Resilience in the Age of Unknowns: The CXO Playbook Forward

Shailendra Fuloria, Vivek Yadav (Director for Cybersecurity · Ministry of Defense), Yask Sharma, Nageshwaran Chinnadurai (CISO · TVS Motors)

Nullcon Goa 2026 · Day 1

Overview

The Nullcon panel discussion, "Resilience in the Age of Unknowns: The CXO Playbook Forward," delved into a critical re-evaluation of cybersecurity resilience. Moderated by Shailendra Fuloria, the session brought together a distinguished panel comprising Nageshwaran Chinnadurai, CISO for TVS Motors; Yask Sharma, an expert in security, privacy, and IT/OT convergence; and Commander Vivek Yadav, Director for Cybersecurity at the Ministry of Defense. The central theme explored whether the traditional understanding of resilience—often limited to backup and restore procedures, compliance checks, and basic metrics—remains adequate in a rapidly evolving threat landscape.

Watch on YouTube

Visual summary for Resilience in the Age of Unknowns: The CXO Playbook Forward by Shailendra Fuloria, Vivek Yadav, Yask Sharma, Nageshwaran Chinnadurai
Visual summary for Resilience in the Age of Unknowns: The CXO Playbook Forward by Shailendra Fuloria, Vivek Yadav, Yask Sharma, Nageshwaran Chinnadurai

Key moments

  1. 0:00 Introduction: Defining resilience in a changing world
  2. 1:40 Manufacturing's challenge: Balancing safety, production, and IT/OT security
  3. 2:50 Defense perspective: Nation-state threats and 'breach first' approach
  4. 4:10 Defense's Zero Trust Architecture and preventing lateral attacks
  5. 5:55 Fighting AI with AI: Defense's strategy for dynamic threats
  6. 8:20 Resilience is not just a technology problem

Resilience in the Age of Unknowns: The CXO Playbook Forward

Speakers: Shailendra Fuloria; Vivek Yadav (Director for Cybersecurity, Ministry of Defense); Yask Sharma; Nageshwaran Chinnadurai (CISO, TVS Motors)

Conference: Nullcon

YouTube: https://www.youtube.com/watch?v=2TzxM-rbuHM

Overview

The Nullcon panel discussion, "Resilience in the Age of Unknowns: The CXO Playbook Forward," delved into a critical re-evaluation of cybersecurity resilience. Moderated by Shailendra Fuloria, the session brought together a distinguished panel comprising Nageshwaran Chinnadurai, CISO for TVS Motors; Yask Sharma, an expert in security, privacy, and IT/OT convergence; and Commander Vivek Yadav, Director for Cybersecurity at the Ministry of Defense. The central theme explored whether the traditional understanding of resilience—often limited to backup and restore procedures, compliance checks, and basic metrics—remains adequate in a rapidly evolving threat landscape.

The discussion highlighted the multifaceted challenges posed by the increasing influx of AI technologies, the complexities of global supply chains, and dynamic geopolitical scenarios. These external and internal pressures necessitate a more comprehensive and proactive approach to cybersecurity. The panelists, representing diverse sectors from manufacturing and industrial control systems to national defense, offered unique perspectives on how their respective domains are grappling with these challenges, emphasizing the need to move beyond purely technological solutions to incorporate business continuity, strategic foresight, and adaptive architectural models.

This article dissects the key insights from this crucial conversation, examining how leading organizations are redefining resilience to withstand sophisticated attacks, manage legacy systems, and secure interconnected environments. It underscores the imperative for CXOs and cybersecurity professionals to adopt a holistic strategy that accounts for both malicious intent and accidental mischance, ensuring operational continuity in an era defined by constant change and emergent threats.

Background

▶ Watch: Introduction: Defining resilience in a changing world (0:00)

For many years, cybersecurity resilience has been primarily understood through the lens of recovery: the ability to restore systems and data after an incident, often relying on robust backup solutions and adherence to regulatory compliance frameworks. While essential, this reactive posture is proving increasingly insufficient against the backdrop of an accelerating technological paradigm shift and a volatile geopolitical climate. The advent of sophisticated Artificial Intelligence (AI), now weaponized by advanced persistent threats and nation-state actors, has introduced a new dimension of attack complexity and adaptability, rendering static, definition-based defenses largely obsolete.

Furthermore, the proliferation of complex supply chains has expanded the attack surface exponentially. Organizations are no longer isolated entities; their security posture is intrinsically linked to the weakest link within their extensive network of suppliers and service partners. This interconnectedness, particularly in critical sectors like manufacturing and defense, introduces significant third-party risks that traditional perimeter security models struggle to address. Adding to this complexity are the inherent challenges of managing legacy systems—industrial control systems (ICS) and operational technology (OT) in manufacturing, or decades-old defense platforms—that possess exceptionally long lifecycles. These systems, not originally designed with modern cybersecurity threats in mind, are now being integrated with IT infrastructure for enhanced analytics and automation, creating new vulnerabilities at the IT/OT convergence layer. The talk addresses the urgent need to evolve resilience strategies beyond mere recovery to encompass proactive defense, comprehensive risk management across extended ecosystems, and architectural adaptability to secure long-lived assets against novel threats.

Key Findings

▶ Watch: Defense perspective: Nation-state threats and 'breach first' approach (2:50)

The panel discussion brought forth several critical findings that redefine cybersecurity resilience for modern enterprises and national security entities:

  1. Resilience as a Business Problem, Not Just Technology: Yask Sharma emphatically stated that resilience extends far beyond technological solutions. While technology forms a part of prediction and withstand capabilities, true resilience involves a strong business angle, anticipating scenarios where technology fails and having alternate, possibly non-technology dependent or manual, ways of operating. The 2021 oil and gas attack in the US, which crippled operations due to over-reliance on technology, served as a stark example.
  2. "Breach First" Approach and Zero Trust: Commander Vivek Yadav highlighted the Ministry of Defense's adoption of a "breach first" approach, assuming that a breach has already occurred and building defenses from that premise. This is complemented by a Zero Trust Architecture (ZTA), which prevents privilege escalation and lateral movement by strictly demarcating duties and setting clear boundaries, even if perimeter security is compromised.
  3. Fighting AI with AI: Recognizing that most modern attacks are heavily reliant on AI, the Ministry of Defense has shifted from static, definition-based responses to ingraining AI into their security operations. This involves training AI models on past attack data and deploying them in Security Operations Centers (SOCs), Endpoint Detection and Response (EDR) solutions, and Business Continuity Management (BCM) systems to effectively combat AI-powered threats with AI-powered defenses.
  4. Strategic Management of Legacy Systems: The discussion acknowledged the pervasive challenge of long-lifecycle systems (e.g., 30-40 year old submarines, 18-year product lifecycles). Commander Yadav emphasized modular system design and securing data pipelines. Crucially, data is kept encrypted at rest, in motion, and during processing, often using proprietary algorithms or increased key sizes rather than solely relying on standard algorithms like those from NIST, especially where data longevity is paramount.
  5. Comprehensive Supply Chain Security: Nageshwaran Chinnadurai outlined the manufacturing sector's approach to supply chain security. This involves a robust Third-Party Risk Management (TPRM) framework to align partners with recommended security use cases. Key measures include secure remote access for service partners, ensuring secure access to internal resources for suppliers, and conducting regular manual assessments of critical suppliers to mitigate indirect business impacts from cyber incidents.
  6. Skepticism Towards Standardized Quantum Algorithms: Commander Yadav expressed caution regarding the rush to migrate to quantum-safe algorithms by deadlines like 2027. He noted that out of the four algorithms initially selected by NIST, two had already been broken, underscoring the need for critical evaluation and potentially developing indigenous, proprietary solutions rather than blindly following international standards, particularly for national security.
  7. Custom Architectures for Critical Infrastructure: A significant finding was the imperative for critical sectors, especially defense, to devise their own architectural models, principles, and algorithms. This stems from the understanding that architectures mandated by external bodies (e.g., RBI for financial institutions) may not fit the unique requirements and long-term legacy considerations of specific industries.
  8. Addressing IT/OT Convergence Challenges: The integration of long-lived OT equipment with IT systems for advanced analytics (predictive, prescriptive, real-time data) introduces significant security challenges. Yask Sharma pointed out that these require either compensatory controls at the technology level or policy changes, recognizing that the desire for more data and real-time responses from these systems inherently expands their attack surface.

Technical Deep Dive

▶ Watch: Defense's Zero Trust Architecture and preventing lateral attacks (4:10)

The panel articulated several advanced technical strategies and architectural philosophies crucial for building resilience in complex environments. At the core of the Ministry of Defense's strategy is a profound commitment to Defense in Depth, coupled with a "breach first" approach. This paradigm shifts the focus from preventing all breaches (an increasingly impossible task against nation-state adversaries) to assuming compromise and designing systems that can detect, contain, and recover from intrusions with minimal impact.

A cornerstone of this approach is the implementation of a Zero Trust Architecture (ZTA). This model fundamentally rejects the notion of implicit trust, even for users or devices already within the network perimeter. Instead, every access request, regardless of origin, is authenticated, authorized, and continuously validated. Commander Yadav detailed how ZTA is applied to prevent privilege escalation and lateral movement—critical attack techniques often employed by sophisticated adversaries. This is achieved through strict demarcation of duties and the establishment of clear boundaries, ensuring that even if an attacker breaches a segment, their ability to move further into the network is severely restricted.

The discussion also highlighted the strategic use of Artificial Intelligence (AI) in cybersecurity. Moving beyond traditional signature-based detection, which is static and reactive, the Ministry of Defense is actively integrating AI into its defensive posture. This involves a proactive strategy of "fighting AI with AI," where AI models are trained on historical attack patterns and threat intelligence to anticipate and respond to evolving threats. These AI capabilities are embedded across various security components, including Security Operations Centers (SOCs) for real-time threat analysis, Endpoint Detection and Response (EDR) solutions for advanced threat hunting and remediation, and Business Continuity Management (BCM) systems to ensure operational resilience. This shift enables dynamic, adaptive responses to attacks that themselves leverage AI for stealth and evasion.

Securing legacy systems with long lifecycles, a common challenge in manufacturing and defense, necessitates specialized technical considerations. The panel emphasized modular system design to allow for incremental upgrades and security enhancements without overhauling entire infrastructures. Crucially, data security is paramount for these systems, with a focus on encryption – ensuring data is encrypted at rest, in motion, and even during processing. Commander Yadav revealed that for highly sensitive, long-lived data, the Ministry of Defense often employs proprietary algorithms or significantly increases the key sizes of existing algorithms, rather than solely relying on standard algorithms like those provided by NIST, to enhance cryptographic strength and longevity against future attacks, including potential quantum threats. Furthermore, micro-segmentation is utilized to isolate older, more vulnerable systems, containing potential breaches to small, manageable areas.

For manufacturing, supply chain security is addressed through a robust Third-Party Risk Management (TPRM) framework. This framework dictates security requirements for all suppliers and service partners. Technically, this includes mandating secure remote access protocols for external entities performing maintenance or other activities on internal OT networks. For suppliers accessing internal resources or applications, such as a SaaS platform integrating with server infrastructure, secure access mechanisms are meticulously implemented and monitored. Regular manual assessments are conducted for critical suppliers to verify their adherence to security standards and to proactively identify and mitigate risks that could indirectly impact the business.

The IT/OT convergence presents unique technical challenges. As industrial devices and IoT sensors in manufacturing plants are increasingly connected to IT networks for data collection and analytics, securing this interface becomes critical. Nagesh Chinnadurai underscored the importance of strengthening connectivity from IT to OT and securing industrial IoT (IIoT) devices. This requires implementing robust network segmentation, intrusion detection systems tailored for OT environments, and strict access controls to prevent threats from traversing between the IT and OT domains. The drive for real-time data and predictive maintenance from long-lived OT equipment necessitates sophisticated data isolation and secure communication protocols to prevent the expanded attack surface from being exploited.

Demo / Proof of Concept

▶ Watch: Fighting AI with AI: Defense's strategy for dynamic threats (5:55)

The panel discussion focused on strategic and architectural approaches to cybersecurity resilience rather than specific tool demonstrations or proof-of-concept exploits. As such, no live demo or technical proof of concept was presented during the talk. The insights provided were primarily conceptual and philosophical, grounded in the practical experiences of the speakers in their respective high-stakes environments.

Defensive Implications

▶ Watch: Resilience is not just a technology problem (8:20)

The insights from this panel offer a robust playbook for defenders looking to enhance their organizational resilience against an increasingly complex threat landscape.

  1. Adopt a "Breach-First" Mindset and Zero Trust: Defenders must fundamentally shift their perspective from preventing all breaches to assuming compromise. This necessitates designing systems with inherent capabilities for detection, containment, and rapid recovery. Implementing a Zero Trust Architecture (ZTA) is paramount, ensuring continuous verification of all users and devices, strict access controls, and granular segmentation to prevent lateral movement and privilege escalation, even within the trusted network perimeter.
  2. Integrate AI into Defensive Strategies: Given the prevalence of AI-driven attacks, organizations must leverage AI proactively in their defense. This means deploying AI-powered solutions in SOCs, EDR systems, and BCM processes to enable dynamic, adaptive threat detection and response. Training these AI models on diverse threat intelligence and historical attack data will be crucial for staying ahead of sophisticated adversaries.
  3. Fortify Supply Chain Security with TPRM: Organizations must recognize the extended attack surface presented by their supply chains. Establishing and rigorously enforcing a comprehensive Third-Party Risk Management (TPRM) framework is essential. This includes mandating secure remote access protocols for all external partners, ensuring secure integration points for supplier applications, and conducting regular, in-depth security assessments of critical third-party vendors to mitigate cascading risks.
  4. Strategize for Legacy Systems and IT/OT Convergence: For environments with long-lived systems (e.g., ICS/OT in manufacturing, older defense platforms), defenders should prioritize modular system design to facilitate security upgrades. Implementing robust encryption for data at rest, in motion, and during processing, potentially using proprietary or enhanced algorithms, is critical. Micro-segmentation should be employed to isolate vulnerable legacy components and limit the blast radius of a breach. When integrating OT with IT for analytics, ensure secure connectivity, protocol translation, and stringent access controls at the convergence points.
  5. Cultivate Business Resilience Beyond Technology: Cybersecurity resilience is not solely a technology problem; it's a business imperative. Defenders must collaborate with business stakeholders to identify critical functions and develop non-technology dependent alternatives or manual fallback procedures for scenarios where IT systems are completely compromised. This proactive anticipation of disruption ensures operational continuity even in the face of severe cyber incidents.
  6. Develop Custom Security Architectures and Algorithms: Critical infrastructure and national security organizations should critically evaluate generic security mandates and standards. Where appropriate, they should invest in developing custom architectural models, security principles, and even proprietary cryptographic algorithms tailored to their unique threat landscape, operational requirements, and the longevity of their assets. This bespoke approach can provide a higher degree of security assurance than off-the-shelf solutions.
  7. Prepare for Emerging Threats with Caution: While preparing for future threats like quantum computing is important (e.g., considering migration by 2027), defenders should approach new technologies and proposed solutions with a healthy degree of skepticism. Continuously evaluating the security of new algorithms and standards, as highlighted by the issues with NIST's quantum algorithm selections, is vital to avoid adopting solutions that may themselves introduce new vulnerabilities.

Key Takeaways

  • Holistic Resilience: Cybersecurity resilience must evolve beyond technical recovery to encompass a holistic business approach, integrating anticipation, non-technological alternatives, and manual fallback procedures.
  • Proactive Defense Against Nation-States: Faced with sophisticated nation-state actors, organizations, especially in critical sectors, must adopt proactive strategies like a "breach-first" mindset and rigorous Zero Trust Architectures to contain and mitigate attacks.
  • AI as a Defensive Imperative: To counter AI-driven threats, defenders must embed AI-powered solutions into their SOCs, EDR, and BCM systems, effectively "fighting AI with AI" for dynamic threat detection and response.
  • Strategic Management of Complex Ecosystems: Securing intricate supply chains requires robust Third-Party Risk Management (TPRM) frameworks, secure remote access, and continuous assessments, while long-lived legacy systems demand modular design, strong encryption, and micro-segmentation.
  • Customization Over Standardization: Critical infrastructure and defense entities should prioritize developing custom security architectures, principles, and algorithms tailored to their unique operational context, rather than blindly adhering to generic or external mandates.
  • Critical Evaluation of Emerging Technologies: While preparing for future threats like quantum computing, a cautious and critical assessment of new algorithms and proposed solutions is essential to ensure they genuinely enhance security and do not introduce new vulnerabilities.

About the Speaker(s)

Shailendra Fuloria moderated the panel, guiding the discussion on the evolving definition of resilience in cybersecurity, particularly in the context of AI, complex supply chains, and geopolitical shifts.

Nageshwaran Chinnadurai serves as the CISO for TVS Motors, bringing an invaluable perspective from the manufacturing industry. His expertise lies in balancing operational safety and availability with cybersecurity, particularly concerning the security of industrial devices, IoT, IT/OT convergence, and managing complex supply chains through Third-Party Risk Management (TPRM) frameworks.

Vivek Yadav, Director for Cybersecurity at the Ministry of Defense, provided insights into national security resilience. His focus is on defending against nation-state actors, employing advanced strategies like a "breach first" approach, Zero Trust Architecture, and leveraging AI to combat AI-driven attacks. He also discussed the challenges of securing legacy systems with long lifecycles and the critical evaluation of new cryptographic standards, including quantum-safe algorithms.

Yask Sharma shared his expertise in security and privacy, with a focus on the convergence of IT and OT industries. He emphasized that resilience is not solely a technology problem but requires a significant business angle, including anticipating disruptions and preparing non-technology dependent or manual operational alternatives to ensure continuity during cyber incidents.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

A panel that had the ingredients for a genuinely interesting conversation — MoD director, manufacturing CISO, IT/OT practitioner — but delivered a greatest-hits album of cybersecurity talking points with almost no specificity or insider signal. The write-up is padded to three times the length the content warrants, and the actual substance underneath is thin.

Heather Calloway (CISO) — SOLID

A credible panel with real practitioners talking about real problems — resilience, legacy systems, IT/OT convergence, supply chain risk — but the conversation stays at the principle level throughout. Nothing here would change how a security program operates tomorrow.

→ Top-rated talks at Nullcon Goa 2026

All talks from Nullcon Goa 2026