Proofpoint is expanding its India operations as cyber threats grow. The company plans to hire over 200 engineers for a new Hyderabad centre after its business tripled last year. Bikramdeep Singh said, "The answer wasn't to slow the business down, but to build governance and security in step with adoption."
Proofpoint is stepping up its India focus as AI adoption accelerates and cyber threats become more sophisticated. In an interview with ET, Bikramdeep Singh discusses the growing risks from autonomous AI agents, the shift towards intent-based threat detection, rising data security concerns and the need for greater enterprise controls. He also outlines Proofpoint's India expansion, including plans to hire more than 200 engineers.
As artificial intelligence (AI) adoption accelerates, cyberattacks are becoming more sophisticated and harder to detect, with AI agents creating a new layer of risk for companies.
Cybersecurity firm Proofpoint recently expanded its security portfolio with two new agentic systems designed to automate risk detection, investigation and remediation across AI, enterprise data and collaboration tools. The company is also stepping up its focus on India, where its business has tripled over the past year and it plans to hire more than 200 engineers for an AI Security Engineering Centre of Excellence in Hyderabad.
On the sidelines of the company's flagship event, Proofpoint Protect 2026 in San Diego, California, Bikramdeep Singh, Vice President, India & SAARC, Proofpoint, spoke to The Economic Times about the evolving threat landscape, the risks posed by agentic AI and the company's strategy for India. Edited excerpts:
Q1. With some AI leaders calling for a slowdown in development, do you believe AI is moving faster than companies can govern and secure it? Where do you see the biggest gap today -- regulation, enterprise controls or security?
The calls for a slowdown are about frontier model development -- a handful of AI labs weighing how fast to push the next generation of models. That's a separate conversation from enterprise AI adoption, which is not slowing down and shouldn't.
We've been here before. Cybersecurity has always had to move alongside new waves of technology -- the shift to cloud, the shift to remote work. Each one carried new risks, and each time, the answer wasn't to slow the business down, but to build governance and security in step with adoption.
If you're asking where the biggest gap is today, I'd point to enterprise controls. It comes down to fundamentals: Do you have visibility into every AI application actually running in your environment, what each AI agent is supposed to be doing in the first place, and what data are being accessed by those AI agents? Most organisations can't answer that yet -- and until they can, governance has nowhere to start.
Q2. Most enterprise AI use today is still AI-assisted, but agentic AI is moving towards autonomous action. What changes when AI agents start acting on their own inside an enterprise?
The simplest way to put it: AI agents are your insider risk, amplified by machine speed. Insider risk has always existed: a person with access who makes a mistake or gets compromised. What agentic AI does is remove the human pace limit on that risk. An agent with standing access to your systems can search, combine and act across data at a speed no person ever could, which means a single bad prompt or manipulated instruction can trigger consequences across connected systems almost instantly.
That means the access controls and forensic visibility we've always built for human identities now have to extend to every AI agent in the enterprise. If it can act on its own, it needs to be governed like an identity, not just deployed like software.
Q3. AI is also making attacks more sophisticated and personalised. How is it changing the way attackers operate?
What we've observed globally is that AI has given attackers two things at once: scale and sophistication, which used to be a trade-off. A convincing, well-researched, personally targeted attack used to take real time and skill to pull off. AI has removed that trade-off.
An attacker can now generate a flawless, context-aware phishing email, mimic a specific colleague's writing style for a business email compromise attempt, or map an organisation's structure, all in minutes.
The attacker hasn't necessarily gotten smarter. The tools have removed the effort and skill barrier that used to limit how personalised an attack could be at scale, and that's the shift every security team needs to plan for.
Q4. As attacks increasingly use legitimate accounts and trusted identities, how difficult is it for companies to distinguish between a genuine user and an attacker?
It comes down to one word: Intent. When an attacker is operating through valid, legitimate credentials, authentication tells you nothing -- the login checks out every time, the account is real, the conversation looks familiar. Behaviour alone can even look normal.
That's why the industry is having to move past rule-based and even purely behavioural detection, towards reasoning about intent -- what is this interaction actually trying to accomplish, and is that plausible given the context? That's a much harder problem to solve than checking whether someone has the right password, but it's the only thing that still works once the credentials themselves can't be trusted.
Q5. Proofpoint talks about securing AI and data together. Why do you think those two areas now need to be treated as one security problem?
As companies speed up AI adoption, one problem keeps surfacing: data exposure risk. And the challenge isn't just finding where sensitive information lives -- it's controlling who, and what, can access it. Today, that data is sprawled across SaaS, cloud and on-premises systems, and the identities touching it aren't just people anymore -- they include service accounts and AI agents too.
Historically, security tools were built to see one half of that picture. An AI security tool can see what an agent is trying to do, but not the sensitive data behind that action. A data security tool can see where sensitive data lives, but not what the AI's intent is. Once you have AI agents pulling from live systems constantly, that gap is exactly the blind spot that gets exploited -- whether by an attacker or by an AI agent accessing something it shouldn't.
That's why we don't treat AI security and data security as two adjacent products. If an AI agent is meant to retrieve information from a specific system to generate a response, you need to know, in real time, that it's touching only what it's authorised for, not reconstruct that after the fact from two disconnected tools. You cannot secure AI without securing the data it acts on, and you cannot secure data without understanding how AI is using it.
Q6. Proofpoint has increased its focus on India. What's driving that focus, how much are you investing here, and how important is India to your global AI-security strategy?
Three things are converging in India at once: rapid AI adoption, an increasingly sophisticated threat landscape, and a new era of data protection through the DPDPA. That combination is exactly where our approach to securing data and AI together matters most, and it's why we're doubling down here.
Proofpoint's India business has tripled year-on-year, with double-digit growth in new customer acquisition and seats protected up more than 600% over the past 18 months. We've recently opened a new Delhi office to bring sales, customer success and partner support closer to customers, and we're building an AI Security Engineering Centre of Excellence in Hyderabad, with plans to hire more than 200 engineers over the next 12 to 24 months -- to advance capabilities from our recent Acuvity acquisition in AI governance and runtime protection.
India isn't a satellite market for us. It's a strategic location for the next generation of AI security innovation, and it's one of the fastest-growing cybersecurity markets in the world, so it plays a central role in our global AI security strategy.
Q7. As companies rush to adopt AI, are you seeing security spending rise alongside that adoption, or are companies having to work within existing cybersecurity budgets?
For most CISOs, that spend still isn't keeping pace with the mandate they've been handed. Our own 2026 Voice of the CISO report found that 92% of Indian CISOs are expected to manage AI-related risks over the next two years without a proportional increase in resources or expertise. Security leaders are being asked to secure and champion AI adoption at the same time, largely within the budget and headcount they already have.
And we are also seeing consolidation in security spending, which has been underway for several years, but AI is accelerating the need for it. Organisations running large numbers of security vendors are finding that every additional tool adds vulnerabilities and patching overhead -- the more security tools an organisation has, the more vulnerabilities and patches it has to manage. So instead of continuing to expand their security estates, enterprises are standardising around a smaller number of strategic pillars: XDR, security operations, identity, SASE and finally human and agent-centric security.