August 4, 2026

"We Have Moved from Technology Security to Business Security" - Ratan Jyoti, CISO, Ujjivan SFB

Prateek Bhajanka
FieldCISO & Former Gartner Analyst
"We Have Moved from Technology Security to Business Security": Ratan Jyoti | Fix the Risk
Fix the Risk · A Hive Pro Podcast

"We Have Moved from Technology Security to Business Security"

A conversation on why known vulnerabilities still persists, what makes threat intelligence selective, and how CTEM changed his team's work queue.

Podcast Interview CTEM Threat Intelligence
Guest
Ratan Jyoti
Role
CISO
Institution
Ujjivan Small Finance Bank
Host
Prateek Bhajanka

Ratan Jyoti has lived through the various phases of transformation of the cybersecurity discipline. Over the course of the conversation he makes an argument that cuts against most industry consensus: the tools work, the visibility works, and organisations still get breached because they rank the wrong problems first.

What follows is that conversation, lightly edited for readability.


How the role has changed

Q You've lived through this whole transformation from the inside: the discipline and the job. How would you describe the way the CISO role has changed and evolved?
Ratan Jyoti
"Earlier the era was of data security, which then moved to information security, which further moved to cyber security, and now we are saying this is AI security." That is an era change, not a rebrand. And the function moved along with it. It used to sit inside IT and answer to technology. Today the board asks the CISO to help the bank transform digitally, to drive innovation, to actively enable the business, and to do all of that while managing cyber risk and, for a regulated institution, regulatory risk. So in one line: "We have moved from technology security to business security. That is a sea change."
Takeaway
The CISO's mandate has moved from protecting technology to enabling and protecting the business itself: a change in kind, not just vocabulary.

Why breaches keep happening

Q Here's the objection every CISO hears in the boardroom: we keep investing, and attacks keep landing. When the board asks you why, how do you answer?
Ratan Jyoti
I break a security program into three dependencies. The first is tools, and I'll dismiss the shortage argument outright. "I don't think there is a shortage of tools. For any problem, you have a tool." If anything, the market has tools overload.
The second is visibility, and that's largely solved too, though there's a caveat worth its own episode: how well a diverse toolset actually talks to each other.
The third parameter carries the weight. "Now I have the tools, I have the visibility, but I have a number of problems to be solved. If my risk management does not take care of what needs to be fixed first, it becomes ineffective." That failure (ranking the wrong problem first) causes most breaches today.
Takeaway
Tools and visibility are largely solved. Most breaches now trace back to a third failure: fixing the wrong thing first.

Why known CVEs still get through

Q Let me press on that. Vulnerability scanners have existed for more than twenty-five years, and attackers still walk straight through vulnerabilities those scanners already flagged. Why?
Ratan Jyoti
Look at what a scanner hands you: a CVSS score. Multiple parameters feed that number, but it still collapses into a single dimension describing the flaw in isolation. Business threat refuses to be one-dimensional. It needs asset criticality. It needs business context. It needs threat intelligence. And it needs attack path validation, which tells you whether anyone can actually reach the thing. So "even though we know this vulnerability has existed for ten years, you will still see an exploit today, because they lack the real, multi-dimensional context." Severity supplies one axis. Someone has to supply the rest.
Takeaway
A CVSS score describes a flaw in isolation. Real exposure is multi-dimensional: asset criticality, business context, threat intel, and reachability. Old CVEs still land because that context is missing.

What makes threat intelligence selective

Q You used the word 'selective' about threat intelligence. I want to double-click on that: I can hear an idea underneath it.
Ratan Jyoti
Walk the filter down, layer by layer. Intelligence about a threat hitting a foreign country may never touch India. Inside India, intelligence aimed at one industry may not apply to banking. Inside banking, one bank differs from the next. And inside a single bank, the business model decides what actually matters. "Unless this context is built, threat intel would not be effective." And then I'd turn the question back on the audience: "You are applying thousands of IoCs, but are those IoCs helping you? Are you measuring their effectiveness? If not, perhaps you are doing something wrong."
Takeaway
Threat intelligence only works when it's filtered down to your country, industry, institution, and business model. If you can't measure whether your IoCs change a decision, they're noise.

CTEM as a progression, not a purchase

Q That draws a straight line to Gartner's Continuous Threat Exposure Management framework. How should a team approach the journey from vulnerability management to CTEM?
Ratan Jyoti
I wouldn't frame CTEM as a new category to go buy. It's not an evolving technology so much as a natural progression. The distinction that matters is counting versus understanding. Point-in-time scanners: "they tell you how many weaknesses are there in your system, but they do not tell you how your business is exposed." What changes it is correlating everything in real time (dark web signals, Shodan, industry peers, the regulator) and then layering business context over the result. Do that, and "your visibility increases many, many times."
Takeaway
CTEM isn't a product to purchase: it's the next step after vulnerability management. It replaces 'how many weaknesses' with 'how is my business exposed,' by correlating external signals in real time and layering business context.

What the platform changed at Ujjivan

Q You already run a lot of tools: you've called your cyber defence highly correlated. So what did CTEM actually add on top of that and how did Hive Pro exposure management platform help?
Ratan Jyoti
My team already runs plenty of tools, and our defence system is highly correlated, so the real question is what CTEM added on top. The first benefit is business context, while staying honest about the ceiling: "there is no tool that will give you complete business context." Hive Pro raised the context awareness rather than completing it, and that's the realistic outcome.
The second one I'd call the biggest advantage: deciding which problem to attack first. An analyst staring at hundreds of alerts is overwhelmed, and something has to intervene. "Some tool or system should tell you: no, you attack this first, this can be ignored, this we can attack later."
It's really about decision-making, not just prioritisation. "The analyst is not required to ask which problem I should solve first. He has a natural choice. He will say, this is a threat to my business, this is dangerous to my business, so I will do this first, and others can follow."
Takeaway
The Hive Pro platform's real value at Ujjivan wasn't more data: it was decision-making. It gives the analyst a natural first move instead of a wall of undifferentiated alerts.

Whether it works retrospectively

Q One quick question: is the threat intelligence real time, or after the fact?
Ratan Jyoti
"It is real time. If it is not real time in today's AI era, the cyber security program would not be that effective."
Takeaway
In an AI-era threat landscape, exposure management has to run in real time to be effective at all.

Closing the loop back to selective intelligence

Q Let me come back to that phrase from earlier: selective intelligence. Does the Hive Pro platform actually deliver on it?
Ratan Jyoti
The answer is conditional, and the condition sits with the customer. "If you are able to tell the tool what is your business context, what is your business model, what is your architecture, what are your crown jewels, then this type of tool will help us in knowing what intelligence to rely more upon." The Hive Pro platform amplifies context. It does not invent it. Undefined crown jewels produce undifferentiated intelligence, whatever you deploy.
Takeaway
The Hive Pro platform amplifies the business context you feed it: it can't invent it. Define your crown jewels first, or the intelligence stays generic.

What security leaders should take from the episode

  • Audit prioritisation, not coverage. If ranking causes breaches, coverage metrics measure the wrong thing.

  • Score threat intelligence the way you score vulnerabilities. A feed that never changed a decision costs money and buys noise.

  • Treat CTEM as the next step, not a replacement. It builds on the vulnerability management program you already run.

  • Define the crown jewels first. No platform supplies a business model you haven't articulated.

Watch the Full Episode

Watch the full episode of Fix the Risk for the complete conversation with Ratan Jyoti.

Watch on Fix the Risk

Quotes have been lightly edited from the spoken transcript for readability; wording and meaning are unchanged.

Recent Resources

Dive into our library of resources for expert insights, guides, and in-depth analysis on maximizing Uni5 Xposure’s capabilities

"We Have Moved from Technology Security to Business Security" - Ratan Jyoti, CISO, Ujjivan SFB

Read More

"You Never Crack the Code": Brendon McCaulley, ConnexPay

ConnexPay's Chief Security and AI Enablement Officer, Brendon McCaulley on AI, exposure management, and what the next five years ask of security leaders Interview by Dan Schoenbaum, CMO of HivePro
Read More
Network security operations center with analysts monitoring vulnerability scanning dashboards

Network Vulnerability Assessment: A Step-by-Step Guide

Schedule a network vulnerability assessment for your enterprise. Learn the step-by-step process of scanning, prioritizing, and remediating threats to reduce...
Read More
Digital visualization of SBOM scanning and supply chain security network

SBOM and Supply Chain Security: A Complete Guide

Book a supply chain security demo. Learn how SBOMs and exposure monitoring help DevSecOps teams find and fix third-party risk.
Read More
Cybersecurity dashboard visualizing continuous threat exposure management

Enterprise Ransomware Prevention Through Exposure Management | Hive Pro

Book a demo to see how enterprise ransomware prevention and continuous threat exposure management protect your organization with Arbis AI.
Read More

Mythos brings the exploit window down to zero.

Every vulnerability management program ever built rests on a quiet assumption: that you have time. Time to triage the vulnerability advisory, time to test the patch, time to schedule the maintenance window, time to reboot the system. The entire discipline — patch cycles, remediation SLAs, “shift left” — is a way of rationing that time.
Read More

What’s new on Hive Pro?

Get through updates and upcoming events, and more directly in your inbox