- Home
- More
- Leadership
- R & D
- L & D
- Women Special
- Cover Story
- Blog
- Editor’s Choice
- Interview
- Magazine
- Events
Subscribe to Updates
Get the latest creative news from FooBar about art, design and business.
Inside the Mind of a Cyber Resilience Leader: Vidya Shankaran on AI, Identity, and Rewriting the Rules for Women in Tech
KEY TAKEAWAYS
- AI and cybersecurity are inseparable, making identity protection the foundation of modern cyber resilience strategies.
- Organizations must prioritize critical data, strengthen identity security, and regularly test recovery preparedness against attacks.
- Women thrive in cybersecurity through strategic thinking, while sponsorship accelerates leadership opportunities beyond mentorship alone.
- Successful AI adoption depends on clean, reliable data, clear business outcomes, and continuous talent development through certification.
In a digital world where the line between attacker and defender is increasingly drawn by artificial intelligence, few voices carry the clarity of Vidya Shankaran. As Field CTO at Commvault, she has spent more than two decades moving between the front lines of enterprise technology and the boardrooms where resilience strategy gets decided - a self-described "two-way turnstile" between customers and product teams. For this installment of the UNI Network Group Women in Tech Series, Shankaran sat down with Roopal Mishra to talk about the collapsing distance between AI and cybersecurity, the anatomy of a modern breach, and why sponsorship - not just mentorship - is the missing ingredient in getting more women into tech leadership.
"AI and cyber are no longer discrete from each other. They are deeply intertwined - and together, they are the top priority for every organization I work with."
Q1. You've been in IT for more than 22 years. How did you find your way into cyber resilience?
I started my career as an application developer on AS400 systems, over two decades ago - back when ransomware wasn't even a concept. Trojan viruses existed, but the systems I worked on were never really vulnerable to them. Fast forward to today, and the shift has been massive. What's stood me in good stead through it all is curiosity: constantly trying to understand what the industry actually needs, where the gaps are, and how I can help customers close them.
I think of my role at Commvault as a two-way turnstile. I carry our message out to customers and partners, and I bring their feedback back in to shape our product and engineering roadmap. I get to see both sides of the world - and especially now, with AI moving as fast as it is, that vantage point has never been more interesting.
Q2. What's is the biggest challenge you're seeing organizations face right now?
AI and cyber, together. What started as a cyber problem has been compounded by AI, because access to AI - even in the hands of malicious actors - hands them the same productivity boost defenders are trying to use for good. I no longer talk about AI and cyber as separate issues. They're deeply intertwined, and together they're the top challenge every customer brings to me.
Q3. How has that changed the shape of an actual attack?
Everything has compressed. In the past, hacking required real technical skill and time. AI has collapsed that timeline dramatically. Social engineering has changed just as much - you probably remember the old "Nigerian prince" spam emails, easy to spot because the grammar was off. That's gone. A $20 AI subscription now produces polished, professional-looking phishing emails that are far harder to catch, with a malicious link buried inside. We've even seen attackers simply call a customer support desk and request a password reset.
That's the moment you realize identity is the final parameter. Humans are the first line of defense - if they aren't equipped to question a suspicious link, email, or phone call, everything downstream is at risk.
"Data is the crown jewel. It's the oil an organization depends on. If it can't be protected - or brought back after an attack - the organization ceases to exist."
Q4. Can you walk us through how these incidents typically unfold?
In one environment we worked with, the attacker didn't need sophisticated malware - they simply called customer support and talked their way into a password reset. With no checks and balances in place, they gained access and began moving laterally, quietly elevating their own privileges. From there, they made a critical jump: from a human identity to a non-human identity, or NHI. Once inside as an NHI - the kind of identity an AI agent uses - they had far more unfettered room to move, both laterally and vertically, until they had access to virtually all the organization's data.
That's why guardrails around AI agent identities matter enormously right now. This pattern - identity compromised first, then data, then backup data - is so consistent across industries that it's stopped being surprising. I take best practices from the most-attacked sectors, like healthcare, and cross-pollinate them into manufacturing and other verticals I work with.
Q5. If an organization is hit, what are the three things they need to do immediately?
First: identity is step zero. Protecting how people authenticate into your systems comes before everything else - if you're locked out of your own house, nothing else you've prepared matters. Second, and this has to happen long before an attack: know what's actually critical to your business. Think of it like a house - passports go in a safe, flyers stay on the coffee table. Too many organizations mix the two, treating everything as equally important, which means nothing gets properly protected.
Third: test for recoverability, relentlessly. Practicing recovery can't be a paper exercise - you need to rehearse it the way you'd rehearse an emergency exit from a burning house, bags packed, kids in tow, more than once. As I like to say: it's better to sweat in peace than to bleed at war.
Q6. Cybersecurity remains a male-dominated field. What has that meant for your own career?
I'd be lying if I said I hadn't faced it. Cybersecurity is essentially digital warfare, and historically warfare has been led by men. But what gets overlooked is that women have a natural, healthy sense of paranoia - the instinct to think two or three steps ahead to mitigate risk, whether at home, at work, or on the road. That instinct is exactly what cyber resilience requires. It's not that men lack the skill; it's that women have a natural inclination toward it, and organizations benefit enormously from putting that inclination to work in leadership roles.
Q7. You've spoken about the difference between mentorship and sponsorship. Why does that distinction matter so much?
Mentorship is valuable - having someone to bounce ideas off of, to talk strategy with. But sponsorship is different: a sponsor invests their time, their energy, and their own brand to advocate for you in rooms you're not sitting in. We're good at encouraging women into entry-level roles, but we don't always hand them high-visibility, P&L-owning responsibility - and that's exactly where the real organizational impact happens. Without a clear pathway toward leadership, we lose women five to seven years into their careers. Sponsorship - from men and women alike - has to start from day one.
"Sponsorship is where someone invests their time, their energy, and their brand in speaking about you - in rooms you are not sitting in."
Q8. How are you working to close the skills gap between what companies need and what graduates bring to the table?
We go directly into STEM high schools and evaluate capstone and senior-year projects, and we sponsor hackathons - that's where the real pockets of talent show up, and with AI at their fingertips, today's students are remarkably well-equipped. We also partner with organizations like Girls Who Code to build exposure early. Personally, this is close to home: I have a 17-year-old daughter who came through a STEM high school, and I mentor many of her friends. It's my way of paying forward what this ecosystem gave me - and making sure the next generation of women don't have to learn the hard way what I've already learned.
Commvault also runs a strong internship program for undergraduate and graduate students, which gives them real exposure across every industry we serve - healthcare, manufacturing, financial services, retail, and beyond.
Q9. With so many security tools on the market, what should organizations actually prioritize?
I'd steer away from thinking in terms of tools - they're largely interchangeable, and the outcome is what matters. Think about walking into a pharmacy: you don't care whether it runs on one database or another, one storage vendor or another. You just want a seamless experience. That's the outcome the business has to protect. For a pharmacy, that might mean deciding you cannot tolerate more than a few days of downtime, because that directly means patients don't get their prescriptions filled. Start with the business outcome, then work backward to the people, process, and technology that protect it.
Q10. What does it take for an organization's AI strategy to actually succeed?
It starts with data - not with AI. Good AI use cases sit on top of good data. If your data is messy, siloed, or unreliable, AI won't fix that; it will magnify it and put it on steroids, producing hallucinations and decisions you can't trust. Use-case identification and data readiness are the least glamorous parts of the work, but they're the part that actually determines whether AI delivers value or becomes a liability.
Q11. What would you tell a woman just starting out in cybersecurity?
Get certified - CISSP, CompTIA Security+, or ISC2's Certified in Cybersecurity are all excellent starting points. Certifications aren't just credentials; they're your entry point into a network of similarly certified professionals, and that network is everything in this field. People recommend people they've actually interacted with. Don't wait for opportunities to come to you — go to the events, join the conversations, and use platforms like LinkedIn to showcase your thinking. Visibility and community are what open doors in cybersecurity.
Vidya Shankaran's message is, at its core, a simple one: technology is only ever an enabler. Real resilience - in an organization, and in a career - is built on people, practice, and the willingness to invest in others. For the women navigating a still male-dominated industry, her advice doubles as a blueprint: get certified, get networked, find sponsors, and don't wait to be handed the room - build it.
Editorial Desk
Related Interviews
Share your Details for subscribe