

As cyber threats become more sophisticated and AI adoption accelerates, digital trust is emerging as a critical priority for businesses. In this conversation, Rajeev Ranjan, Editor, Digital Terminal, speaks with James Cook, Group Vice President Sales APJ at DigiCert, about strengthening cyber resilience, addressing emerging security risks, building trust in AI-generated content and preparing for shorter SSL/TLS certificate lifecycles.
Rajeev: With phishing and identity-based attacks on the rise, what steps should organizations take to strengthen their cyber resilience?
James: Organizations need to move beyond traditional perimeter-based security and adopt an identity-first approach to cyber resilience. As phishing, credential theft, and identity-based attacks become increasingly sophisticated, every user, device, application, and machine identity must be continuously verified and protected. Implementing strong authentication mechanisms such as multi-factor authentication (MFA), adopting Zero Trust security principles, and ensuring effective certificate and key management are critical steps.
Organizations should also automate certificate lifecycle management to eliminate outages caused by expired or misconfigured certificates. Fostering a strong security culture through regular employee awareness training is also very important as human error remains one of the most common attack vectors.
Rajeev: What role will digital trust play in supporting India's rapidly expanding digital economy and AI ambitions?
James: Digital trust will be a foundational pillar of India's digital transformation journey. As the country accelerates adoption of AI, cloud technologies, digital payments, connected devices, and e-governance platforms, trust becomes essential for enabling secure interactions between individuals, businesses, governments, applications, and machines. Without trust, digital innovation cannot scale sustainably.
For India's AI ambitions in particular, organizations must be able to verify the authenticity, integrity, and origin of digital content, data, software, and communications. Digital trust technologies such as PKI, digital signatures, certificate-based authentication, and cryptographic verification help establish confidence in digital transactions and AI-driven systems. As India continues to build one of the world's largest digital economies, digital trust will be the invisible infrastructure that enables innovation, protects users, and supports long-term economic growth.
Rajeev: Cyberattacks in India are becoming more sophisticated. What emerging threats should Indian organizations be most concerned about in 2026?
James: In 2026, organizations should be particularly concerned about AI-powered cyberattacks, identity-based threats, software supply chain compromises, and increasingly sophisticated social engineering campaigns. Attackers are leveraging generative AI to create highly convincing phishing emails, fake identities, deepfake videos, and fraudulent communications that are more difficult to detect than ever before.
Machine identities are also growing rapidly as organizations expand their cloud, IoT, and AI deployments. Every machine identity represents a potential attack surface if not properly managed. Supply chain attacks also remain a major concern, as threat actors increasingly target trusted vendors, software providers, and third-party ecosystems to gain broader access.
As cybercriminals become more organized and technologically advanced, organizations must adopt a proactive security posture focused on identity protection, cryptographic security, continuous monitoring, and automation to stay ahead of evolving threats.
Rajeev: How can businesses build trust in AI as concerns around deepfakes, misinformation, and AI-generated content continue to grow?
James: As AI-generated content becomes increasingly sophisticated, businesses need to move beyond simply trusting what they see and begin verifying where content came from, how it was created, and whether it has been altered. Building trust in AI starts with establishing authenticity, accountability, and provenance across the AI lifecycle.
Organizations should focus on three key areas. First, every AI system, agent, and model should have a verifiable identity so users know who—or what—is generating content and taking actions. Second, organizations need cryptographic provenance and content credentials that can trace content back to its source and provide transparency into whether AI was involved in its creation or modification. Third, strong governance and auditability are essential so organizations can understand, monitor, and explain AI-driven decisions.
The challenge isn't AI itself, but it's the absence of trust mechanisms around AI. We've faced similar challenges with websites, software, and digital identities before. The solution is the same: establish trusted identities, verify integrity, and create transparent records that allow people to independently validate what they're interacting with.
As AI becomes more autonomous and content becomes more difficult to distinguish from synthetic media, trust must be based on verification rather than assumption. Organizations that invest in identity, provenance, and governance today will be best positioned to realize the benefits of AI while mitigating the risks of deepfakes, misinformation, and manipulated content.
Rajeev: What are the biggest digital trust challenges facing Indian enterprises today?
James: As organizations accelerate digital transformation, the number of certificates, cryptographic keys, and machine identities requiring protection continues to grow exponentially, making it one of the biggest challenges to digital trust.
Another challenge is balancing innovation with security. Enterprises are rapidly adopting cloud services, AI, and connected technologies, but often struggle to implement security controls at the same pace. Regulatory compliance requirements, evolving cyber threats, and fragmented security environments further add to the complexity.
Additionally, the rise of AI-generated content and sophisticated impersonation attacks has elevated concerns around authenticity and verification. Enterprises must therefore focus on building comprehensive digital trust frameworks that combine strong identity management, automation, cryptographic security, and governance to maintain trust across their digital operations.
Rajeev: How prepared are Indian organizations for shorter SSL/TLS certificate lifecycles and the need for greater automation?
James: The move toward shorter SSL/TLS certificate lifecycles represents an important step toward improving internet security, but it also introduces new operational challenges. Many organizations still rely on manual processes to manage certificates, making them vulnerable to outages, security gaps, and compliance risks as certificate renewal frequencies increase.
While awareness around certificate lifecycle management has improved significantly, preparedness levels vary across industries. Organizations with mature security programs are increasingly investing in automation to discover, monitor, renew, and manage certificates at scale. However, many enterprises are still in the early stages of this transition.
The reality is that shorter certificate lifecycles make automation a business necessity rather than a security enhancement. Organizations that automate certificate management will be better positioned to maintain security, reduce operational risk, and ensure business continuity, while those relying on manual processes may face increasing challenges in managing their digital trust infrastructure effectively.
𝐒𝐭𝐚𝐲 𝐢𝐧𝐟𝐨𝐫𝐦𝐞𝐝 𝐰𝐢𝐭𝐡 𝐨𝐮𝐫 𝐥𝐚𝐭𝐞𝐬𝐭 𝐮𝐩𝐝𝐚𝐭𝐞𝐬 𝐛𝐲 𝐣𝐨𝐢𝐧𝐢𝐧𝐠 𝐭𝐡𝐞 WhatsApp Channel now! 👈📲
𝑭𝒐𝒍𝒍𝒐𝒘 𝑶𝒖𝒓 𝑺𝒐𝒄𝒊𝒂𝒍 𝑴𝒆𝒅𝒊𝒂 𝑷𝒂𝒈𝒆𝐬 👉 Facebook, LinkedIn, Twitter, Instagram