Mumbai — Artificial intelligence is reshaping cybersecurity from both sides of the fight — arming attackers with faster, more convincing tools while giving defenders new ways to detect and respond to threats at scale. Alok Ranjan, Founder & Director of Mumbai-based CyEile Technologies Private Limited, has been watching that shift play out directly in the assessments and incident response engagements his team runs for clients.
AI as an Attacker’s Tool
Ranjan points to a clear shift in the threats CyEile’s teams encounter: phishing campaigns that read as fluent and context-aware rather than generic, malware that adapts its behavior to evade detection, and social engineering attempts that are harder for employees to spot on instinct alone. His view is that AI has lowered the skill floor for attackers, letting less sophisticated actors run more convincing campaigns — a shift that changes what organizations need to defend against, not just how much.
AI as a Defender’s Force Multiplier
On the defense side, Ranjan sees AI-assisted monitoring as increasingly central to keeping pace with attack volume. CyEile’s Security Operations Center and MDR/XDR services rely on SIEM and SOAR platforms that use automated correlation and anomaly detection to flag threats faster than manual review could manage, particularly across the 24×7 monitoring workloads his team handles for clients. He is careful to frame this as augmentation rather than replacement — automated systems narrow down what human analysts need to investigate, but the judgment calls during an active incident still rest with experienced responders.
Why Human Judgment Still Matters
Ranjan cautions against treating AI tools as a substitute for fundamentals. In his experience running penetration tests and forensic investigations, the organizations that fare worst in an incident are often the ones that assumed automated tooling alone would catch everything, without maintaining tested incident response plans or skilled staff to act on alerts. His position is that AI changes the pace and scale of both attack and defense, but the underlying discipline — patching, access control, monitoring, and rehearsed response — remains the foundation everything else sits on.
Preparing for What Comes Next
Looking ahead, Ranjan expects the gap between AI-equipped attackers and under-resourced defenders to be one of the defining cybersecurity challenges in India over the next few years, particularly for mid-sized organizations without dedicated security operations. He argues that closing that gap will depend less on any single tool and more on organizations building continuous, integrated security operations — assessment, monitoring, and response working together — so that AI-driven threats are met with defenses that are just as adaptive.
Leave a comment