributed to transformative IT initiatives across India, the UK, and the US, working with Fortune 500 clients to build, modernize, and optimize complex systems that drive business and operational excellence. My journey began in Management Information Systems (MIS), where I developed a deep appreciation for the power of data-driven decision-making. From there, I expanded my expertise into Supply Chain Management, Retail Store Systems, HR People Systems, and Warehouse Management — gaining a holistic understanding of enterprise operations and the critical role of technology in driving efficiency and growth. Over the last decade, I transitioned my focus to Healthcare IT, specializing in Pega PRPC architecture and administration, emphasizing system modernization, security, and performance optimization. My work in legacy system modernization, DevSecOps implementation, cloud migration, and AI/ML-driven automation has enabled healthcare organizations to streamline operations, strengthen security, and improve patient outcomes through more efficient, reliable, and scalable technology solutions. To me, technology has always been about solving real-world problems—building resilient systems, fostering innovation, and empowering organizations to serve their communities more effectively. As the landscape evolves, I remain committed to exploring new frontiers in Healthcare IT, DevSecOps, and AI to drive meaningful, lasting change. Beyond technical expertise, I am passionate about mentorship, collaboration, and community engagement. As a Senior Member of IEEE, a Forbes Technology Council Member, and an active contributor to BCS, ACM, and ADPList, I enjoy sharing knowledge and fostering professional growth. I have had the opportunity to author industry articles, contribute to research papers, and speak at international conferences, discussing Healthcare IT modernization, DevSecOps best practices, and AI-driven enterprise solutions. My experience judging expert panels and participating in industry forums allows me to stay at the forefront of emerging trends and best practices. My goal is to continue driving technology-driven healthcare solutions, leveraging secure, scalable, and efficient systems while mentoring the next generation of professionals in the field.
Harikrishnan Muthukrishnan
Published content

expert panel
Cybersecurity has long been a race between attackers trying to get in and defenders trying to keep them out. But frontier AI is changing the pace of that race. By helping threat actors discover vulnerabilities, conduct reconnaissance and experiment with attack techniques more quickly and at a greater scale, AI can shrink the time security teams have to recognize a threat and respond before it causes damage. Offensive activities that once took weeks can increasingly be compressed into minutes. That shift also challenges a more fundamental assumption behind traditional detection: that defenders will recognize enough of an attack to know what they’re looking for. Frontier AI can help adversaries vary techniques, combine attack methods and explore unfamiliar paths at a scale that makes relying primarily on established signatures, indicators and playbooks increasingly risky. Cybersecurity guidance is consequently evolving toward models that account for AI-enabled attacks while also using AI to strengthen defense and proactively address emerging threats.Preparing for that environment means looking beyond how quickly an organization can identify an attack to how much room for maneuver its systems leave an attacker in the first place. Members of the Senior Executive Cybersecurity Think Tank share deep expertise in enterprise cybersecurity strategies, data breach prevention, risk management, threat detection and modern security architecture. Below, they explore how security leaders should adapt their defenses for an AI-accelerated threat landscape and which capabilities are becoming most important.

expert panel
NIST emphasizes that effective AI risk management depends on organizations being able to govern, map, measure and manage how AI systems are used. However, following that guidance is becoming increasingly complicated.Artificial intelligence is moving into everyday business operations faster than many organizations’ security and governance processes can keep up. Employees and business teams can now build workflows around large language models, add AI copilots to existing tools, and connect agents to company systems without the kind of formal deployment process that traditionally gives security teams visibility into new technology. As AI moves from standalone experimentation into copilots, connected workflows and increasingly autonomous agents, security teams may have less visibility into where it’s being used, what data it can reach and what actions it’s authorized to take. The result is a widening gap between the AI environment an organization believes it is governing and the one actually taking shape across the business.It’s essential for security leaders to gain visibility into the web of AI systems being built across their organizations—and the ever-expanding attack surface that comes with it. Below, members of the Senior Executive Cybersecurity Think Tank—with expertise spanning enterprise cybersecurity strategy, breach prevention, risk management and cybersecurity leadership—explain how security leaders can get ahead of business-led AI deployments and recognize when unmanaged AI risk is already beginning to compound.

expert panel
An attacker who gains access through a stolen credential may quickly move across devices, cloud resources and network systems in search of valuable data or greater control. Each step can generate clues, but when those signals land in separate tools and queues, security teams may struggle to recognize the full attack before the damage spreads.This challenge is becoming harder to tackle as traditional boundaries between users, devices, applications and infrastructure continue to dissolve. NIST’s zero-trust guidance reflects that shift, moving security away from static, network-based perimeters and toward continuous decisions based on users, assets and resources. This same erosion of boundaries is what makes it harder to catch attackers who don’t need to break anything to move around. CISA’s guidance on identifying and mitigating “living off the land” techniques warns that attackers can abuse legitimate, trusted tools and processes to blend in with normal system activity, making isolated alerts harder to interpret without broader context.Yet many organizations still measure security effectiveness largely by how well they detect suspicious activity. Detection remains essential, but alerts alone don’t determine which risks matter most, coordinate action across environments, or help the business continue operating when defenses fail. That requires an approach that connects visibility with timely decisions, enforceable controls and plans for maintaining and restoring critical operations.Moving beyond a detection-centric model means reconsidering how security data, decisions and defenses work together across the enterprise. Below, members of the Senior Executive Cybersecurity Think Tank—with expertise in enterprise cybersecurity strategies, data breach prevention, risk management, threat detection and cybersecurity leadership—explain what a more unified, real-time approach to visibility, control and resilience should look like.

expert panel
A vendor’s data breach doesn’t stay neatly contained within its own systems. Business clients may face exposed information, operational disruptions, regulatory scrutiny and difficult questions from their own stakeholders, even when their networks weren’t directly compromised. Third-party risk management is a growing issue for companies whose customers’ data resides in a growing web of applications and workflows.Once the initial crisis passes, vendors typically issue reassuring statements about investigations, remediation and stronger security. But communications crafted for customers and the media can’t establish whether the conditions that allowed the attack have truly been addressed. Telecommunications and media giant Comcast learned this the hard way in 2024 when a vendor initially said a breach hadn’t impacted Comcast’s customers—only to reverse course more than four months later.For organizations deciding whether to continue trusting a breached provider, the real question isn’t whether the vendor responded quickly or communicated effectively. It’s whether the vendor can demonstrate that it learned from the incident and has taken real, effective steps to reduce the risk of another one. Below, members of the Senior Executive Cybersecurity Think Tank—with expertise in enterprise cybersecurity strategy, data breach prevention and risk management—share what would convince them that a breached vendor will be a safer partner going forward.
Company details
BCBS FLORIDA
Company bio
Florida Blue brought the first Blues plan to Floridians in 1944 to enable access to quality, affordable care. Over the course of 80 years, Florida Blue built a new world of health care resources. Today, our mission-driven, not-for-profit model continually puts innovation to work for nearly 6 million members. In our pursuit to deliver high-quality, affordable care for all, Florida Blue has become the largest single-state provider of individual marketplace plans in the country. In 2006, Florida Blue was the first insurer to open Florida Blue Centers where members could speak directly with experts about their health. Throughout the last two decades, Florida Blue has tackled critical health inequities among at-risk communities with our partners and through our Florida Blue Foundation — the state’s largest health-focused philanthropic organization