Dr. Jagannath Sahoo, Group Chief Information Security Officer (CISO), INOXGFL Group is a seasoned cybersecurity,
risk management, and digital transformation leader with over 24 years of experience spanning Information
Security, Cyber Resilience, IT Governance, Privacy, and Enterprise Risk Management. Throughout his career, he
has led large-scale cybersecurity transformation initiatives across diverse industries, delivering secure
digital innovation while ensuring regulatory compliance and business resilience.
1. Please tell us about your professional journey and your role in the current organization.
Dr. Jagannath Sahoo is a seasoned cybersecurity, risk management, and digital transformation leader with over
24 years of experience spanning Information Security, Cyber Resilience, IT Governance, Privacy, and
Enterprise Risk Management. Throughout his career, he has led large-scale cybersecurity transformation
initiatives across diverse industries, delivering secure digital innovation while ensuring regulatory compliance
and business resilience.
He currently serves as the Group Chief Information Security Officer (CISO) at Gujarat Fluorochemicals Limited
(INOXGFL Group). In this role, he is responsible for defining and executing the Group's cybersecurity
strategy, governance, risk management, privacy, and digital trust programs across IT, OT, cloud, manufacturing,
and emerging technology environments.
Dr. Sahoo leads enterprise-wide initiatives covering Zero Trust Security, Security Operations (SOC), AI-driven
threat intelligence, cyber resilience, ransomware protection, OT/ICS security, data protection, and
regulatory compliance aligned with frameworks such as ISO 27001, NIST CSF, ISO 42001, DPDP Act, and
CERT-In guidelines. He has successfully driven several award-winning cybersecurity and digital trust programs,
including AI-enabled risk intelligence and cyber resilience frameworks that have significantly enhanced threat
detection, incident response, and business continuity capabilities.
Beyond his corporate responsibilities, Dr. Sahoo actively contributes to the cybersecurity ecosystem as a
speaker, mentor, guest faculty, and thought leader, collaborating with academic institutions, industry
bodies, and professional forums to promote cyber awareness, AI governance, and secure digital transformation.
His mission is to build a resilient, secure, and trusted digital enterprise that enables business growth while
effectively managing evolving cyber risks in an increasingly connected world.
2. What are the key Security challenges you face and how do you plan to alleviate them?
AI-Powered Cyber Threats & Deepfakes
Challenge: Sophisticated phishing, business email compromise
(BEC), and social engineering attacks leveraging Generative AI.
Mitigation: Deploy AI-driven threat
detection, email security, deepfake detection controls, and continuous employee awareness programs.
Ransomware & Cyber Resilience
Challenge: Increasingly targeted ransomware attacks impacting
business continuity.
Mitigation: Implement immutable backups, Zero Trust architecture, XDR/SOC capabilities,
ransomware response playbooks, and regular cyber recovery testing.
IT-OT Convergence Risks
Challenge: Expanding attack surface across manufacturing plants, industrial
control systems (ICS), and operational technology environments.
Mitigation: Strengthen OT security
monitoring, network segmentation, secure remote access, asset visibility, and OT-specific incident response
capabilities.
Cloud & SaaS Security
Challenge: Rapid adoption of cloud services leading to data exposure and
misconfiguration risks.
Mitigation: Adopt Cloud Security Posture Management (CSPM), CASB, DLP, encryption,
and continuous cloud configuration monitoring.
Third-Party & Supply Chain Risks
Challenge: Security vulnerabilities introduced through vendors,
OEMs, and partner ecosystems.
Mitigation: Enhance third-party risk assessments, continuous vendor monitoring,
contractual security requirements, and cybersecurity audits.
Identity & Privileged Access Management
Challenge: Credential theft, insider threats, and misuse of
privileged accounts.
Mitigation: Enforce MFA, PAM, Just-in-Time access, Zero Trust access controls, and
continuous identity monitoring.
Data Privacy & Regulatory Compliance
Challenge: Evolving regulations such as DPDP Act, CERT-In
requirements, and global privacy mandates.
Mitigation: Strengthen privacy governance, data classification,
DLP controls, compliance automation, and periodic regulatory assessments.
Cybersecurity Skills Gap
Challenge: Shortage of specialized cybersecurity talent amid rapidly evolving
threats.
Mitigation: Invest in training, certifications, cyber drills, AI-assisted security operations, and
fostering a strong security culture across the organization.
Visibility Across Distributed Digital Ecosystems
Challenge: Managing security across on-premises,
cloud, mobile, remote users, and OT environments.
Mitigation: Establish centralized SOC operations with
integrated SIEM, SOAR, XDR, and real-time threat intelligence capabilities.
Balancing Security with Business Innovation
Challenge: Enabling digital transformation and AI adoption
without compromising security.
Mitigation: Adopt a Security-by-Design approach, AI governance frameworks,
risk-based decision-making, and proactive stakeholder engagement.
Overall Focus: Building a resilient, AI-enabled, Zero Trust-driven cybersecurity ecosystem that protects
business operations, ensures regulatory compliance, and supports secure digital transformation.
3. How do you plan to augment the Security function within your organization?
Accelerate AI-Driven Security Operations
Leverage AI and automation across SOC, threat hunting,
incident response, and risk intelligence to improve detection speed and operational efficiency.
Strengthen Zero Trust Architecture
Expand Zero Trust principles across users, devices, applications,
workloads, and OT environments with continuous verification and least-privilege access.
Enhance Cyber Resilience & Recovery
Invest in ransomware protection, immutable backups, cyber
recovery vaults, and regular resilience testing to ensure business continuity.
Advance IT-OT Security Integration
Improve visibility, monitoring, and risk management across
manufacturing plants and critical industrial systems through dedicated OT security controls.
Expand Threat Intelligence & Proactive Defense
Adopt continuous threat exposure management, attack
surface monitoring, and threat intelligence platforms to identify and mitigate risks before exploitation.
Strengthen Identity & Privileged Access Management
Enhance MFA, PAM, adaptive authentication, and
identity threat detection to protect critical accounts and reduce insider risks.
Elevate Data Security & Privacy Governance
Implement advanced data classification, DLP, encryption,
and privacy controls to comply with DPDP Act, CERT-In, and global regulatory requirements.
Embed Security by Design
Integrate cybersecurity into digital transformation, cloud adoption, AI
initiatives, and new business projects from the planning stage.
Develop a Cyber-Aware Culture
Conduct continuous awareness programs, phishing simulations, executive
tabletop exercises, and role-based security training across the enterprise.
Strengthen Governance & Board Engagement
Enhance cyber risk reporting, security metrics, and
executive dashboards to enable data-driven decision-making and greater board-level visibility.
Strategic Vision: Build an intelligent, resilient, and business-aligned cybersecurity ecosystem that
enables secure digital transformation while protecting the organization's people, data, operations, and
reputation.
4. Any new initiatives in Security undertaken over the past year or planned to be undertaken in future?
New Security Initiatives Undertaken in the Past Year and Planned for the Future
Initiatives Undertaken in the Past Year
- AI-Driven Security Operations: Enhanced SOC capabilities through AI-powered threat detection, XDR,
SIEM, and SOAR integration to improve threat visibility and response times.
- Zero Trust Security Expansion: Strengthened identity security through MFA, PAM, conditional access,
and least-privilege access controls across enterprise environments.
- OT/ICS Security Modernization: Expanded cybersecurity controls across manufacturing plants through
asset visibility, network segmentation, industrial threat monitoring, and secure remote access.
- Cyber Resilience & Ransomware Protection: Implemented immutable backups, cyber recovery
frameworks, and periodic recovery drills to improve resilience against ransomware attacks.
- Cloud Security Transformation: Strengthened cloud governance through CSPM, CASB, DLP, and continuous
security posture assessments.
- Data Protection & Privacy Program Enhancement: Advanced data classification, encryption, and
privacy governance initiatives aligned with DPDP Act, CERT-In guidelines, and global best practices.
- Cyber Awareness & Human Risk Management: Conducted enterprise-wide phishing simulations,
awareness campaigns, and executive cyber crisis exercises to strengthen security culture.
Planned Future Initiatives
- AI-Augmented Cyber Defense Platform: Leverage Generative AI and security copilots for automated
threat analysis, incident investigation, and risk intelligence.
- Continuous Threat Exposure Management (CTEM): Implement proactive attack surface management and
continuous risk validation to identify vulnerabilities before exploitation.
- Advanced IT-OT Convergence Security: Further integrate OT security monitoring with enterprise SOC for
unified visibility and faster incident response.
- Cyber Risk Quantification & Board Dashboards: Develop business-aligned cyber risk metrics and
executive dashboards to support data-driven security investments.
- Adaptive Zero Trust Architecture: Extend Zero Trust principles across applications, cloud workloads,
third-party ecosystems, and emerging digital platforms.
- Security-by-Design for AI & Digital Transformation: Embed security, privacy, and AI governance
controls into all new digital initiatives and Industry 4.0 programs.
- Enhanced Supply Chain Security: Strengthen third-party risk management through continuous vendor
monitoring, security ratings, and independent assessments.
Strategic Objective
To build a resilient, AI-enabled, Zero Trust-driven cybersecurity ecosystem
that protects critical business operations, enables secure digital transformation, and enhances enterprise trust
across IT, OT, cloud, and data environments.
5. How do you foresee Security technologies progressing within India? What are the learnings from global
organizations?
- AI-Powered Cybersecurity will become mainstream -- Indian enterprises will increasingly adopt
AI-driven SOCs, autonomous threat detection, behavioral analytics, and security automation to counter
AI-enabled cyberattacks. This trend aligns with broader industry direction toward AI-led defense and
automation.
- Zero Trust will become the default security architecture -- Organizations will move away from
perimeter-based security toward continuous verification of users, devices, applications, and workloads.
Several industry outlooks identify Zero Trust as a foundational security model for the coming years.
- Cyber Resilience will take priority over prevention alone -- Leading organizations are shifting focus
from "preventing every attack" to ensuring rapid detection, response, recovery, and business continuity
following incidents.
- OT/ICS Security will see significant investment -- As India accelerates Industry 4.0 adoption,
critical infrastructure, manufacturing plants, and industrial control systems will require specialized
protection and continuous monitoring.
- Data Privacy and Digital Trust will drive security spending -- Adoption of privacy regulations and
increasing customer expectations will push organizations to strengthen data governance, encryption, and data
protection programs.
- Quantum-Resistant Security will emerge as a strategic priority -- Forward-looking organizations will
begin planning for post-quantum cryptography and crypto-agile architectures to protect long-term sensitive
information.
Key Learnings from Global Organizations
- Cybersecurity must be treated as a business risk, not just an IT issue. Leading global organizations
integrate cyber risk into board-level decision-making and enterprise risk management.
- Security-by-Design is more effective than Security-by-Remediation. Successful organizations embed
security, privacy, and compliance requirements into digital transformation, cloud, and AI initiatives from
the outset.
- Identity is the new security perimeter. Global breach analysis consistently shows that protecting
identities, privileged access, and credentials is critical to reducing cyber risk.
- Automation is essential to address the cybersecurity skills gap. High-performing security teams
leverage AI, XDR, SOAR, and threat intelligence platforms to improve efficiency and response speed.
- Cyber resilience differentiates mature organizations. The most resilient organizations regularly test
incident response plans, conduct cyber drills, maintain immutable backups, and validate recovery
capabilities before a crisis occurs.
Closing Perspective
India is rapidly evolving from a cybersecurity consumer to a cybersecurity
innovator. The future will be defined by AI-driven defense, Zero Trust, cyber resilience, OT security,
privacy-centric governance, and quantum-ready security frameworks. Organizations that combine these
technologies with strong governance and a security-first culture will be best positioned to navigate the
evolving threat landscape.