Rapid technological acceleration and shifting regulatory landscapes warrant robust governance, risk management, and workforce readiness, skill development, essential to build national cyber resilience. Anwesh Koley of ELE Times had an exclusive interaction with key leadership from ISACA, who shared strategic perspectives on India’s evolving cybersecurity posture, the impact of legislative initiatives and the pressing need to bridge the domain’s skills gap.
ELE Times: At the onset, could you brief us on what is currently happening at ISACA regarding cybersecurity, governance, risk, compliance, and related fields?
Team ISACA: This is a pivotal moment for cybersecurity in India. Over the last five years, the government has made multiple moves indicating a clear focus on increasing national cyber posture and resilience.
Crucial legislation like the Digital Personal Data Protection (DPDP) Act has been pivotal. Furthermore, traditional regulators such as the Reserve Bank of India (RBI) and the Securities and Exchange Board of India (SEBI)—particularly within financial services—have consistently remained at the forefront of cybersecurity enforcement. Across sectors, there is expanding interest in skill development, awareness, and building a deeper appreciation of what constitutes a robust cybersecurity program.
However, the ecosystem remains fragmented. A wide spectrum of policymakers and regulators operate with varying levels of understanding regarding how cyber risks impact their specific sectors. While entities like CERT-In and the National Cyber Security Coordinator serve as positive signals, the lack of a single, unifying national body to tie these initiatives together leads to disparate, localised pockets of progress rather than a fully unified national strategy.
On artificial intelligence, the implementation across sectors is similarly experiencing fragmented approaches. While there is currently no plan to introduce national AI legislation in India—keeping the focus intentionally on fostering innovation—the rapid pace of AI adoption makes AI security and enterprise governance frameworks critical.
Finally, addressing the skills gap remains essential. Building a well-qualified workforce requires continuous, innovative development initiatives to establish standard capabilities across all domains.
ELE Times: You raised the important issue of skill development. What specific avenues is ISACA focusing on, and where does India feature in your strategic plans regarding quality skill development?
Team ISACA: India is a critical jurisdiction for ISACA, and our organisation is making significant strategic investments here. India represents our largest concentration of staff outside North America. Beyond building local cybersecurity postures and AI capabilities, India aims to leverage cybersecurity and AI as economic growth levers to position itself as a regional technology leader. We actively support this vision alongside our local network of 10,000 members organised across 12 chapters.
There is an important opportunity for India to make the cybersecurity sector a national economic success story, mirroring its historical success in the software and IT services industry.
Skill development extends beyond pure-play cybersecurity specialists; there is surging demand for cybersecurity expertise in adjacent corporate roles—including procurement, legal, project management, and executive board governance. Beyond specialised operational roles, building a robust national talent pool enables the creation and export of domestic cybersecurity products and services.
To support these goals, ISACA delivers a multi-pronged approach:
- Extensive Credential Portfolio: Offering structured pathways from foundational competencies through to specialist credentials, including new certifications designed as entry points into cybersecurity careers.
- Enterprise Governance & Benchmarking Frameworks: Providing frameworks (such as COBIT) that allow enterprises to review, assess, and benchmark their maturity in adopting AI, IT controls, IT audit assurance, and governance.
- Continuous Learning & Local Framework Alignment: Moving away from static, one-time certifications toward mandatory, continuous professional education (CPE). Additionally, our credentials and workforce frameworks adapt to local regulatory requirements to ensure seamless regional implementation.
ELE Times: How do you assess the current Indian workforce and its preparedness toward accepting cybersecurity norms and building long-term careers in this domain across various industry verticals?
Team ISACA: Workforce preparedness varies across sectors. Industries like financial services have made substantial investments, and critical infrastructure sectors are actively advancing their capabilities. However, operational challenges remain, particularly within public sector capacity and municipal-level infrastructure where personnel manage multiple operational responsibilities.
A central challenge is the sheer speed at which the field evolves. Rather than replacing cybersecurity roles, technologies like AI are reshaping job requirements rapidly. Cybersecurity professionals must continually adapt to keep pace with emerging technology stacks.
Additionally, growth is accelerating in intersecting domains like risk management and regulatory compliance. Navigating this environment demands an agile mindset and a commitment to continuous learning to stay ahead of evolving threats and technological shifts.
ELE Times: Expanding beyond India, how do you see the broader South Asian and regional markets performing in terms of cybersecurity readiness and willingness to adopt scaling frameworks?
Team ISACA: India acts as a primary technology and policy leader across South Asia. While smaller regional jurisdictions can sometimes move faster due to scale, there is a widespread recognition across South Asia that robust cybersecurity adoption is mandatory to participate effectively in the global digital economy.
Beyond South Asia, regions like the Middle East—Saudi Arabia in particular—are moving rapidly to establish strong national cybersecurity profiles. India holds a strong position to offer thought leadership and drive regional dialogue across these markets.
Regarding the willingness to adopt cyber norms and frameworks across the region, industry resistance is rarely the barrier. Instead, organisations face challenges around regulatory proliferation and a lack of harmonisation.
When enterprise teams must navigate overlapping, unaligned compliance requirements from multiple authorities, compliance becomes burdensome. Diverting technical staff and financial resources purely toward administrative compliance exercises can take focus away from vital operational security tasks—such as active risk management, system patching, and continuous monitoring.
The industry is receptive to regulation, standards, and guidance. However, the priority must be regulatory coherence and harmonisation so that compliance directly drives meaningful improvements in an organisation’s overall security posture.

