transcribe

Black Hat India CISO Circle Series Ep. 1- Supply Chain Risk Management- Prajal Kulkarni, CISO, Groww

Black Hat India · 21m · transcribed Aug 2026
More from Black Hat India Business
𝕏 Share ▶ YouTube 📥 PDF 🤖 .md

Section Insights

# 0:00

Introduction to Black Hat India and Guest Background

What is Black Hat India and who is the guest?

Black Hat India is a cybersecurity event taking place in Bangalore, featuring discussions on current threats and industry gaps. The guest, Prajal Kulkarni, is the CISO at Grow, with a background in offensive security and leadership roles.

  • Black Hat India aims to address pressing cybersecurity issues.
  • Prajal Kulkarni has extensive experience in security, transitioning from technical roles to leadership.
  • The event will feature top minds in cybersecurity discussing critical topics.
# 4:14

Challenges in Vendor and Supply Chain Security

What are the main challenges in vendor and supply chain security?

Vendor and supply chain security is a significant challenge due to the difficulty in controlling third-party ecosystems. Organizations must focus on uplifting their critical vendors to enhance overall security.

  • Vendor security is a top concern for cybersecurity professionals.
  • Organizations often lack control over third-party security measures.
  • Identifying and tiering critical vendors is essential for effective security management.
# 8:28

The Importance of Continuous Security Assessments

How can organizations ensure their vendors are secure?

Organizations should conduct continuous security assessments and collaborate closely with vendors rather than relying solely on reports. This includes understanding data management and security practices within the vendor's ecosystem.

  • Continuous assessments are crucial for maintaining vendor security.
  • Collaboration with vendors enhances security beyond mere compliance.
  • Understanding the vendor's security practices is vital for data protection.
# 12:42

Addressing Shadow AI in Vendor Risk Management

How should organizations handle the challenges posed by Shadow AI?

Organizations need to ensure transparency from vendors regarding their AI usage and incorporate AI-related assessments into their vendor risk management processes to address potential blind spots.

  • Transparency from vendors about AI usage is essential.
  • Vendor risk management should include AI considerations.
  • Legal compliance regarding data retention is becoming increasingly important.
# 16:56

The Role of Education in Cybersecurity

What role should educational institutions play in cybersecurity?

Educational institutions should focus on developing cybersecurity curricula to prepare the next generation of security engineers. Involving students in events like Black Hat India can enhance their learning and professional growth.

  • Universities need to integrate cybersecurity into their curricula.
  • Student participation in cybersecurity events fosters community growth.
  • Bridging the gap between technical skills and organizational culture is crucial for security.

Transcript

0:10 Black Hat is coming to India this October. And the first edition of Black Hat India will be held at Bangalore. In the lead up to the event, we are inviting some of the top minds in cybersecurity to come and have a discussion with us about what is really happening on the ground. The threats, the gaps, and the conversations the industry needs to have. Welcome to the Black Hat India podcast. And today's guest is Prajal Kulkarni, CISO at Grow, India's largest retail stock broker with over 80 million registered users and more than 12 million active trades.

0:45 That's a platform where security is critical because it touches people's savings, their investments, their financial futures. Prajal came up through the offensive security world with experience in penetration testing, vulnerability assessment, web application security before moving into leadership roles at Flipkart and Cleartrip, and eventually into the CISO seat at Grow in 2023. Hello Prajal, and welcome to our cyber leaders podcast series. I would like to begin by diving a little bit into your professional journey.

1:15 You started in offensive security, pen testing, vulnerability assessment. Most people who go to that route stay technical. What made you want to cross over into security leadership? >> First of all, Ayush, thank you so much for having me here. >> You're welcome. >> Thank you Black Hat India as well to come to India and start this summit. to your question, you know, starting technical, going very deep into something which I love. I think all of us started somewhere, and most of us were pure technical folks, right? Picking up a subject, trying to master that, being SMEs in that. I also started something on the same lines. It was security for me.

1:57 tried putting my hands in pretty much all areas of security to gather as much as hands-on hands-on experience as possible. But at some point of time you realize that if you really need to make a lot of game-changing security strategic bits in a in a company, you need that leadership shift. And it happened for me quite organically. It was at some point of my career that I saw that this was needed, and that was a trigger where I thought let's let's do this jump and see if I can make a difference.

2:33 >> Account takeover is one of the most common and damaging attacks on investment platforms. Someone loses access to their account and an adversary has access to their entire portfolio. So, what is the defensive stack for that scenario, and where are the weak points? >> Yeah. account takeovers are unfortunately one of the most, you know, abused security threats today. And it is relevant because a lot of our products that we release in the market has convenience baked into it. Like how people log into that application, we want to make it as seamless user experience-wise as possible. And because of that, this is this is an outcome.

3:14 Account takeover is an outcome of it. The way I look at it, Ayush, is like, you know, you have to build a balance of reactive and proactive security to take care of it. A lot of legacy applications, it's it's a journey for them to reach a proactive state. But a newer area application, it is much more easier to start baking those security protocols very early in the game. For example, you can have, say, just a mobile number OTP like login to your application. Top it up with something like a device binding, or top it up with something like a, you know, MFA on top of it, or maybe a personalized PIN. In the most of the UPI apps, you will see an MPIN part of it, right? So, this kind of reinforces security, proactive security for the way people log in and see that experience and log in to an application.

4:06 if everything goes bad even after that, then your reactive controls come in where you kind of build a pipeline of detection very seamlessly and then freeze that account the moment you detect something out of the dark web, right? So, I kind of feel a balance is much more easier approach to go about account security. >> So, vendors usually outsource to other vendors. >> Yeah. >> Consultants, contractors, since every vendor is a possible vector, how do you audit with your end supplier in the chain to ensure that they are not an entry point for an attack on your corporate network and IT infrastructure?

4:44 >> supply chain and vendor security haunts me every time I, you know, think about it. It's been 16 years for me in the industry and it is one of the most difficult problems to solve. According to me, if you ask me like the top three security problems to solve, vendor and supply chain security is one of the top on my list. The reason being is because that you you do everything to secure your own ecosystem and your own home, but the moment some of it goes to a third-party ecosystem, that becomes difficult for you to control because that's you don't have any say there, right? The moment your data is shifted out of your home to somewhere else, it's not in your control. It's gone, right? The only thing that you can do is maybe uplift your vendors in getting their security right.

5:37 So, honestly, I I used to say not about auditing the nth vendor. >> Okay. >> It's about making sure you know your critical vendors in the ecosystem >> Okay. >> and you tear them. You have tier one vendors where you share the most critical data >> Got it. >> from your house to you know and I call them your extended family. >> Got it. >> These vendors are like as critical as how you take care of your security within the ecosystem.

6:05 >> Right. >> And if you are able to do a better job in uplifting and upgrading their security it is going to be taking care of a lot of your vendor security problems. And today we've tried a lot of it with regulations. We've tried a lot of it with what we know of how vendor risk assessment works and we are still long way. We are still long way >> Got it. So, what frameworks do you recommend to help uplift a vendor security and how often should you do maybe a security audit or a risk assessment for them?

6:42 >> Yeah. See again to my philosophy of getting your tiering of vendors right going after the T1 vendors and upgrading their security you kind of build a relation with them over time. Right? Some of them will be very collaborative. Some of them will be resisting. >> Okay. >> There are frameworks. There are there are CISA frameworks. There are NIST frameworks. There are auditing frameworks. But, it's just on paper at the moment. All right? That's how I look at it. That's That's how it's been my experience.

7:15 You can take like a SOC 2 report. You You can take like an ISO 27000 report. But, honestly that's security theater for me. >> Okay. >> there's there's there's security engineering and just like you know security theater which has their own faces. And for me real security comes in only when you kind of know your T1 vendors, you collaborate with them, you really understand. In in my previous gigs when I used to take care of like a lot of vendor management security risks, I used to work with them. I used to ask them questions around what is the security team that you have today? Can you introduce me to them, right? Or let me talk to them. I used to get on calls with them. I used to understand how they think about security. Because we are open to do business with you, but are you open to upgrade your security for us, right? That was the conversation tone that we used to use. And a lot of time we used to realize that the more you talk to them, you can influence better in how they do security in their ecosystem. And this is so that is my philosophy around >> Do you also maybe recommend red teaming or like actively doing continuous pen testing for the vendors itself?

8:32 >> Yeah, it is recommended. But again, some of them will say we will do it. they will give you a reports from VPT vendors, but again, it's just on paper. It's security theater for me. It's more like how you collaborate with them and then sometimes even we used to do security assessments for them. Like my team used to do red teaming. My my team used to do pen testing. again, all with NDA signing. And that used to kind of help. It will used to understand where our data lies, how the sanitization is there, what kind of encryption protocols they are using, what kind of overall processes they have within their security team, right? So, it was more like an extended team from security and you kind of flow your philosophical security principles to that team. So, seamless like that then just taking reports from them and saying, you know, we are secure.

9:26 >> Got it. So, 95% of organizations increase their TPRM budgets in 2025, but only 97 but still 97% still got breached through their supply chain. So where do you see the problem? >> Again, the problem is not about finding one bad vendor in your ecosystem. >> Okay. >> The problem lies in not knowing the vendor ecosystem. >> Got it. >> Although you fund with like 97% of your TPRM budgets, you will only try and see I I remember back in the day we used to have you know security programs where you used to have like a small TPRM as a task. That task was basically you do a vendor risk assessment, you take reports from the vendor, you ask bunch of questions on that and most of them will be green.

10:22 >> Okay. >> The vendors will be sharing you their VPA reports where they're like super clean. The TPRM questions will be like you know they are complying to every every protocol. >> Okay. >> Again, there will be a breach, right? >> Yeah. >> So it's not about increasing the vendor coverage, it's about getting your inventory of your vendors right. >> Got it. >> It is having gating at the right processes within your procurement and your legal pipelines where you know that every vendor that goes for any sort of procurement, there is a security gate to it. You take approvals and then you go there, right? That way you're solving one thing. Your inventory is foolproof and your tearing layer kind of kicks in where you can tear your vendors saying these are my T1 vendors and this is my extended family. And I will take care of it the same way I take care of my security at home.

11:14 >> Right. >> So that's that's how I >> Got it. So know the vendor landscape well, know how to tier them and know your inventory basically. >> Exactly. >> Okay, great. How do you deal with this issue of vendor or tools sprawl especially when different tools do not share intelligence? >> Yeah. So I used to have this problem about having 100 tools or, you know, different vendors in the ecosystem. the way I used to deal with it is like a lot of tools have now come across like a consolidation view, right?

11:48 One way to look at it is you have a cut down of your tool budget and look at only the class tool vendors who can solve say three problems, but two of them they have solved very very beautifully and let one problem will organically solved over course of time. So, that way you have a way to consolidate the vendor tool ecosystem and you deal with only a smaller subset. Right? So, tool sprawling there is going to be controlled.

12:18 >> Okay. >> a lot of vendors kind of deal with data that they don't tell you that they deal with. >> Okay. >> But then in the back end they take your data and then they massage and crunch on that data. That is another aspect that you have to have very much transparency with your business and the business has to be very vocal about it with the vendor that you have to have legal documents to cover all of this.

12:47 And if they are there is transparency there, I think security also kind of overlays and comes across. >> Got it. Okay. Now, coming to Shadow AI. So, Shadow AI is becoming a new challenge for our TPRM. So, most TPRM programs do not even consider end party AI use in their assessments. >> Yeah. >> And many times even the vendor is not aware of how the AI is using the data, where it is going. So, how should an organization handle this new blind spot?

13:14 >> Yeah. One is transparency. Again, going back to the previous question. if the vendor is eager to do business with the company, he should be transparent about what kind of AI roadmap he has, right? A lot of tools will end up doing it. AI will be part of their roadmap. They will have some sort of a feature to have productivity gains, insight view, all of that. But then they should be more proactive about that this is something is part of their roadmap and transparently they should disclose it in their documents. Similarly, the TPRM process that we have, we should have a AI checklist as well as part of it.

13:53 Because today you have vendors and if they have capabilities around say you know AI insights or whatever, that data is today going out of your ecosystem. A lot of the laws that are coming in India will require that data retention view as well. Right, I think in that aspects vendor should be transparent about if there is any feature of that sort that will be baked in. And your TPRM process can then follow. >> Okay, great. So, you went from a hands-on senior security role to CISO.

14:25 A lot of people who make that transition underestimate how much of the job is organizational. building teams, managing up, navigating politics. So, what's the part of CISO leadership that nobody tells you about until you're in it? >> Yeah. So, it was also very organic for me. >> Right. >> as I said earlier there was an inflection point where you realize if you have to make any s- security strategic changes, then you need to you know change your base of looking at things. And for me it was very organic that let's do a leadership role and figure out if I can you know change that.

15:08 and it has been a lot of learnings in the last three, four years. one is I have I've not been exposed to people management. I was not exposed to how influencing the the works at scale. And in the last three four years I've been able to you know, learn those things. It does it does change you a bit the way you think about security, the way you try to change things within an organization. These are some of the learnings that you kind of bake into in the journey. There are places that you falter, but those learnings kind of help you be a better security expert in in in the process.

15:50 And it it was very organic for me. It worked out and I I was able to, you know, learn very quickly. >> So, Black Hat India is coming to Bangalore bringing the global Black Hat community to a market with some of the most sophisticated fintech infrastructure in the world. And also the highest rates of digital fraud. What conversations do you think need to happen at an event like this that aren't happening anywhere else? >> I think first of all Black Hat India coming to you know, India itself is amazing and a lot of security professionals getting an opportunity to be part of it. This itself is a game-changer at the moment.

16:32 I remember in all my 16 years I used to when I started security, I used to have a dream about just joining one of those training sessions or going to Black Hat US, Black Hat Singapore. Now Black Hat is coming to India. I think it's it's more good for the country than Black Hat itself. This will help the country grow security mindset better. >> Correct. >> And whatever conversations, whatever talks that happen as part of that, they'll just help the entire ecosystem better the overall security thought process.

17:09 >> All right. >> Who in the Indian security community do you think needs to be in the room at Black Hat India? And what do you think they should take away? >> I hope everybody is there. Okay. And more than the Indian security ecosystem, I feel we should focus a lot on universities and colleges because I feel that's where the opportunity lies, right? A lot of Indian universities and colleges, if they try and have this curriculum on security, cybersecurity, we will build the next set of security engineers in the country.

17:46 >> Right. >> And if students are there in in the conference, it will just help everybody, you know, in the overall space of security. >> Right. So, we do have a thriving community of both offensive and defensive cybersecurity experts coming up in India. Lots of students coming up with brilliant research, developing open-source tools, and we're hoping to promote all of those communities at our Black Hat India event and help them in their growth and their journey in in terms of their professional journey as well as on the technical side. If you could put one problem, one thing that Indian security practitioners are not solving fast enough on the agenda for Black Hat India, what would it be?

18:30 >> I think it I always think about bridging the culture part of security within the company. We we come from, as you also stated, most of us come from pure tech cybersecurity backgrounds, right? we always see security and tech going hand in hand, but there's always a bridge which which kind of helps us get everybody in the ecosystem aligned towards cybersecurity.

19:01 I think that is one area I would love to see, you know, emerge very well is how people learn to bridge that gap. >> Got it. An an like this will not just help you from a technical perspective, but also will help you connect to other people in the community and build your network. And now you're responsible for protecting the financial data and investments of tens of millions of Indians. So, what does that weight feel like and what keeps you in this work?

19:31 >> Honestly, you know, I don't see that weight in the same lens as other seed because a lot of that weight is taken care by people who work with me and they are their caliber and their their expertise is some some of them are, you know, much more smarter than what I bring on the table. >> Okay. >> I'm I'm fortunate in a way to work with some of the smartest minds of security and that way I feel they balance it out and everyone comes together to save security in some way.

20:10 >> Yeah, and I've also heard a lot of the same being said about you as well. So, I think it was great having you here today. So, 80 million users, one CISO, a lot of attack surface. That's Prajal Kulkarni's world and exactly the kind of real world security challenges that Black Hat India exists to dig into. Thank you so much for joining us today and sharing your candid insights with us. >> Thank you, Ayush. >> Black Hat India is happening from October 27th to 30th at Sheraton Grand Hotel in Bangalore. Four days of arsenal, briefing, trainings, summit, and business hall for the people who actually are doing this work.

20:51 Cybersecurity practitioners, researchers, and cybersecurity leaders who are looking for more than just a keynote and a vendor hall. You can find details and registration at Bangalore for Black Hat India. >> I can't India.

Summary

Black Hat India is set to debut in Bangalore this October, featuring discussions with top cybersecurity experts, including Prajal Kulkarni, CISO of Grow. The podcast explores the current cybersecurity landscape in India, focusing on the challenges of account takeovers, vendor security, and the importance of building a security culture within organizations.

- Prajal Kulkarni transitioned from technical roles in offensive security to leadership to drive strategic security changes.
- Account takeovers are a significant threat in investment platforms, necessitating a balance of proactive and reactive security measures.
- Vendor and supply chain security is a critical challenge, with emphasis on understanding and tiering vendors to manage risks effectively.
- Effective vendor management involves collaboration and transparency, rather than relying solely on compliance reports.
- The rise of Shadow AI presents new risks, requiring organizations to incorporate AI assessments into their vendor risk management processes.
- The transition to a CISO role involves navigating organizational dynamics and building teams, which is often underestimated.
- Black Hat India aims to enhance the security mindset in the country, emphasizing the need for educational institutions to focus on cybersecurity curricula.
- Bridging the cultural gap in cybersecurity within organizations is essential for fostering a collaborative security environment.

Questions Answered

What is Black Hat India and who is the guest?

Black Hat India is a cybersecurity event taking place in Bangalore, featuring discussions on current threats and industry gaps. The guest, Prajal Kulkarni, is the CISO at Grow, with a background in offensive security and leadership roles.

What are the main challenges in vendor and supply chain security?

Vendor and supply chain security is a significant challenge due to the difficulty in controlling third-party ecosystems. Organizations must focus on uplifting their critical vendors to enhance overall security.

How can organizations ensure their vendors are secure?

Organizations should conduct continuous security assessments and collaborate closely with vendors rather than relying solely on reports. This includes understanding data management and security practices within the vendor's ecosystem.

How should organizations handle the challenges posed by Shadow AI?

Organizations need to ensure transparency from vendors regarding their AI usage and incorporate AI-related assessments into their vendor risk management processes to address potential blind spots.

What role should educational institutions play in cybersecurity?

Educational institutions should focus on developing cybersecurity curricula to prepare the next generation of security engineers. Involving students in events like Black Hat India can enhance their learning and professional growth.

© transcribe · For agents Built with care and craft by Gokul Rajaram