HomeLatest NewsCyber SecurityIndia and APAC must leverage AI and OT security to protect Supply Chains

India and APAC must leverage AI and OT security to protect Supply Chains

Supply chain disruptions can dominate headlines and create chaos in global markets. 

Preferred Source of Google

The world struggled with a lack of supplies when the pandemic wreaked havoc on supply chains, and again, in 2021, the Ever Given ship blocked the Suez Canal for six days, holding up billions of dollars worth of goods. However, a subtler yet potentially more alarming risk has been poking holes in our supply chains again—cyber attacks.

While the risk of falling prey to a cyber attack looms, facility operators aren’t considering risks when adopting new technologies that boost facility efficiency. This of facilities includes adopting simple internet-connected devices, such as cameras and sensors, that send information to the for managers to retrieve off-site, expanding the arena of cyber threats from a physical facility to a data-heavy cloud infrastructure.

The exciting potential for operators to connect some sensors to boost efficiency leaves security teams with a new level of complexity and risk without the tools needed to mitigate it properly. 

Advertisement
Saksham Bharat 2026
Saksham Bharat 2026
A multi-stakeholder dialogue on skilling gap in Cybersecurity, Data Resilience and AI — and the roadmap to a Saksham Bharat.
Register Now →
VeeamON 2026 Tour India - Mumbai
VeeamON 2026 Tour India - Mumbai
A VeeamON 2026 India Leadership Series Mumbai for senior public sector and government technology leaders.
Register Now →
Cyber Surakshit Uttar Pradesh
Cyber Surakshit Uttar Pradesh
Find out strategies, frameworks and solutions for building a resilient and secure digital ecosystem across Uttar Pradesh.
Register Now →
VeeamON 2026 Tour India - Bengaluru
VeeamON 2026 Tour India - Bengaluru
A VeeamON 2026 India Leadership Series Bengaluru for senior public sector and government technology leaders.
Register Now →
VeeamON 2026 Tour India - Delhi
VeeamON 2026 Tour India - Delhi
A VeeamON 2026 India Leadership Series Delhi for senior public sector and government technology leaders.
Register Now →
Infosec Reimagined
Infosec Reimagined
Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.
Register Now →
Digital Senate
Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.
Register Now →
CIO Prism
CIO Prism
CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.
Register Now →

Aimed at instant connectivity, many of these devices lack security protocols and run on ‘hacker-friendly’ software. This imbalanced approach has made it too easy for private or state-run attackers to lock medical workers out of a health facility, take out power stations, and threaten critical pieces of infrastructure. Therefore, it’s no coincidence that over half of facilities reported attacks between 2023 and 2024, compared to only 11% in the 12 months prior. While the financial loss is enough for private organisations to take action, an attack on critical infrastructure is enough to put an entire public region in danger.

Now, if maximum impact is what hackers are looking for, then all eyes should be on the cloud. This is because a staggering 94% of global companies leverage the cloud in their daily operations. This trend is reflected in data storage, with a whopping 60% of corporate data residing in the cloud at the end of last year. With nearly half of companies feeling comfortable storing their critical data in the cloud, it’s questionable whether the current security protocols are enough to prepare for future attacks.

Data Security in the Cloud

The increasingly hostile threat landscape demands that decision-makers outside of security teams be more aware and proactive in securing the Asia-Pacific and Japan (APJ) region, particularly in India, surrounding how data is stored and secured both on-premises and in the cloud. 

Advertisement

While the Indian government has begun implementing data security regulations, such as the Digital Personal Protection Act of 2023, it remains unclear if the requirements are enough for Indian enterprises to remain secure as significant overhauls of operational technology (OT) security are expected within the next three to five years. However, unlike the US, which has comprehensive guidelines from the National Institute of Standards and Technology (NIST) and a Supply Chain Resilience Council, or the EU, which has the Cybersecurity Act (CRA) and Network and Information Systems Directive (NIS2), India has not yet adopted such rigorous national measures focused on supply chains. 

This leaves each organisation to conduct an internal security audit and decide which steps are relevant to them, an approach that lacks standardisation and is ripe for weak links. 

As Indian manufacturing becomes increasingly prominent in global supply chains, public and private stakeholders must prioritise OT security. The proactive measures seen in sectors like healthcare and should serve as models for the industrial sector.

Advertisement

Leveraging AI’s Double-Edged Sword

Given the rapid growth of industrial sectors in India and the rise of sophisticated hackers leveraging AI, fighting fire with fire is the only viable strategy.

While AI’s defensive capabilities have been recognised and deployed in both endpoint and cloud security environments, hackers can also use it to probe systems faster than ever until a vulnerability is found. This technology can automate attacks, create more convincing phishing schemes, and develop malware that adapts to avoid detection.

To secure the supply chain, AI tools must be able to look across internal and 3rd party data to identify potential threats and pre-emptive solutions. This is because AI-driven tools thrive at automating threat detection and response activities, reducing the burden on human analysts and allowing them to focus on more complex tasks. Large language models (LLMs), for example, can quickly process and analyse vast amounts of data, identifying threats in real time and providing actionable insights.

AI also plays a crucial role in upskilling employees within cybersecurity teams. Leveraging LLMs in everyday tasks to explain complex findings, junior team members can confidently make impactful decisions based on AI-driven insights. These models allow analysts to use natural language queries to gather information, eliminating the need for specialised training in various querying languages. Running queries like “Can vulnerability ‘#123′ be found anywhere in the network? Are there any active exploitations occurring on the network?” followed up with other relevant questions, such as “How have other teams handled this vulnerability?” allows teams to remain agile, quickly identifying potential threats and taking necessary action.

Furthermore, AI assists in automating routine tasks, allowing cybersecurity professionals to focus on strategic initiatives. It can offer next-step recommendations based on previous actions, enhancing decision-making. For example, when an alert is triggered, AI can provide insights such as “This alert is typically dismissed by 90% of users” or “An event looks suspicious; click here to investigate further.” This streamlines operations and accelerates the learning curve for junior analysts, enhancing the entire team’s capabilities.

Looking Forward

As we look to the future, integrating AI into both OT and cloud security strategies will be pivotal in safeguarding critical infrastructure and supply chains that society relies on. Combining AI-driven insights and human expertise will create a formidable defence against cyber threats. However, this requires a concerted effort from governments, businesses, and security professionals to embrace these technologies and implement robust security frameworks.

The only path forward involves adopting advanced technologies allowing for greater cybersecurity awareness and education from day one. By prioritising OT security and leveraging AI, India and the region as a whole can build a resilient infrastructure that withstands the evolving threat landscape. The time to act is to stay ahead of cybercriminals and protect the critical systems underpinning our economies and daily lives.

The author is Sr. Director of Cloud Security at SentinelOne. Views are personal.

Get the day's headlines from Tech Observer straight in your inbox

By subscribing you agree to our Privacy Policy, T&C and consent to receive newsletters and other important communications.
Anand Prakash
Anand Prakash
Anand Prakash is Sr. Director of Cloud Security at SentinelOne. He joined the firm after his company PingSafe, a cloud-native application protection platform, was acquired by SentinelOne for $100 million.
- Advertisement -
Powered By Veeam Logo
- Advertisement -

Subscribe to our Newsletter

By subscribing you agree to our Privacy Policy, T&C and consent to receive newsletters and other important communications.
- Advertisement -

India to Lead Global IT Security Standards Body for Two Years

India will chair the Common Criteria Development Board from April 2026, gaining influence over international IT security certification standards recognised by 38 countries.

RELATED ARTICLES