Bhavya Bhandari
Cybersecurity Risk Management Leader | Financial ServicesERNST AND YOUNG US LLP
About
Technology and cyber risk leader with 15+ years of experience leading large‑scale security, regulatory, and risk transformation programs for global financial services organizations. Trusted advisor to executive leadership and boards, specializing in cyber strategy, integrated GRC, and exam preparedness across global frameworks and regulations. Proven track record of building and scaling risk programs, leading complex stakeholder ecosystems, and translating regulatory and cyber risk into measurable business and resiliency outcomes.
Bhavya Bhandari
Published content

expert panel
Cyber exercises give an organization a chance to uncover weaknesses before a real attack puts its response to the test. Yet what teams rehearse often differs from what they face. A 2025 survey of 480 senior U.S. cybersecurity leaders found that 57% of significant cyber incidents involved attacks the security team hadn’t prepared for. Since no organization can rehearse every scenario, the value of an exercise lies less in the script than in whether it builds the judgment and coordination a response will need when events don’t go according to plan. A scenario that simply walks the security team through familiar technical steps reveals little about how the business would function when a critical vendor goes dark, core systems are unavailable, or executives must make high-stakes calls about operations, disclosure and customer communication with incomplete information. CISA has advised that incident response plans include senior business leadership and board members and that senior management participate in tabletop exercises, reflecting the view that cyber readiness must extend well beyond the security team.Members of the Senior Executive Cybersecurity Think Tank bring deep expertise in enterprise cybersecurity strategy, risk management, incident response and cybersecurity leadership. Below, they explore what separates a useful cyber exercise from a compliance-driven tabletop and how leaders can design exercises that test executive judgment, operational dependencies and cross-organizational coordination.

expert panel
As companies move more critical systems and data into cloud and SaaS environments, investigating a cyber incident can become a complicated exercise in reconstructing events across systems an organization doesn’t fully control. If important evidence is unavailable or incomplete, determining what happened—and demonstrating what did or didn’t happen—can become much harder. NIST’s work on cloud forensics highlights the distinct challenges investigators face when collecting and analyzing evidence in cloud computing environments.Access to that evidence isn’t always a given. In 2024, CISA, OMB and ONCD worked with Microsoft to expand cloud audit logging for federal customers regardless of license tier and increase default retention from 90 to 180 days, part of a broader push to make critical security logs available without added licensing barriers. That highlights a larger business risk: An organization may discover the limits of its forensic visibility only after an incident, when legal teams, regulators and insurers are looking for clear answers.Cybersecurity leaders therefore need to look beyond whether their cloud environments can detect suspicious activity and determine whether those environments can support a credible investigation after a breach or other security incident. Members of the Senior Executive Cybersecurity Think Tank bring deep experience in enterprise security, incident response, risk management, regulatory compliance and cloud security. Below, they examine how leaders can strengthen forensic readiness before an incident occurs and where evidence gaps can create the greatest problems once an investigation is underway.

expert panel
Cybersecurity teams have always had to distinguish legitimate activity from malicious activity, but external AI agents make that judgment call harder. Unlike a conventional user session or scripted bot, an agent can pursue a goal across multiple steps, adapt as conditions change and operate at a speed and scale that can far exceed human activity.The challenge grows when organizations are interacting with agents they didn’t build, deploy or directly control. Those agents may be acting on behalf of customers, vendors or business partners—or probing systems for an attacker—and their behavior can evolve in real time. In a recent real-world example, AI agents run internally by OpenAI found an unintended path to the internet while trying to complete an evaluation, then breached Hugging Face systems in an effort to obtain information that could help them finish the task. The incident illustrates how quickly an autonomous system can move beyond the boundaries its operators expected.For cybersecurity leaders, that raises a broader question: How do you defend systems when the actor at the other end may be autonomous, adaptive and outside your control? Members of the Senior Executive Cybersecurity Think Tank bring deep expertise in enterprise cybersecurity, risk management, threat detection and modern security architecture. Below, they explore how defensive strategy should evolve as external AI agents become more capable and which protections matter most when agent-driven activity originates beyond the organization.

expert panel
The technology businesses depend on every day also creates openings for attackers, and the vulnerability queue isn’t getting shorter. CVE submissions to NIST's National Vulnerability Database increased 263% between 2020 and 2025, and submissions in the first three months of 2026 were nearly one-third higher than during the same period a year earlier. For security teams, that volume makes treating every newly disclosed flaw as an isolated problem increasingly difficult—and risks turning vulnerability management into an endless cycle of finding, prioritizing and patching.Security leaders need to look beyond individual CVEs and address the recurring weaknesses that keep generating new vulnerabilities. Recent analysis of more than 39,000 CVE records highlights how identifying recurring root causes can inform security investments and development practices aimed at eliminating entire classes of defects. The challenge for security leaders is doing that longer-term work without losing sight of vulnerabilities that pose an immediate threat to the business.Members of the Senior Executive Cybersecurity Think Tank bring deep experience in enterprise cybersecurity strategy, risk management, threat detection, secure architecture and breach prevention. Below, three of them share how security leaders can balance urgent remediation with a more systemic approach to vulnerability management—reducing today’s risk while working to prevent the same kinds of flaws from resurfacing tomorrow.

expert panel
Cybersecurity has long been a race between attackers trying to get in and defenders trying to keep them out. But frontier AI is changing the pace of that race. By helping threat actors discover vulnerabilities, conduct reconnaissance and experiment with attack techniques more quickly and at a greater scale, AI can shrink the time security teams have to recognize a threat and respond before it causes damage. Offensive activities that once took weeks can increasingly be compressed into minutes. That shift also challenges a more fundamental assumption behind traditional detection: that defenders will recognize enough of an attack to know what they’re looking for. Frontier AI can help adversaries vary techniques, combine attack methods and explore unfamiliar paths at a scale that makes relying primarily on established signatures, indicators and playbooks increasingly risky. Cybersecurity guidance is consequently evolving toward models that account for AI-enabled attacks while also using AI to strengthen defense and proactively address emerging threats.Preparing for that environment means looking beyond how quickly an organization can identify an attack to how much room for maneuver its systems leave an attacker in the first place. Members of the Senior Executive Cybersecurity Think Tank share deep expertise in enterprise cybersecurity strategies, data breach prevention, risk management, threat detection and modern security architecture. Below, they explore how security leaders should adapt their defenses for an AI-accelerated threat landscape and which capabilities are becoming most important.

expert panel
An attacker who gains access through a stolen credential may quickly move across devices, cloud resources and network systems in search of valuable data or greater control. Each step can generate clues, but when those signals land in separate tools and queues, security teams may struggle to recognize the full attack before the damage spreads.This challenge is becoming harder to tackle as traditional boundaries between users, devices, applications and infrastructure continue to dissolve. NIST’s zero-trust guidance reflects that shift, moving security away from static, network-based perimeters and toward continuous decisions based on users, assets and resources. This same erosion of boundaries is what makes it harder to catch attackers who don’t need to break anything to move around. CISA’s guidance on identifying and mitigating “living off the land” techniques warns that attackers can abuse legitimate, trusted tools and processes to blend in with normal system activity, making isolated alerts harder to interpret without broader context.Yet many organizations still measure security effectiveness largely by how well they detect suspicious activity. Detection remains essential, but alerts alone don’t determine which risks matter most, coordinate action across environments, or help the business continue operating when defenses fail. That requires an approach that connects visibility with timely decisions, enforceable controls and plans for maintaining and restoring critical operations.Moving beyond a detection-centric model means reconsidering how security data, decisions and defenses work together across the enterprise. Below, members of the Senior Executive Cybersecurity Think Tank—with expertise in enterprise cybersecurity strategies, data breach prevention, risk management, threat detection and cybersecurity leadership—explain what a more unified, real-time approach to visibility, control and resilience should look like.







