Visualização de leitura

Cyble and DRONA Launch New Push to Close India’s Cybersecurity Gap

Cyber Yodha Campaign

AHMEDABAD (INDIA) — Cyble, the global AI-native cybersecurity company, and DRONA Cyber Solutions, the Ahmedabad-headquartered security operations firm, have launched an AI-powered cyber defense initiative in Ahmedabad, combining threat intelligence, investigation and endpoint enforcement through a joint managed security model.

The AI-Powered Intelligence for Cyber Defense initiative was formally launched Tuesday at DRONA Cyber Solutions' Command and Control Centre, where the companies presented a live technical demonstration showing how an intrusion attempt can be detected, investigated and contained.

The launch comes as India faces a growing cybercrime burden. India recorded 28.15 lakh cybercrime cases in 2025, a 24 percent increase over the previous year, with reported losses reaching ₹22,495 crore. The government's 1930 cybercrime helpline received 32.4 million calls during the year. Of the complaints filed, 55,484 were converted into FIRs. AI-powered cyber defense While large enterprises and banks increasingly have dedicated security teams, budgets and incident response capabilities, many manufacturers, hospital chains, schools and mid-sized businesses, particularly across Tier-2 and Tier-3 cities, continue to operate without comparable security resources.

AI-Powered Cyber Defense Takes Center Stage in Ahmedabad

Rather than focusing solely on formal remarks, Cyble and DRONA used the launch to demonstrate the initiative through a live technical exercise for the media. The demonstration began with material recovered from infostealer logs circulating on a criminal forum, alongside a lookalike domain registered to impersonate a target organisation. Analysts traced the infrastructure, established a pattern of previous activity associated with the same actor and demonstrated the detection and containment of an intrusion attempt on an endpoint.

The final containment action was authorised by a human analyst rather than executed automatically. The demonstration brought together multiple capabilities. Cyble Vision provided the initial detection through continuous monitoring of criminal marketplaces and leak sites.

Cyble Hawk supported the investigative process and attribution, while Cyble Titan handled endpoint enforcement, using hardware-level integrity checks to support its assessment. DRONA analysts remained at the centre of the process, making decisions that the system was deliberately not permitted to make independently. Cybersecurity Collaboration Mandar Patil, Executive Vice President at Cyble, said the initiative was designed to address a longstanding gap between threat detection and action for mid-sized businesses.
"India is not short of alerts. It is short of what happens next," Patil said. "We have spent a long time in this industry watching mid-sized businesses get told about a threat and then having nowhere to take that information. What we are launching today is not another alert. It is a complete chain — intelligence before the attack, investigation that would stand up to scrutiny, enforcement on the device, and a person accountable for the decision at the end of it."
Dhruv Pandit, Co-Founder and CEO of DRONA Cyber Solutions, said the initiative reflects the operational needs of organisations that require immediate action rather than another security dashboard.
"A factory owner calling us at two in the morning does not want to be shown a dashboard," Pandit said. "He wants to know what happened, he wants it contained, and he wants someone to take responsibility for what happens next."

From the Command Centre to Gujarat University, India

The Gujarat University engagement was not simply a conventional cybersecurity student session. It was a technical session titled “Kavach: Beyond the Surface — Threat Intelligence from the Dark Web Depths,” hosted by the Department of Biochemistry and Forensic Science, Gujarat University, in collaboration with Cyble.

The session brought together speakers from Cyble and DRONA Cyber Solutions to examine areas including dark web threat intelligence, government and PSU cybersecurity projects, digital forensics and incident response (DFIR), and the transition of threat intelligence from information to action.

Mandar Patil and Augustin Kurian of Cyble discussed the dark web threat intelligence landscape. Prathmesh Pawar spoke about government and PSU cybersecurity projects, while Brijesh Kapadiya addressed DFIR and Vijay Mali discussed moving threat intelligence from information to action. The keynote was delivered by Prof. Dr. Kapil Kumar, Coordinator, Department of Biochemistry and Forensic Science. AI-powered cyber defense

The session highlighted several practical aspects of cybersecurity work. The dark web was discussed not simply as a hidden part of the internet, but as a structured ecosystem requiring dedicated intelligence-gathering and threat-discovery methods. DFIR was presented as an area where speed and process are as important as technical expertise.

Another key takeaway was the importance of turning threat intelligence into action. Rather than treating intelligence as information alone, the session focused on how it can inform practical security decisions.

Patil told students that the cybersecurity industry faces a shortage of professionals with practical skills in analysing and validating threat intelligence.
"The gap this industry has is not a gap of ideas. It is a gap of people who know how to do the work," Patil said. "What separates a useful analyst from an alert-reader is the ability to ask whether a piece of intelligence is actually true before you act on it."
Augustin Kurian, Editor-in-Chief of The Cyber Express, told students that threat intelligence and journalism share an emphasis on verification.
Every story we publish about a breach, a ransomware group or a leaked database starts exactly where today's demonstration started — with intelligence somebody had to go and find, verify, and decide was worth acting on," Kurian said. The instinct we have tried to build at The Cyber Express is the same instinct a good analyst needs: do not report, and do not act on, what you have not verified.
The programme also involved technical and production teams supporting the session. Screen, sound and lighting were handled by the technical team under the guidance and supervision of Aditya More, while Misha Alagiya, Kavya Maharaja, Pathak Ami, Omi and Nandini supported stage management and photography.

A Broader Cybersecurity Collaboration

Both companies emphasised that the partnership is not intended to represent a single solution to India's cybersecurity deficit. Cyble and DRONA maintain relationships with other partners, service providers and government bodies.
"India's exposure is too large for any single partnership to take credit for solving," Patil said. "What matters is whether more of these collaborations exist a year from now, and whether the businesses we are talking about today — the ones without a security team — actually have somewhere to turn."

The AI-Powered Intelligence for Cyber Defense initiative will be delivered through DRONA's Ahmedabad command centre, with the companies indicating an intent to extend the service model to customers elsewhere in India over time.

The initiative also folds into DRONA's existing Cyber Yodha Campaign, a national programme aimed at building 50 integrated cybersecurity command centre labs and training more than 100,000 defenders.

FTC Sues Hims & Hers Over Health Data Privacy, Billing Practices

Hims & Hers lawsuit

The Hims & Hers lawsuit has put the telehealth provider under scrutiny after the FTC, along with Utah and California authorities, accused the company of deceptive billing practices and unlawfully sharing consumers' sensitive health information with third-party advertising platforms. According to a complaint filed in federal court, regulators allege that Hims & Hers misled consumers about its privacy protections, enrolled users in recurring subscriptions without clear disclosure, and shared health-related data with companies including Meta and Snap.

The complaint alleges that the San Francisco-based telehealth provider failed to clearly inform consumers that prescription charges could be processed almost immediately after they submitted an online intake form, despite representing that they would first consult with a medical provider to determine an appropriate treatment.

FTC Complaint Alleges Deceptive Billing Practices

According to the FTC complaint, consumers interested in Hims & Hers services are required to complete an online intake form for review by a medical provider before receiving prescription treatment. During this process, users provide billing information after being assured they would not be charged unless medication was prescribed.

However, regulators allege that most consumers were not given a consultation with a provider before being charged. Instead, the complaint states that submitting the intake form automatically enrolled many users in recurring prescription subscriptions and processed charges before consumers had an opportunity to review or approve the treatment.

The complaint also alleges that Hims & Hers did not clearly disclose when prescription refills would occur, making it difficult for consumers to cancel subscriptions before the next billing cycle.

One consumer complaint cited by the FTC stated that they were told they would speak with a doctor within a few days and would not be charged immediately, but their payment was processed before any consultation took place.

Hims & Hers Lawsuit: Privacy Practices Under Investigation

The Hims & Hers lawsuit also centers on allegations involving health data privacy.

According to the complaint, Hims & Hers shared consumers' sensitive health information with advertising platforms such as Meta and Snap, despite assuring users that their medical information would remain private.

The FTC alleges that the company shared customer lists with advertising platforms and also used third-party tracking technologies that automatically transmitted website activity, referred to as "Events," to those companies.

Regulators argue that these practices exposed health-related information while contradicting the company's privacy representations to consumers.

Subscription Cancellation Process Questioned

The complaint further alleges that Hims & Hers created obstacles for consumers attempting to cancel recurring subscriptions.

Before 2023, most users could only cancel by contacting customer service through phone, email, or chat. Even after introducing online cancellation, regulators allege the company continued to make the process difficult by hiding the cancellation option behind multiple navigation steps. According to the complaint, consumers first had to select "add/remove items from order" before eventually reaching the cancellation page.

The FTC alleges these practices violate both the FTC Act and the Restore Online Shoppers' Confidence Act, which governs deceptive billing and subscription practices. Utah and California have also alleged violations under their respective consumer protection laws.

Hims & Hers Rejects Allegations

In a statement posted on X, Hims & Hers rejected the allegations and said the lawsuit ignores evidence provided during the FTC's nearly three-year investigation.

The company described the action as an attempt to generate headlines rather than enforce consumer protection laws and said it intends to defend itself in court vigorously.

Hims & Hers also stated that millions of consumers have relied on its services since 2017 and that its Privacy Policy explains how customer data is used. The company added that patients can choose how their information is handled and maintained that information shared with healthcare providers is used only to deliver care.

The lawsuit was authorized by a 2-0 vote of the Commission and filed in the U.S. District Court for the Northern District of California. The allegations remain claims made by regulators, and the court will ultimately decide the case.

Sunil Varkey Joins Hexaware Technologies as EVP & CISO

Sunil Varkey

Sunil Varkey has been appointed as Executive Vice President (EVP) and Chief Information Security Officer (CISO) at Hexaware Technologies, where he will lead the company's information security strategy, governance, risk management, and enterprise resilience initiatives. The appointment marks the latest leadership role for the cybersecurity veteran, who brings more than three decades of experience across global enterprises and multiple industry sectors. Based in Chennai, India, and operating in a hybrid work model, Varkey will be responsible for strengthening enterprise cybersecurity governance, risk management frameworks, and overall security strategy at Hexaware Technologies. His appointment was announced in June 2026.

Sunil Varkey to Lead Cybersecurity Strategy at Hexaware Technologies

In his new role, Sunil Varkey will oversee key areas including information security governance, enterprise risk management, and resilience initiatives. His responsibilities align with Hexaware Technologies' broader technology and growth objectives as the company continues to support large-scale digital transformation programs for clients worldwide. Hexaware Technologies delivers technology-led services across application development, cloud services, automation, data analytics, and enterprise IT operations. The company serves organizations across multiple industries and supports digital modernization initiatives at scale. Varkey's appointment comes as organizations continue to focus on strengthening cybersecurity programs and managing digital risks across increasingly complex technology environments.

More Than 30 Years of Cybersecurity Leadership Experience

Varkey brings over 30 years of experience in cybersecurity leadership spanning banking, telecommunications, IT services, manufacturing, and enterprise technology sectors. His professional experience extends across India, the Middle East, and the United States. His areas of expertise include cybersecurity governance, risk and compliance (GRC), security architecture, incident response, DevSecOps, cloud security, privacy management, cyber defense, business continuity management, security operations, and AI security. Prior to joining Hexaware Technologies, Varkey served as Cyber Security Consultant and Advisor at TAHAKOM in Riyadh, Saudi Arabia, from June 2023 to March 2025. In that role, he worked alongside the organization's CISO to enhance cybersecurity resilience and strengthen security posture. Before TAHAKOM, he held the position of Vice President and Chief Technology Officer for EMEA and APJ at Forescout Technologies Inc. between April 2021 and November 2022. Based in Dubai, he focused on IT/OT security strategy, enterprise cybersecurity advisory services, and product positioning across global markets.

Leadership Roles Across Global Organizations

Between March 2020 and January 2021, Varkey served as Managing Director and Global Head of Cyber Security Assessments and Testing at HSBC in Hyderabad. He led a team of approximately 300 professionals responsible for penetration testing, threat modeling, vulnerability management, and third-party security risk assessments. Earlier, from December 2018 to February 2020, he worked as CTO and Security Strategist for the Middle East, Africa, and Eastern Europe region at Symantec. His responsibilities included developing cybersecurity strategies for enterprise, government, industrial, and financial sector organizations. His career also includes senior leadership positions such as Global CISO at Wipro, CISO for Security and Privacy at Idea Cellular, and Vice President of Security Engineering at Barclays. Additionally, he held global security leadership roles at GE Capital, Genpact, Paramount Computer Systems, and other multinational organizations.

Focus on Governance, Risk Management, and Enterprise Resilience

Throughout his career, Varkey has overseen cybersecurity functions covering governance, compliance, strategy, security engineering, incident response, privacy, cloud security, cyber defense, and enterprise resilience. His experience includes leading security programs for organizations with large-scale user bases and complex operational environments. At Wipro, he served as Global CISO for a technology company supporting more than 200,000 end users. At Idea Cellular, he led security and privacy initiatives for a telecom operator with approximately 120 million subscribers. With his appointment, Hexaware Technologies adds a cybersecurity leader with extensive experience in building and scaling security programs across global enterprises. The move underscores the company's continued focus on strengthening cybersecurity operations, governance frameworks, and digital risk management capabilities as part of its ongoing technology initiatives.
❌