Ganesh Devarajan Of EY On How AI is Making Embedded Devices More Vulnerable to Cyberattacks

Ganesh Devarajan Of EY On How AI is Making Embedded Devices More Vulnerable to Cyberattacks

Cybersecurity lets you pair deep technical problem-solving with protecting people, critical infrastructure, and organizations. That combination is what pulled me in, and it’s what has kept me in the field ever since.


As a part of our series about how AI is making embedded devices more vulnerable to cyberattacks, we had the pleasure of interviewing Ganesh Devarajan.

Ganesh is helping build a better working world by transforming cybersecurity into a key enabler of business transformations. He champions the idea of “cyber from the start,” integrating cybersecurity into business and technology initiatives. By promoting a culture of collaboration, trust, and innovation, Ganesh empowers organizations to leverage AI and enhance their competitive edge. His approach ensures that cybersecurity acts as a facilitator, not a hurdle, allowing businesses to navigate challenges confidently and accelerate growth while adopting emerging technologies for a safer digital landscape.

Thank you so much for joining us in this interview series! Before we dig in, our readers would like to get to know you. Can you tell us a bit about how you grew up?

My upbringing was defined by constant movement, spanning three different countries, 19 states, and roughly 26 different cities. I spent the early part of my life in India, moving through cities like Delhi, Mumbai, and Chennai before moving to the Middle East, where I completed middle and high school in Bahrain. This lifestyle of relocation eventually brought me to the U.S. for my first Master’s at Syracuse University, and later to professional chapters in Texas and Arizona, before settling in Illinois for the last 14 years.

I grew up with hardworking parents who influenced my own leadership philosophy today. My journey into a cybersecurity career has led me from offensive research and security engineering to moving to the defensive side and my current role at EY as Americas Consulting Cyber Risk Practice Leader, where I’m responsible for empowering organizations to leverage AI to enhance their cybersecurity competitive edge.

Is there a particular story that inspired you to pursue a career in cybersecurity? We’d love to hear it.

My inspiration came from turning a childhood fascination with how technology works into a career with real, global impact. Early on, I loved digging into the inner workings of systems — from understanding closed applications to watching how data moved through networks. I found myself asking “what could go wrong?” long before I realized there was an entire profession built around that question. The “aha” moment was realizing that the same curiosity that drives you to explore a system can also help you defend it — and that the stakes are often enormous. Cybersecurity lets you pair deep technical problem-solving with protecting people, critical infrastructure, and organizations. That combination is what pulled me in, and it’s what has kept me in the field ever since.

Can you share the most interesting story that happened to you since you began this fascinating career?

A defining moment in my career was learning that the research I had conducted on Industrial Control Systems (ICS) / Supervisory Control and Data Acquisition (SCADA) and vulnerabilities was being utilized at the upper echelon of world governments to address incredibly high-stakes security threats. Knowing my work was being leveraged as a strategic resource provided a powerful confirmation of the importance of this field and my contributions to it. It made me realize how much cybersecurity truly helps make the world a safer and more secure place.

You are a successful leader. Which three character traits do you think were most instrumental to your success? Can you please share a story or example for each?

Work Ethic: My foundation for hard work was built by watching my parents navigate significant challenges. My father joined the Navy at just 16 years old to support his seven siblings, eventually rising through the ranks to become a Chief Petty Officer. My mother, who is my biggest role model, was a university gold medalist in statistics but was initially denied entry into an MBA program because the university preferred to give the seat to a male student. She filed a court case, fought it in the High Court and won, and successfully earned her MBA degree. Growing up with that level of dedication, persistence and resilience instilled in me a work ethic that is now a core part of who I am as a leader.

Open-Mindedness: From a cybersecurity professional’s perspective, open-mindedness and problem-solving aren’t just nice leadership traits- they’re operational necessities. Cyber threats don’t follow predictable patterns. Attackers constantly evolve their tactics, combining techniques in ways that bypass traditional defenses. A leader who is rigid in thinking or overly reliant on past solutions will fall behind quickly. Open-mindedness allows a cybersecurity leader to stay receptive to new ideas, emerging technologies, and unconventional approaches.

Teamwork: The team aspect of leadership is one of my highest priorities because I’d rather build something meaningful together than chase individual credit. In cybersecurity, the mission is bigger than any one person — protecting others, sharing context quickly, and making better decisions as a group.

Are you working on any exciting new projects now? How do you think that will help people?

One important project we’re working on now focuses on the growing strain organizations are feeling from AI-related security risks. Instead of treating AI as something you tack on to improve efficiency, we’re building security directly into the foundation. Our goal is to go beyond just spotting problems- we’re creating systems that can actually respond to and stop threats in real time.

By allowing these systems to both identify and fix issues on their own, response times can drop from months or hours to just minutes and seconds. The end result is simple: leaders can feel more confident knowing that even complex attacks are being handled quickly and effectively mitigated.

Ok super. Thank you for all that. Let’s now shift to the main focus of our interview. In order to ensure that we are all on the same page let’s begin with some simple definitions. Can you tell our readers about the different forms of cyber attacks prevalent today?

To understand the current threat landscape, we must recognize that we are at a high-stakes crossroads where AI is weaponizing the digital landscape just as it fortifies defenses. Manual defenses used to be enough, but today’s attacks are faster and more advanced than those methods can keep up with. In fact, almost all (96%) of senior security leaders say AI-enabled cybersecurity attacks are a significant threat to their organization, with about half (48%) estimating that of all the cybersecurity incidents their organization had experienced in the past year, at least a quarter were enabled by AI, according to the EY Cybersecurity Roadmap Study.

These AI-enabled threats manifest in several sophisticated forms, including Advanced Persistent Threats (APTs), which involve long-term, stealthy network infiltration for data harvesting, and deepfake or impersonation attacks that use manipulated media to deceive security protocols. We also see prevalent risks in account takeovers or identity-based attacks, which target the digital keys and permissions governing user access, alongside real-time fraud, which relies on automation to execute high-speed deceptive activities.

Ultimately, as these advanced tactics have become standard, AI-driven attacks have upended the cyber landscape, leaving traditional security approaches no longer sufficient to keep pace.

How do you ensure the ongoing monitoring and detection of potential security threats posed by AI systems? What tools, technologies, or processes do you use to stay vigilant and respond promptly to emerging threats?

To stay ahead of attackers operating at machine speed, organizations have shifted from manual vigilance to an autonomous defense framework. Security leaders can ensure ongoing monitoring by leveraging AI-driven platforms that handle high-stakes security functions in real time, specifically behavioral analytics and automated threat hunting. These tools allow organizations to identify anomalies and pinpoint predictive vulnerabilities before they can be exploited.

By deploying systems that can reason and respond independently, leaders close the window of opportunity for attackers and move from a reactive state to one of proactive prevention, significantly improving the overall time to recovery in an ever-evolving landscape.

With the increasing use of AI in various industries, how do leaders strike a balance between maintaining security and enabling innovation? What approaches or methodologies do you follow to ensure security without stifling technological advancements?

Striking the right balance between security and innovation means going beyond simply layering AI onto existing processes, which often slows progress. Instead of automating outdated approaches, organizations need to adopt an AI-native mindset where security is built in from the start as a foundation of trust.

That foundation needs to be intentionally designed across areas like governance, compliance, transparency, and ethics so AI systems can scale safely and reliably.

Equally important is how people and AI work together. The goal isn’t just to operate side by side, but to amplify each other’s strengths. Leaders ensure accountability and sound judgment, creating the confidence needed to adopt AI more broadly so that automation enhances decision-making rather than undermines it.

Collaboration and information sharing among organizations are crucial in combating security threats from malicious AI. How do leaders foster collaboration within the industry, both in terms of sharing threat intelligence and developing common best practices to protect against evolving threats?

Fostering collaboration across organizations is now a strategic necessity, particularly in an unsettled regulatory environment. Organizations must work together to establish strong internal governance and shared standards that ensure AI systems remain safe, trusted, and compliant. As it stands today, virtually all senior security leaders report having an AI cybersecurity governance framework in place, and among those, 98% agree that the framework has proven essential for ensuring the responsible use of AI.

This requires moving beyond siloed defenses toward a collective model built on shared threat intelligence, aligned governance, and common best practices. By integrating human-in-the-loop frameworks, pooling resources, and coordinating investments, organizations can create a more unified approach to risk management and response.

Ultimately, this kind of collaboration enables a more resilient security posture that evolves in step with emerging threats, reduces duplication of effort, and strengthens the industry’s ability to both anticipate and counter increasingly sophisticated, AI-driven attacks.

Can you share a real-world example where an organization effectively prevented or minimized a security threat from malicious AI? What measures did they take, and what lessons can other organizations learn from their experience?

We’re seeing a sharp rise in malicious use of AI to automate everything from highly convincing phishing campaigns to coordinated attacks that move across networks at machine speed. In many cases we have worked on, organizations were facing repeated, fast-moving intrusion attempts that were slipping past traditional, alert-based defenses. Their existing process relied heavily on human review, which meant response times stretched into hours, which is far too slow for the pace of these attacks.

To address this, they shifted to a model that prioritized immediate action. Instead of simply flagging suspicious behavior, they implemented systems that could automatically contain threats, isolating affected accounts, cutting off suspicious connections, and triggering remediation steps the moment something abnormal was detected. This reduced their response time from hours to minutes and significantly limited the impact of each incident.

The key lesson for other organizations is straightforward: speed now matters as much as accuracy. If your defenses are built only to detect and escalate, you’re already behind. Organizations need to design their security approach around rapid response and containment, not just visibility. In an environment where attackers are operating at machine speed, any delay creates an opening- and if your response is measured in hours, you will lose that battle every time.

Here is our main question. What are the “5 Things We Must Do To Protect From AI-Powered Cyberattacks” and why?

1. Reprioritize Budgets Toward AI-Native Defense

We have to acknowledge that cyber threats are advancing faster than most organizations can keep up with, making it a strategic necessity to rebalance technology spend toward AI-driven cybersecurity. This isn’t just a future-dated worry; it is hitting the bottom line today, as the majority (85%) of senior security leaders who are using AI in cybersecurity say that their current cybersecurity budget is insufficient to meet AI-enabled threats. While just 9% of senior security leaders today say that at least a quarter of their organizations’ total cybersecurity budget is dedicated to AI solutions for cybersecurity, an impressive 48% say this will be the case in two years. This investment shift is fueled by the reality that manual security processes simply cannot scale on their own to meet the speed of AI-driven threats.

2. Deeply Integrate Agentic AI into Core Security Functions

Real value comes when agentic AI is built into everyday cybersecurity operations — not treated as a side quest. And as threats move faster than humans can respond, organizations are increasingly relying on AI to take on critical tasks like detecting persistent attacks. By embedding these systems more deeply, it allows organizations to better handle high-speed, high-volume threats in real time, strengthening overall resilience and freeing up security teams to focus on more strategic decisions.

3. Maintain Oversight

As AI systems take on more responsibility, strong human oversight is essential to building trust in their decisions. While AI excels at detecting patterns and acting quickly, it can miss the context and nuance required in high-stakes situations, making fully automated responses potentially too rigid. Keeping people actively involved ensures AI enhances, rather than replaces, decision-making, combining speed with the judgment needed to act responsibly.

4. Architect Governance as a System of Trust

Governance should be the foundation for responsible, reliable, and scalable AI deployment across the enterprise. Strong governance is what turns AI’s potential into real business value, ensuring systems are used safely and effectively. Without it, organizations face significant exposure to security and compliance risks, including a higher likelihood of data breaches tied to unmanaged AI activity. In today’s uncertain regulatory environment, mature internal governance acts as a stabilizing force, helping ensure AI remains secure, trusted, and accountable as external rules continue to evolve.

5. Re-skill and Upskill the Workforce

One of the biggest risks in AI-enabled cybersecurity today is the growing skills gap. Many organizations recognize that when teams aren’t trained to handle AI-driven threats, overall security is significantly weakened. So rather than replacing human expertise, AI should be shifting the role of the workforce toward higher-value work, such as strategic decision-making, governance, and validating critical actions. When teams are properly trained to use these tools, organizations see major gains in efficiency, allowing people to focus less on routine tasks and more on the complex challenges that require human judgment.

You are a person of enormous influence. If you could inspire a movement that would bring the most amount of good to the most amount of people, what would that be? You never know what your idea can trigger. :-)

If I could inspire a movement, it would be focused on making the world a much safer and more secure place for everyone to live in. The core of this effort would be around encouraging people to move beyond looking out only for their individual personal gains and instead prioritize the collective security of our global community. I believe that if I could spread the word and inspire people to focus on this broader goal of mutual protection, it would bring the greatest amount of good to the largest number of people.

How can our readers further follow your work online?

To see more of my work, you can follow me on LinkedIn here and learn more about the EY Cybersecurity practice here.

This was very inspiring and informative. Thank you so much for the time you spent with this interview!

TechVIP InterviewsEY
AM
Written by

Authority Magazine Editorial Staff

Writer & Contributor

Contributor at Authority Magazine covering leadership, innovation, and industry insights.

Authority Magazine
Published inAuthority MagazineTop Lessons, Top Authorities · 42K Followers

Exclusive, curated interviews with the leaders and changemakers shaping tomorrow. Leadership lessons, industry deep dives, and executive profiles.