Skills
About
I've spent over a decade in security, building and leading security programs at enterprise scale across tech, finance, and healthcare; most recently as Senior Security Manager at Microsoft. My work sits at the intersection of technical security engineering and business risk, and I care deeply about making security programs that actually work in the real world, not just on paper. Outside of my day job, I have mentored 100+ security professionals and continue to do so actively. I've been recognized globally as one of the top cybersecurity mentors and featured at Times Square for that work. I speak and panel at security conferences, academic institutions, and industry events, and I write about current state of enterprise security.
Gaurav Kulkarni
Published content

expert panel
An attacker who gains access through a stolen credential may quickly move across devices, cloud resources and network systems in search of valuable data or greater control. Each step can generate clues, but when those signals land in separate tools and queues, security teams may struggle to recognize the full attack before the damage spreads.This challenge is becoming harder to tackle as traditional boundaries between users, devices, applications and infrastructure continue to dissolve. NIST’s zero-trust guidance reflects that shift, moving security away from static, network-based perimeters and toward continuous decisions based on users, assets and resources. This same erosion of boundaries is what makes it harder to catch attackers who don’t need to break anything to move around. CISA’s guidance on identifying and mitigating “living off the land” techniques warns that attackers can abuse legitimate, trusted tools and processes to blend in with normal system activity, making isolated alerts harder to interpret without broader context.Yet many organizations still measure security effectiveness largely by how well they detect suspicious activity. Detection remains essential, but alerts alone don’t determine which risks matter most, coordinate action across environments, or help the business continue operating when defenses fail. That requires an approach that connects visibility with timely decisions, enforceable controls and plans for maintaining and restoring critical operations.Moving beyond a detection-centric model means reconsidering how security data, decisions and defenses work together across the enterprise. Below, members of the Senior Executive Cybersecurity Think Tank—with expertise in enterprise cybersecurity strategies, data breach prevention, risk management, threat detection and cybersecurity leadership—explain what a more unified, real-time approach to visibility, control and resilience should look like.

expert panel
A vendor’s data breach doesn’t stay neatly contained within its own systems. Business clients may face exposed information, operational disruptions, regulatory scrutiny and difficult questions from their own stakeholders, even when their networks weren’t directly compromised. Third-party risk management is a growing issue for companies whose customers’ data resides in a growing web of applications and workflows.Once the initial crisis passes, vendors typically issue reassuring statements about investigations, remediation and stronger security. But communications crafted for customers and the media can’t establish whether the conditions that allowed the attack have truly been addressed. Telecommunications and media giant Comcast learned this the hard way in 2024 when a vendor initially said a breach hadn’t impacted Comcast’s customers—only to reverse course more than four months later.For organizations deciding whether to continue trusting a breached provider, the real question isn’t whether the vendor responded quickly or communicated effectively. It’s whether the vendor can demonstrate that it learned from the incident and has taken real, effective steps to reduce the risk of another one. Below, members of the Senior Executive Cybersecurity Think Tank—with expertise in enterprise cybersecurity strategy, data breach prevention and risk management—share what would convince them that a breached vendor will be a safer partner going forward.

expert panel
Companies rarely operate wholly within their own digital walls anymore. Critical business functions now depend on cloud platforms, software components, contractors, service providers and sprawling networks of suppliers, with each trusted relationship creating another possible route into an organization. And the risk is growing: Verizon’s 2026 Data Breach Investigations Report found that breaches involving third parties had increased 60% from the previous year’s dataset, accounting for 48% of all breaches analyzed.For attackers, compromising a well-connected partner can be faster and more effective than challenging each target’s defenses directly. A 2025 GitHub Action supply chain compromise demonstrated how a tool embedded in development workflows could expose credentials and other sensitive information across downstream users. Yet many organizations still evaluate cyber risk from outside partners primarily through questionnaires and scheduled reviews—methods that document security practices but often fail to reveal how risks, access or dependencies have changed since the assessment was completed.Reducing third-party cyber risk now requires organizations to look beyond whether a vendor passed an assessment and consider how trusted relationships affect their security and resilience over time. Below, members of the Senior Executive Cybersecurity Think Tank—with expertise in enterprise cybersecurity strategy, data breach prevention and risk management—explain what effective third-party risk reduction looks like today and where (and why) companies must move beyond checklist-driven oversight.

expert panel
Artificial intelligence has fundamentally changed cybersecurity—not just for defenders but also for attackers. AI can now generate convincing phishing campaigns, rapidly mutate malware and automate reconnaissance at a scale that would have required large teams only a few years ago. As attack velocity accelerates, many organizations are discovering that even mature detection and response capabilities struggle to keep pace.That shift is forcing security leaders to rethink longstanding assumptions. Members of the Senior Executive Cybersecurity Think Tank, a community of experienced cybersecurity executives and practitioners, argue that future-ready organizations will succeed not by responding faster, but by preventing more attacks from succeeding in the first place.According to IBM's Cost of a Data Breach Report, organizations that combine AI-driven security with proactive risk reduction significantly reduce both breach costs and response times, reinforcing the business value of moving security "left" before attackers gain a foothold.Below, Think Tank members share practical strategies for moving beyond reactive security, highlighting the technologies, processes and leadership mindset needed to stay ahead of these AI-powered threats.

expert panel
Vulnerability management used to depend on a familiar rhythm: A new flaw was disclosed, public databases added analysis and security teams worked through the queue by severity. That model is now straining under its own weight. Vulnerability disclosures keep climbing, but the National Vulnerability Database has faced a significant operational breakdown: Beginning in early 2024, NIST sharply slowed enrichment of new CVE entries, and in April 2026, NIST formally announced it would no longer enrich all CVE entries, moving to a triage model that leaves the majority of submissions without scores, metadata or supporting analysis.Security leaders need to rethink defensive strategies, from monitoring to remediation. Even with the help of automation, teams with limited resources can’t approach every vulnerability with equal urgency, and waiting for more complete information can leave a business exposed while attackers keep moving. Security teams must learn to weigh new vulnerabilities in terms of the organization’s real environment, operational priorities and potential business impact. In a world of incomplete signals, security leaders need a sharper sense of which risks matter now, which can wait and which require a different kind of control altogether. Members of the Senior Executive Cybersecurity Think Tank are leaders in enterprise cybersecurity strategies, data breach prevention, risk management and modern security architecture. Below, they share how organizations can rethink vulnerability risk assessment as public data becomes less complete and focus attention where it can have the greatest protective impact.

expert panel
Cybersecurity leaders have never had the luxury of moving slowly, but the second half of 2026 may test even the most mature security teams. AI is accelerating both sides of the fight: Attackers can find vulnerabilities, craft more convincing scams and move faster, while businesses (and employees) are racing to embed AI into products, workflows and everyday operations. That combination raises the stakes for every leader responsible for protecting data, systems, customers and trust.The challenge isn’t just technical. As cyber risk spreads across engineering, finance, operations, legal, HR, procurement and executive teams, the old model of security as a separate checkpoint no longer fits how businesses actually run. The organizations that handle this next phase successfully will need to rethink cybersecurity as a shared operating discipline, not a last-minute review, compliance exercise, or problem for one department or leader to solve alone.Members of the Senior Executive Cybersecurity Think Tank have deep expertise in enterprise cybersecurity strategies, risk management, threat detection and cybersecurity leadership. Below, a group of them discusses what they see as the biggest cybersecurity challenges for leaders in the second half of 2026 and how organizations move from reactive defense to enterprisewide resilience.