"We Have Moved from Technology Security to Business Security"
A conversation on why known vulnerabilities still persists, what makes threat intelligence selective, and how CTEM changed his team's work queue.
Ratan Jyoti has lived through the various phases of transformation of the cybersecurity discipline. Over the course of the conversation he makes an argument that cuts against most industry consensus: the tools work, the visibility works, and organisations still get breached because they rank the wrong problems first.
What follows is that conversation, lightly edited for readability.
How the role has changed
"Earlier the era was of data security, which then moved to information security, which further moved to cyber security, and now we are saying this is AI security." That is an era change, not a rebrand. And the function moved along with it. It used to sit inside IT and answer to technology. Today the board asks the CISO to help the bank transform digitally, to drive innovation, to actively enable the business, and to do all of that while managing cyber risk and, for a regulated institution, regulatory risk. So in one line: "We have moved from technology security to business security. That is a sea change."
Why breaches keep happening
I break a security program into three dependencies. The first is tools, and I'll dismiss the shortage argument outright. "I don't think there is a shortage of tools. For any problem, you have a tool." If anything, the market has tools overload.
The second is visibility, and that's largely solved too, though there's a caveat worth its own episode: how well a diverse toolset actually talks to each other.
The third parameter carries the weight. "Now I have the tools, I have the visibility, but I have a number of problems to be solved. If my risk management does not take care of what needs to be fixed first, it becomes ineffective." That failure (ranking the wrong problem first) causes most breaches today.
Why known CVEs still get through
Look at what a scanner hands you: a CVSS score. Multiple parameters feed that number, but it still collapses into a single dimension describing the flaw in isolation. Business threat refuses to be one-dimensional. It needs asset criticality. It needs business context. It needs threat intelligence. And it needs attack path validation, which tells you whether anyone can actually reach the thing. So "even though we know this vulnerability has existed for ten years, you will still see an exploit today, because they lack the real, multi-dimensional context." Severity supplies one axis. Someone has to supply the rest.
What makes threat intelligence selective
Walk the filter down, layer by layer. Intelligence about a threat hitting a foreign country may never touch India. Inside India, intelligence aimed at one industry may not apply to banking. Inside banking, one bank differs from the next. And inside a single bank, the business model decides what actually matters. "Unless this context is built, threat intel would not be effective." And then I'd turn the question back on the audience: "You are applying thousands of IoCs, but are those IoCs helping you? Are you measuring their effectiveness? If not, perhaps you are doing something wrong."
CTEM as a progression, not a purchase
I wouldn't frame CTEM as a new category to go buy. It's not an evolving technology so much as a natural progression. The distinction that matters is counting versus understanding. Point-in-time scanners: "they tell you how many weaknesses are there in your system, but they do not tell you how your business is exposed." What changes it is correlating everything in real time (dark web signals, Shodan, industry peers, the regulator) and then layering business context over the result. Do that, and "your visibility increases many, many times."
What the platform changed at Ujjivan
My team already runs plenty of tools, and our defence system is highly correlated, so the real question is what CTEM added on top. The first benefit is business context, while staying honest about the ceiling: "there is no tool that will give you complete business context." Hive Pro raised the context awareness rather than completing it, and that's the realistic outcome.
The second one I'd call the biggest advantage: deciding which problem to attack first. An analyst staring at hundreds of alerts is overwhelmed, and something has to intervene. "Some tool or system should tell you: no, you attack this first, this can be ignored, this we can attack later."
It's really about decision-making, not just prioritisation. "The analyst is not required to ask which problem I should solve first. He has a natural choice. He will say, this is a threat to my business, this is dangerous to my business, so I will do this first, and others can follow."
Whether it works retrospectively
"It is real time. If it is not real time in today's AI era, the cyber security program would not be that effective."
Closing the loop back to selective intelligence
The answer is conditional, and the condition sits with the customer. "If you are able to tell the tool what is your business context, what is your business model, what is your architecture, what are your crown jewels, then this type of tool will help us in knowing what intelligence to rely more upon." The Hive Pro platform amplifies context. It does not invent it. Undefined crown jewels produce undifferentiated intelligence, whatever you deploy.
What security leaders should take from the episode
-
Audit prioritisation, not coverage. If ranking causes breaches, coverage metrics measure the wrong thing.
-
Score threat intelligence the way you score vulnerabilities. A feed that never changed a decision costs money and buys noise.
-
Treat CTEM as the next step, not a replacement. It builds on the vulnerability management program you already run.
-
Define the crown jewels first. No platform supplies a business model you haven't articulated.
Watch the full episode of Fix the Risk for the complete conversation with Ratan Jyoti.
Watch on Fix the RiskQuotes have been lightly edited from the spoken transcript for readability; wording and meaning are unchanged.




