Skills
About
Ritesh is a seasoned executive with deep cybersecurity expertise across both public and private sectors. As the head of cyber-intelligence and counterterrorism of a national intelligence agency, he has honed his expertise in cybersecurity working in the front lines of cyber war. Extending his expertise to IBM Research, Ritesh has built ground-breaking products that have been deployed in many industries. Combined with his role as an executive with PWC running large cyber consulting programs and the global CISO of one of the world’s largest mining companies, Ritesh has the unique experience to see a cybersecurity challenge from the lens of a practitioner, an innovator and a business leader.
Kumar Ritesh
Published content

expert panel
Companies rarely operate wholly within their own digital walls anymore. Critical business functions now depend on cloud platforms, software components, contractors, service providers and sprawling networks of suppliers, with each trusted relationship creating another possible route into an organization. And the risk is growing: Verizon’s 2026 Data Breach Investigations Report found that breaches involving third parties had increased 60% from the previous year’s dataset, accounting for 48% of all breaches analyzed.For attackers, compromising a well-connected partner can be faster and more effective than challenging each target’s defenses directly. A 2025 GitHub Action supply chain compromise demonstrated how a tool embedded in development workflows could expose credentials and other sensitive information across downstream users. Yet many organizations still evaluate cyber risk from outside partners primarily through questionnaires and scheduled reviews—methods that document security practices but often fail to reveal how risks, access or dependencies have changed since the assessment was completed.Reducing third-party cyber risk now requires organizations to look beyond whether a vendor passed an assessment and consider how trusted relationships affect their security and resilience over time. Below, members of the Senior Executive Cybersecurity Think Tank—with expertise in enterprise cybersecurity strategy, data breach prevention and risk management—explain what effective third-party risk reduction looks like today and where (and why) companies must move beyond checklist-driven oversight.

expert panel
Artificial intelligence has fundamentally changed cybersecurity—not just for defenders but also for attackers. AI can now generate convincing phishing campaigns, rapidly mutate malware and automate reconnaissance at a scale that would have required large teams only a few years ago. As attack velocity accelerates, many organizations are discovering that even mature detection and response capabilities struggle to keep pace.That shift is forcing security leaders to rethink longstanding assumptions. Members of the Senior Executive Cybersecurity Think Tank, a community of experienced cybersecurity executives and practitioners, argue that future-ready organizations will succeed not by responding faster, but by preventing more attacks from succeeding in the first place.According to IBM's Cost of a Data Breach Report, organizations that combine AI-driven security with proactive risk reduction significantly reduce both breach costs and response times, reinforcing the business value of moving security "left" before attackers gain a foothold.Below, Think Tank members share practical strategies for moving beyond reactive security, highlighting the technologies, processes and leadership mindset needed to stay ahead of these AI-powered threats.
Company details
CYFIRMA
Company bio
CYFIRMA is a global leader in preemptive external threat landscape management, enabling organizations to predict and prevent cyberattacks through its AI-powered intelligence platform. By integrating nine pillars of external threat management including Attack Surface Discovery, Vulnerability Intelligence, Brand & Digital Risk Management, Third-Party Risk, Situational Awareness, Predictive Threat Intelligence, Threat Adaptive Awareness, and Sector-Tailored Deception Intelligence, CYFIRMA shifts cybersecurity from reactive to predictive. The platform delivers early warnings, personalized insights, and actionable intelligence from a hacker’s perspective, helping reduce cyber risk and costs through threat prioritization, contextual decision-making, improved visibility, and stronger operational resilience. CYFIRMA serves Fortune 500 companies and national agencies and is headquartered in Singapore with offices across APAC, the US, and EMEA.