In an era where cyberattacks unfold at machine speed and perimeter defenses are routinely bypassed, traditional models of information security are facing an existential reckoning. The prevailing wisdom that organizations can completely prevent intrusions has been decisively undermined by increasingly sophisticated, AI-driven adversaries.
To explore this paradigm shift, we sat down with Agnidipta Sarkar, Chief Evangelist at ColorTokens and a veteran cybersecurity leader with over three decades of experience spanning cyber defense, risk management, business continuity, privacy, and Zero Trust. Sarkar, who has served as Group CISO at Biocon and held senior risk leadership roles at DXC Technology, Hewlett Packard Enterprise, and HP, offers a masterclass in shifting enterprise security from a posture of elusive prevention to one of absolute, resilient containment.
Executive Overview
The modern threat landscape is defined by velocity, automation, and complexity. As attackers leverage artificial intelligence to compress reconnaissance, vulnerability exploitation, and lateral movement from weeks into mere minutes, conventional incident-response models are buckling under the pressure.
In this environment, Sarkar argues, organizations can no longer afford to treat cybersecurity solely as a technical compliance exercise. Instead, it must be governed as a foundational business and financial imperative. Central to this philosophy is the concept of breach readiness—the operational capability to anticipate, withstand, and evolve through a cyberattack while preserving core business functions.
By marrying advanced microsegmentation with strategic resilience metrics like Maximum Acceptable Material Impact (MAMI) and the Minimum Viable Digital Enterprise (MVDE), ColorTokens and visionary security leaders are rewriting the playbook on enterprise survival. This article examines Sarkar’s three-decade evolution across the frontline of global technology, the mechanics of machine-speed defense, the integration of bounded AI autonomy, and the future of containing both human and non-human identities.
Detailed Chronology: From the Chaos of the ‘Wild West’ to C-Suite Governance
The Formative Years and the First Wake-Up Call
Tracing Sarkar’s journey across three decades reveals a career forged in the crucible of escalating technological complexity. In his early days at HCL and Wipro, cybersecurity felt like the "Wild West"—exciting, chaotic, and brimming with experimentation. Sarkar dove headfirst into firewalls, intrusion detection systems (IDS), multi-factor authentication (MFA), encryption, audits, and governance.
However, the real education came when he watched his first major security incident unfold. Under the immense pressure of an active intrusion, rigid best-practice frameworks crumbled. That initial failure served as an essential wake-up call.
Scaling Chaos at HP and Leading from the Front at Biocon
Later, at Hewlett Packard (HP) and Hewlett Packard Enterprise (HPE), Sarkar received a front-row seat to enterprise-scale chaos. Every subsequent incident underscored a fundamental truth: enterprise IT never stands still, and no amount of capital investment can guarantee absolute safety.
When he eventually took the reins as Group Chief Information Security Officer (CISO) at Biocon, Sarkar understood that his primary mandate was not to maintain an illusion of impenetrability, but to build a repeatable, predictable playbook capable of keeping the business operational amid a storm. On paper, security tools often appeared pristine; in reality, IT Service Management (ITSM)—encompassing asset management, patching, configuration changes, and risk—was inextricably tangled with human error.
"There is no script for the war room when a breach hits. Chaos is the rule, not the exception," Sarkar reflects. "That is why I have spent my career building structure in the eye of the storm and helping leaders cut through the noise and manage risk, rather than getting swept away by it."
The Philosophy of Koun Ryusui
Drawing upon these decades of frontline experience, Sarkar formulated a comprehensive breach readiness framework. Inspired by the philosophy of Koun Ryusui—drifting like clouds, flowing like water—this framework guides enterprises to move dynamically with the storm rather than fighting it rigidly. When unprecedented attacks strike, organizations must exercise structured flexibility, transforming their technology investments into engines of operational resilience.
Supporting Context & Metrics: Redefining Enterprise Survivability
The Economics of Catastrophic Disruption
Cyberattacks do not merely compromise internal systems; they cascade across supply chains and disrupt human lives. Whether it is patients turned away from a hospital, travelers stranded at a major airport, or automotive dealerships left financially paralyzed, the true cost of an incident is measured in business disruption and eroded trust.
To navigate this financial reality, Sarkar advocates for two critical metrics that every board of directors must track quarterly:
- Maximum Acceptable Material Impact (MAMI): The quantum of material loss or disruption that the board is willing to accept in pursuit of digital and AI initiatives. This metric sets the baseline for operational survivability.
- Minimum Viable Digital Enterprise (MVDE): The exact percentage of the digital enterprise that must remain operational even during a severe cyberattack.
While traditional business continuity plans often leave up to 60% of an enterprise exposed, setting an MVDE target (such as 70% or higher) forces organizations to architect their defenses to sustain core operations through an active breach.
Calculating and Controlling the "Blast Radius"
The term "blast radius" has become a vital metric for cyber resilience, but understanding its scope requires precision. Sarkar recommends conducting a Breach Readiness Impact Assessment (BRIA)—a non-intrusive, API-driven dipstick analysis leveraging existing Endpoint Detection and Response (EDR) platforms—to evaluate current risk exposure.
However, blast radius cannot be viewed in isolation. A cache service speeding up an e-commerce platform inherently requires wide system-to-system connectivity. The vulnerability arises when unauthorized users or compromised workloads exploit those pathways. Consequently, blast radius must be correlated with behavioral anomalies, access misuse, privilege creep, and authentication failures.
Official Statements & Industry Evolution
The ColorTokens Approach: Microsegmentation Meets Machine-Speed AI
Founded on the principles of Zero Trust and microsegmentation, ColorTokens focuses on helping enterprises survive when traditional perimeter defenses fail. Its flagship Xshield Enterprise Microsegmentation Platform creates granular security boundaries around workloads and data centers, cloud infrastructure, Kubernetes environments, operational technology (OT), and Internet of Things (IoT) devices.
By deploying AI-assisted workflows for environment discovery, policy creation, and deployment acceleration, ColorTokens limits the lateral movement of malware and attackers, shrinking the potential blast radius of any intrusion.
Bounded Autonomy: Trusting AI Responsibly
As artificial intelligence accelerates reconnaissance and exploitation, defenders must similarly deploy AI to maintain pace. However, Sarkar issues a clear warning regarding autonomous execution:
"The objective isn’t to make AI autonomous. It is to make defensive autonomy bounded."
At ColorTokens, AI is utilized for discovery, correlation, dependency mapping, attack-path analysis, blast-radius calculation, and policy synthesis. Yet, critical determinations—such as business criticality, safety boundaries in OT, crown-jewel definitions, and irreversible containment actions—remain firmly under human oversight. AI proposes actions, waits for explicit human sign-off, and then enforces changes at machine speed within strict architectural guardrails.
The Practical Evolution of Microsegmentation
Historically hampered by complex deployments, rigid firewall rules, and heavy operational overhead, microsegmentation has undergone a technological renaissance.
- Identity as the Perimter: In modern cloud environments, IP addresses are largely irrelevant. Modern microsegmentation follows identity, access, and workload context rather than static network infrastructure.
- Agentless Protection: Advanced platforms now extend protection to legacy systems, IoT devices, and OT environments that cannot support traditional agents, integrating seamlessly with existing EDR telemetry.
- AI-Assisted Policy Engineering: Artificial intelligence removes the primary bottleneck of manual policy creation, simulating and synthesizing rules before enforcement.
Future Outlook: Managing Non-Human Identities and Autonomous Agents
Looking toward the immediate future, the greatest challenge facing enterprise security will not originate from compromised human accounts alone, but from the proliferation of autonomous AI agents.
As organizations deploy agents with live access to applications, data, credentials, and infrastructure—projected to outnumber human identities by a factor of 250—breach readiness must expand to cover this high-velocity class of non-human identity (NHI). Vulnerable to prompt injection, tool poisoning, and behavioral drift, autonomous agents can cascade compromises faster than human-paced responses can track.
To counter this, breach readiness must evolve from asking “Can we recover after encryption?” to “Can we contain an autonomous actor operating with valid credentials before damage cascades?” By treating agent trust as an extension of Zero Trust, implementing runtime behavioral baselining, and leveraging AI-driven microsegmentation for automated containment, enterprises can preserve operational continuity.
Conclusion
As Agnidipta Sarkar demonstrates, the future of cybersecurity belongs not to those who chase the illusion of total prevention, but to those who master the art of breach readiness. By combining the fluidity of Koun Ryusui, the architectural precision of microsegmentation, and the disciplined governance of bounded AI, organizations can withstand the storm of modern cyber threats and emerge stronger, more resilient, and fully operational.
