AI, Cybersecurity and the Race to Build Digital Trust

As technology reshapes industries, economies and everyday life, the need to build trust alongside innovation has never been more critical. From the growing influence of artificial intelligence to increasingly sophisticated cyber threats, organisations and policymakers are navigating a complex digital landscape where security, privacy, governance and ethical responsibility are closely interconnected. In this exclusive interaction with Machine Edge Global, Tara Wisniewski, ISACA Senior Vice President of Advocacy and Dr. Sanjana Mehta, ISACA Associate Vice President of Advocacy share their perspectives on the evolving cybersecurity landscape, the opportunities and risks presented by AI, India’s role in shaping trusted technology, and the importance of building a skilled and inclusive digital workforce. They also discuss how organisations and governments can strengthen resilience and digital trust while enabling responsible innovation.

Dr Sanjana Mehta

Technology is transforming every sector at an unprecedented pace. What, in your view, are the biggest opportunities and risks organisations need to address in this digital era?

The biggest opportunity in this digital era is for organisations to use technology to improve efficiency, expand access to services, strengthen decision-making and create new value for customers, employees and communities.

At the same time, the pace of transformation brings significant risks, including cyber threats, data privacy challenges, AI-related bias and misinformation, regulatory complexity and the potential erosion of trust if technology is deployed without proper governance. ISACA’s latest Tech Trends and Priorities Pulse Poll found that AI-driven cyber threats and deepfakes, failure to detect/respond to a breach causing irreparable harm, and insider threats and human error digital trust are keeping digital trust professionals up at night. Additionally, they’re focused on AI-driven social engineering (63%), ransomware and extortion attacks (54%) and insider threats (35%) as the most significant cyber threats in 2026.

To succeed, organisations need to treat innovation and digital trust as interconnected priorities, ensuring that cybersecurity, privacy, risk management, assurance and ethical oversight are built into technology strategies from the beginning. Those that can innovate responsibly while protecting people, data and systems will be best positioned to compete and build lasting confidence in the digital economy.

With AI becoming increasingly embedded in business and everyday life, how can organisations balance innovation with trust, security, privacy and ethical responsibility?

Organisations can balance AI innovation with trust, security, privacy and ethical responsibility by embedding strong governance and accountability into AI initiatives from the start. This means establishing clear policies for how AI is developed, deployed and monitored; protecting data and systems through robust security and privacy controls; regularly assessing AI tools for bias, accuracy and unintended consequences; and ensuring human oversight remains central to decision-making. By involving digital trust professionals across cybersecurity, risk, assurance, governance and privacy, organisations can move quickly and confidently while maintaining the transparency, safeguards and ethical guardrails needed to earn the trust of customers, employees, regulators and society.

ISACA works extensively across information security, governance, assurance, risk management and data privacy. Which of these areas do you believe organisations in India need to strengthen most urgently?

Organisations need to prioritize information security, governance, assurance, risk management and data privacy because these disciplines form the foundation of digital trust, helping protect sensitive data, reduce operational and regulatory risks, and ensure technology is used responsibly. As threats, regulations and emerging technologies evolve, strengthening these areas enables organizations to innovate with confidence while maintaining trust with customers, employees, partners and regulators. While all of these domains are important for organizations to prioritize, data privacy is an especially timely focus area, given the phased commencement associated with India’s India’s Digital Personal Data Protection Act. Organizations in India should consider taking several actions now to strengthen their DPDP readiness, including by designing privacy into products, systems and supplier relationships, and demonstrating their readiness through data maps, workflows, control logs, breach playbooks and deletion records.         

Cybersecurity threats are becoming more sophisticated with the rise of AI and other emerging technologies. How should organisations rethink their cybersecurity strategies?

According to ISACA research, 45% of digital trust professionals say that AI risks are an immediate priority, and 63% cite AI-driven social engineering as the most significant threat facing organizations this year. However, only 41% say they are confident in their own ability to detect AI powered misinformation, and only 36% are confident in their organization’s ability to detect AI-powered misinformation. Additionally, over half (56 percent) do not know how long it would take to halt an AI system due to a security incident, while 39 percent say they do not know whether they have a documented process for shutting down or overriding AI systems if things go wrong.

Cybersecurity professionals should be involved in AI development, onboarding and implementation from the start to help identify risks, embed appropriate safeguards and ensure these tools are deployed securely and responsibly. ISACA’s research also shows that cybersecurity professionals have increased their use of AI for a variety of security related operations, including automating threat detection/response, endpoint security, and automating routine security tasks. Not only are they increasing their use of AI tools, but they are also more likely to be involved with shaping how their enterprise uses AI—more security professionals are involved in the development, onboarding, or implementation of AI solutions and the development of a policy governing the use of AI technology this year, compared to 2025.

Addressing cybersecurity workforce shortages and skills gaps is also essential to building cyber resilience and preparing for evolving threats. Organizations that invest in training, upskilling and clear career pathways will be better positioned to strengthen defenses, respond effectively to incidents and adapt as the threat landscape changes.

India is rapidly emerging as a global technology and digital innovation hub. What role can India play in shaping global conversations around trusted technology?           

India can play an important role in shaping global conversations around trusted technology by bringing together its strengths in digital innovation, scale, talent and policy development. As Indian organizations, startups and technology professionals help build solutions used across the world, India has an opportunity to demonstrate how innovation can advance responsibly—grounded in strong cybersecurity, governance, assurance, risk management and data privacy practices. By contributing practical experience from one of the world’s most dynamic digital economies, India can help define global approaches to digital trust that are inclusive, scalable and responsive to the needs of both emerging and mature markets.

Diversity and inclusion remain important challenges in the technology sector. What needs to change to create stronger career pathways for women and other under-represented groups in technology?

Creating stronger career pathways for women and other under-represented groups in technology requires moving beyond awareness and focusing on measurable action across education, hiring, retention and advancement. Employers and academic institutions need to make technology careers more accessible through early exposure to digital skills, mentorship, scholarships, apprenticeships and flexible learning pathways that connect directly to in-demand roles in cybersecurity, governance, risk, assurance, privacy and emerging technologies. Organizations also need to address bias in recruitment and promotion, provide visible role models and sponsorship, and build inclusive cultures where diverse professionals have equal access to stretch assignments, leadership development and career progression. Strengthening representation is essential to building a more resilient, innovative and trusted technology workforce.

Looking ahead over the next five years, which emerging technologies or technology trends do you believe will have the greatest impact on cybersecurity, governance and the future of work?

ISACA’s latest Tech Trends and Priorities Pulse Poll found that digital trust professionals consider AI and machine learning (62%), generative AI and LLMs (59%), cloud security (40%), data privacy and sovereignty (30%), and zero trust architecture (22%) to be the top technology trends or priorities impacting their work this year. Additionally, they cited regulatory compliance (66%), business continuity and resilience (62%), and managing AI-related risk (48%) as very important focus areas for them for the year as well. Together, these findings show that the future of work will depend on professionals who can connect emerging technology adoption with the governance, resilience and trust needed to manage its risks responsibly.

Tara Wisniewski

Cybersecurity has moved from being primarily an IT concern to becoming a strategic business and national priority. How has the conversation around cybersecurity changed among policymakers and business leaders globally?

The conversation around cybersecurity has shifted significantly from a technical discussion about protecting systems to a boardroom and policy-level discussion about resilience, economic stability, national security and public trust. Policymakers and business leaders increasingly recognize that cyber risk can disrupt critical infrastructure, supply chains, financial systems, healthcare, education and public services, making it a shared responsibility across governments, enterprises and individuals. As a result, the focus is moving beyond prevention alone to include stronger governance, incident preparedness, regulatory compliance, workforce development, international cooperation and accountability at the leadership level. Globally, cybersecurity is now viewed as a strategic enabler of digital transformation and trusted innovation—not simply a defensive function, but a core requirement for protecting organizations, citizens and economies in an increasingly connected world.

India has rapidly strengthened its position as a global technology and digital innovation hub. From an international perspective, what role can India play in shaping global cybersecurity standards and policies?

India has an important opportunity to help shape global cybersecurity standards and policies by bringing the perspective of a rapidly scaling digital economy with deep technology talent, a large and diverse user base, and growing experience in data protection and cyber resilience. As cyber risks increasingly cross borders, India can contribute practical insight into how policies should support secure digital infrastructure, responsible innovation and trusted cross-border data flows while remaining workable for organizations of different sizes and maturity levels. Its evolving regulatory landscape, including the Digital Personal Data Protection Act, also positions India to play a stronger role in global conversations about accountability, privacy, breach readiness and responsible technology governance. From an international perspective, India’s greatest contribution may be in helping ensure that cybersecurity frameworks are not only technically sound, but also inclusive, scalable and adaptable to the needs of both emerging and mature digital economies.

Governments are introducing new regulations around cybersecurity, data protection and artificial intelligence. How can policymakers strike the right balance between stronger regulation and allowing technological innovation to flourish?

Policymakers can strike the right balance by creating regulation that is risk-based, outcomes-focused and developed in close consultation with industry, academia and digital trust professionals. Stronger rules are needed to protect people, organizations and critical infrastructure from rapidly evolving risks, but regulation should also be clear, practical and flexible enough to keep pace with innovation rather than slow it down. This means setting baseline expectations for cybersecurity, privacy, AI governance, accountability and transparency while allowing room for responsible experimentation, sector-specific implementation and international alignment. The most effective policies will not treat innovation and regulation as opposing forces, but as complementary: thoughtful regulation can build the trust, confidence and resilience needed for new technologies to be adopted safely and at scale.

Artificial intelligence is transforming both cybersecurity and cyber threats. How should governments and organisations prepare for an environment where AI can be used by both defenders and attackers?

Governments and organisations should prepare for AI’s dual role in cybersecurity by treating it as both a powerful defensive tool and a rapidly evolving risk that requires clear governance, skilled oversight and coordinated action. This means investing in AI-enabled threat detection and response while also strengthening safeguards against AI-driven social engineering, deepfakes, automated attacks and misinformation. Leaders should establish policies for how AI is developed, procured, deployed and monitored and involve cybersecurity, privacy, risk and assurance professionals from the start. ISACA’s State of Cybersecurity survey report found that more and more cybersecurity professionals have become involved in the development, onboarding, or implementation of AI solutions and the development of a policy governing the use of AI technology—a step in the right direction. Organisations should also regularly test whether AI systems can be paused, overridden or secured during an incident. Just as importantly, governments and organisations need to collaborate across borders and sectors so that standards, threat intelligence and response capabilities keep pace with how attackers are using AI.

With cyberattacks increasingly crossing national borders, how important is international cooperation in combating cybercrime and protecting critical digital infrastructure?

International cooperation is essential because cybercrime does not respect borders, while laws, enforcement authorities and incident response capabilities often remain nationally defined. Attacks on critical digital infrastructure can originate in one country, target organizations or citizens in another, and move through systems across multiple jurisdictions, making it difficult for any single government or enterprise to respond effectively alone. Stronger collaboration among governments, regulators, law enforcement, industry and digital trust professionals can improve threat intelligence sharing, coordinated incident response, harmonized standards, cybercrime investigations and support for countries with developing cyber capabilities. As digital infrastructure becomes more interconnected, global cooperation is not optional—it is fundamental to strengthening resilience, protecting economies and maintaining trust in the digital systems that societies increasingly depend on.

Looking ahead, what are the biggest cybersecurity and technology policy challenges you expect organisations and governments to face over the next five years?

Over the next five years, organisations and governments will face the challenge of keeping pace with increasingly sophisticated cyber threats while building policies that protect people and critical infrastructure without slowing responsible innovation. AI-driven attacks, ransomware, deepfakes, supply chain vulnerabilities, data protection requirements and the security of critical digital infrastructure will continue to test both technical defenses and public policy frameworks. At the same time, leaders will need to address persistent cyber skills gaps, strengthen governance and accountability, improve incident preparedness, and align regulations across borders so organisations are not navigating fragmented expectations. The biggest challenge will be building resilience at scale—ensuring that cybersecurity, privacy, AI governance and workforce development advance together as core priorities for trusted digital economies.

Leave a Reply

Your email address will not be published. Required fields are marked *