How AI is transforming cybersecurity from static, rule-based defenses to behaviour-driven, proactive systems how sophisticated phishing, malware and insider threats demand integrated tools the non‑negotiable role of human oversight, regulation and education in an AI-first world In the AI-driven world, cybersecurity will no longer be just about blocking attacks after they happen. In this conversation, Zoho’s AI Security Head, Sujatha S Iyer explains how organisations must move from static, rule-based defenses to behaviour-driven, AI-powered security that can detect anomalies early, secure data across tools and vendors, and build strong guardrails into systems from the start. The discussion also looks at insider threats, phishing, agentic AI, and why human oversight, compliance and continuous education remain central in the age of AI. Recently, there was a US cybersecurity agency that listed three risk areas in AI cybersecurity: cybersecurity of AI systems, AI-enabled cyber attacks and AI-enabled cyber defense. Where do you think most organisations are failing today across these three aspects, and how do you tackle each of them? Organisations today are far more privacy and security aware, with security moving from a checklist item to a core priority. This shift is largely driven by stricter regulations like GDPR, the California Privacy Act, and India’s Digital Personal Data Protection Act. The focus now is on building security into systems from day one. However, many organisations still rely on outdated rule-based systems that are easy to bypass, especially in insider attacks where users stay just below defined thresholds or show subtle anomalies like unusual login times. At the same time, threats have become more advanced. Modern malware and phishing are highly sophisticated and no longer depend on obvious signatures, which makes traditional detection less effective. This is where AI plays a key role. By focusing on behaviour rather than static rules, AI can