Skills
About
Ritesh is a seasoned executive with deep cybersecurity expertise across both public and private sectors. As the head of cyber-intelligence and counterterrorism of a national intelligence agency, he has honed his expertise in cybersecurity working in the front lines of cyber war. Extending his expertise to IBM Research, Ritesh has built ground-breaking products that have been deployed in many industries. Combined with his role as an executive with PWC running large cyber consulting programs and the global CISO of one of the world’s largest mining companies, Ritesh has the unique experience to see a cybersecurity challenge from the lens of a practitioner, an innovator and a business leader.
Kumar Ritesh
Published content

expert panel
Cybersecurity teams have always had to distinguish legitimate activity from malicious activity, but external AI agents make that judgment call harder. Unlike a conventional user session or scripted bot, an agent can pursue a goal across multiple steps, adapt as conditions change and operate at a speed and scale that can far exceed human activity.The challenge grows when organizations are interacting with agents they didn’t build, deploy or directly control. Those agents may be acting on behalf of customers, vendors or business partners—or probing systems for an attacker—and their behavior can evolve in real time. In a recent real-world example, AI agents run internally by OpenAI found an unintended path to the internet while trying to complete an evaluation, then breached Hugging Face systems in an effort to obtain information that could help them finish the task. The incident illustrates how quickly an autonomous system can move beyond the boundaries its operators expected.For cybersecurity leaders, that raises a broader question: How do you defend systems when the actor at the other end may be autonomous, adaptive and outside your control? Members of the Senior Executive Cybersecurity Think Tank bring deep expertise in enterprise cybersecurity, risk management, threat detection and modern security architecture. Below, they explore how defensive strategy should evolve as external AI agents become more capable and which protections matter most when agent-driven activity originates beyond the organization.

expert panel
Software supply chain security is often treated as a gatekeeping problem: Keep malicious code from entering the environment. But modern applications are built from dense webs of open-source and third-party dependencies, and a single compromised package can surface across numerous applications and systems downstream, far beyond the first project that installs it.Recent attacks have shown how quickly that risk can multiply. In September 2025, the self-replicating Shai-Hulud worm infiltrated the npm ecosystem through compromised maintainer accounts, spreading automatically across the registry by hijacking developer credentials. By the time it was contained, the worm had compromised more than 500 packages, prompting GitHub to remove them from the registry to stop further propagation.For security leaders, the challenge isn’t only determining whether a package is safe at the point of entry—it’s understanding how far a compromise could travel once that software is already embedded across an organization. Supply chain risk is compounded when organizations lack visibility into how the technology they rely on is developed, integrated and deployed.Members of the Senior Executive Cybersecurity Think Tank bring deep expertise in enterprise cybersecurity strategies, data breach prevention, risk management, threat detection and modern security architecture. Here, three of them examine how leaders should assess the downstream risk posed by poisoned software dependencies and what meaningful prevention and containment look like when a single compromised component has the potential to affect many systems.

expert panel
The technology businesses depend on every day also creates openings for attackers, and the vulnerability queue isn’t getting shorter. CVE submissions to NIST's National Vulnerability Database increased 263% between 2020 and 2025, and submissions in the first three months of 2026 were nearly one-third higher than during the same period a year earlier. For security teams, that volume makes treating every newly disclosed flaw as an isolated problem increasingly difficult—and risks turning vulnerability management into an endless cycle of finding, prioritizing and patching.Security leaders need to look beyond individual CVEs and address the recurring weaknesses that keep generating new vulnerabilities. Recent analysis of more than 39,000 CVE records highlights how identifying recurring root causes can inform security investments and development practices aimed at eliminating entire classes of defects. The challenge for security leaders is doing that longer-term work without losing sight of vulnerabilities that pose an immediate threat to the business.Members of the Senior Executive Cybersecurity Think Tank bring deep experience in enterprise cybersecurity strategy, risk management, threat detection, secure architecture and breach prevention. Below, three of them share how security leaders can balance urgent remediation with a more systemic approach to vulnerability management—reducing today’s risk while working to prevent the same kinds of flaws from resurfacing tomorrow.

expert panel
As AI agents move from assisting employees to taking actions on their behalf, organizations face a new accountability problem: It’s no longer enough to know what happened. As agents gain access to sensitive data, systems and business processes, organizations are likely to need evidence that establishes not only what an agent did but also why it was permitted to do it. That includes demonstrating that an agent had the right authority, was acting for the right purpose, and stayed within the boundaries established for that particular task.Cybersecurity experts have warned that agentic systems complicate the traditional model in which actions can be traced to an identifiable person with defined permissions and a clear audit trail. And at the moment, teams may need to work on solving the AI accountability conundrum on their own—while the issue is unquestionably on guiding agencies’ radars, NIST only began requesting input for a project on how identity standards and best practices can be applied to software agents in February 2026. Among those with an eye on the security challenges that come with AI agents are the members of the Senior Executive Cybersecurity Think Tank. They bring deep experience in enterprise cybersecurity, risk management, security architecture and emerging technology to bear on the question. Below, two of them examine how organizations should rethink evidence and auditability for agent-driven workflows and what stronger, more trustworthy proof of authorization could look like in practice.

expert panel
Cybersecurity has long been a race between attackers trying to get in and defenders trying to keep them out. But frontier AI is changing the pace of that race. By helping threat actors discover vulnerabilities, conduct reconnaissance and experiment with attack techniques more quickly and at a greater scale, AI can shrink the time security teams have to recognize a threat and respond before it causes damage. Offensive activities that once took weeks can increasingly be compressed into minutes. That shift also challenges a more fundamental assumption behind traditional detection: that defenders will recognize enough of an attack to know what they’re looking for. Frontier AI can help adversaries vary techniques, combine attack methods and explore unfamiliar paths at a scale that makes relying primarily on established signatures, indicators and playbooks increasingly risky. Cybersecurity guidance is consequently evolving toward models that account for AI-enabled attacks while also using AI to strengthen defense and proactively address emerging threats.Preparing for that environment means looking beyond how quickly an organization can identify an attack to how much room for maneuver its systems leave an attacker in the first place. Members of the Senior Executive Cybersecurity Think Tank share deep expertise in enterprise cybersecurity strategies, data breach prevention, risk management, threat detection and modern security architecture. Below, they explore how security leaders should adapt their defenses for an AI-accelerated threat landscape and which capabilities are becoming most important.

expert panel
NIST emphasizes that effective AI risk management depends on organizations being able to govern, map, measure and manage how AI systems are used. However, following that guidance is becoming increasingly complicated.Artificial intelligence is moving into everyday business operations faster than many organizations’ security and governance processes can keep up. Employees and business teams can now build workflows around large language models, add AI copilots to existing tools, and connect agents to company systems without the kind of formal deployment process that traditionally gives security teams visibility into new technology. As AI moves from standalone experimentation into copilots, connected workflows and increasingly autonomous agents, security teams may have less visibility into where it’s being used, what data it can reach and what actions it’s authorized to take. The result is a widening gap between the AI environment an organization believes it is governing and the one actually taking shape across the business.It’s essential for security leaders to gain visibility into the web of AI systems being built across their organizations—and the ever-expanding attack surface that comes with it. Below, members of the Senior Executive Cybersecurity Think Tank—with expertise spanning enterprise cybersecurity strategy, breach prevention, risk management and cybersecurity leadership—explain how security leaders can get ahead of business-led AI deployments and recognize when unmanaged AI risk is already beginning to compound.
Company details
CYFIRMA
Company bio
CYFIRMA is a global leader in preemptive external threat landscape management, enabling organizations to predict and prevent cyberattacks through its AI-powered intelligence platform. By integrating nine pillars of external threat management including Attack Surface Discovery, Vulnerability Intelligence, Brand & Digital Risk Management, Third-Party Risk, Situational Awareness, Predictive Threat Intelligence, Threat Adaptive Awareness, and Sector-Tailored Deception Intelligence, CYFIRMA shifts cybersecurity from reactive to predictive. The platform delivers early warnings, personalized insights, and actionable intelligence from a hacker’s perspective, helping reduce cyber risk and costs through threat prioritization, contextual decision-making, improved visibility, and stronger operational resilience. CYFIRMA serves Fortune 500 companies and national agencies and is headquartered in Singapore with offices across APAC, the US, and EMEA.



