AI Will Replace Tasks, Not Analysts – Falgun Rathod | Leaders Talk

Falgun Rathod - Leaders Talk
Falgun Rathod – Leaders Talk

In today’s HOC Cybersecurity Leaders Talk, we feature Falgun Rathod, a cybersecurity professional, entrepreneur, and author of The Modern SOC.

He shares insights from his career journey, the changing world of ai impact, security operations, evolving cyber threats, and the key skills the next generation of cybersecurity professionals should focus on.

Opening: the journey

1. How did you get started in ethical hacking?

Back then, it wasn’t called bug bounty. It was known as responsible disclosure. I reported critical vulnerabilities to the Government of India and to several global tech giants long before bug bounty programmes became mainstream. There was no ChatGPT, no ready reference material, no CTFs or practice labs. We had to figure out everything on our own. Looking back, I feel proud that I managed to do it, and that experience still gives me the confidence that we can take on anything, even today.

2. Why did Falgun Rathod start Cyber Octet?

At that time, there were only three or four cybersecurity training institutes in the whole of India, and none in Ahmedabad. That was a big gap, because there was no one offering education and professional training together to students who wanted to build a career in cybersecurity. The market was just starting to emerge, and many IT professionals also wanted to upskill and stay relevant. What all of them were missing was real, hands-on training, the kind you need to get a job and then to handle your day-to-day work once you’re in it. That’s the gap I wanted to fill with Cyber Octet.

3. How has cybersecurity training evolved since 2011?

Ans. The starting point hasn’t changed. Anyone entering this field first needs strong fundamentals in computers and information technology, because that is the foundation of a cybersecurity career. But technology itself has changed dramatically since 2011. We’ve seen the rise of cloud computing, AI, blockchain, DevOps, compliance, privacy and much more. Each of these shifts has shaped cybersecurity and created new job opportunities. So training today has to cover these areas as well. At Cyber Octet, we update our curriculum every six months. We remove what has become outdated and add what candidates actually need, so they are always moving forward in their careers.

Cyber Octet and the training business

4. What services does Cyber Octet offer?

Ans. Cyber Octet covers offensive security, defensive security, governance, risk management and compliance, DFIR, corporate training, workforce development, staff augmentation, and now cybersecurity support as well. In short, we cover cybersecurity end to end for organisations across every vertical, and we work closely with CEOs, CIOs, CISOs and CTOs.

In my view, the biggest gap is communication. Boards often can’t see the risks sitting inside their own business, risks that turn into real problems later. Most businesses still take a reactive approach to cybersecurity, and that’s exactly where major breaches and cyber attacks happen. Training is part of this too. In most large organisations it happens once a year, when it really should happen every month.

As for certifications, it depends on the candidate. Which skills someone should build depends on several factors, including their background and their interests, so there’s no one-size-fits-all answer.

5. Why is there still a cybersecurity skills gap in the industry?

Ans. What’s missing today is practical experience and mentoring that’s relevant to the industry. A bachelor’s or master’s degree in cybersecurity or forensics doesn’t automatically make someone ready for an industry job. Candidates need proper hands-on training, a solid grounding in IT and computer basics, and ideally a fellowship or mentorship under someone experienced who can guide them with real industry knowledge.

The book | The Modern SOC: Security Operations Center

6. What is “The Modern SOC” about?
What prompted you to write specifically about the SOC at this point in your career — and what’s one “modern SOC” concept you think is still widely misunderstood?

Ans. The Modern SOC is a practical playbook for building, running and growing a Security Operations Center. It follows the journey from reactive monitoring to proactive, predictive and AI-assisted defence. After 17+ years, 400+ projects and 250+ incident investigations, I kept seeing organisations buy tools while their security operations stayed reactive. So Dr. Devanshi Vyas and I put our experience into one guide.

The most misunderstood concept is AI. People think AI will run the SOC and replace analysts. It won’t. The modern SOC is AI-assisted and human-directed.

7. Who should read The Modern SOC?
Did your VAPT or GRC experience influence any part of the book? and who did you write it for?

Ans. It’s written for students, SOC analysts, threat hunters, incident responders, and CISOs and security leaders. My VAPT experience helped me write about detection from an attacker’s point of view. My GRC experience is behind the sections linking SOC operations to frameworks like ISO 27001 and NIST CSF, and to the CISO’s view of business risk. 

Latest trends in cybersecurity

8. How is AI changing cybersecurity attacks and defense?
AI is now used on both sides — by attackers to accelerate exploitation, and by defenders to speed up triage. Where do you see that balance currently sitting?

Ans. Right now, I’d say attackers have a slight edge. They don’t need approvals, budgets or compliance sign offs, so they adopt AI faster, using it to write convincing phishing, find vulnerabilities and speed up exploitation. Defenders are catching up quickly with AI-assisted triage and detection. In the end, the balance will tip toward whoever uses AI with the best human judgement behind it. 

9. How are deepfakes and voice cloning affecting cybersecurity training?
Deepfake-driven social engineering is starting to affect organizations directly. Is that changing how you approach training?

Ans. Yes, it has changed our approach completely. “Spot the spelling mistake in the email” doesn’t work anymore when an attacker can clone your CEO’s voice or face on a video call. We now train people to verify the process, not the person: call back on a known number, use a code word, and never approve payments or share credentials just because the request sounds or looks real. This is also why I say training should be monthly, not annual. 

10. How is India’s DPDP Act affecting cybersecurity compliance?
With the DPDP Act now in force, how is compliance work reshaping the GRC side of your business?

Ans. The DPDP Act has made privacy a board-level topic in India. Earlier, many companies treated data protection as an IT checkbox. Now they want to know what personal data they hold, where it sits, who can access it and how consent is managed. For us, it has created strong demand for gap assessments, data mapping, policies and audit readiness, and it’s pushing GRC from documentation to real accountability. 

11. Which industries are most targeted by ransomware right now?
Are you seeing ransomware groups shift focus toward mid-size manufacturers and healthcare providers rather than only large enterprises, based on your own engagements?

Ans. Yes, we’re clearly seeing that shift. Large enterprises have invested heavily in security, so attackers are moving to mid-size manufacturers, healthcare providers and their supply chains. These organisations can’t afford downtime, often run older systems, and usually don’t have a dedicated security team, which makes them easy and profitable targets. 

12. Will AI replace cybersecurity analysts?
Agentic AI is starting to operate inside SOCs, not just support them. How much of a Tier-1 analyst’s role do you expect to be automated over the next few years?

Ans. AI will replace tasks, not analysts. Over the next few years, I expect a large part of Tier-1 work, like alert triage, enrichment and closing false positives, to be automated by agentic AI. But that doesn’t remove the analyst. It moves them up to investigation, threat hunting and decision-making. As we say in The Modern SOC, the future is AI-assisted and human-directed. 

Closing — personal and forward-looking

13. Advice for the Next Generation?
With more graduates entering the field, where do you see the biggest gap today—practical experience, technical skills, hands-on-experience?

Ans. As mentioned in Answer 5.

14. What’s next for Cyber Octet?
Is there another book already taking shape?

Ans. We are coming with lot of things with expansion, a platform for GRC and yes obviously a book too but this time only for academics 

FAQ 

  • Who is Falgun Rathod? 

Falgun Rathod is the Founder and Managing Director of Cyber Octet. He is also an author dedicated to sharing knowledge and promoting cybersecurity awareness.

  • What is Cyber Octet? 

Cyber Octet is a cybersecurity company offering training services, VAPT, GRC, compliance, based in Ahmedabad, India.

  • What is a Security Operations Center (SOC)? 

A SOC is a dedicated team that keeps an organization’s systems and networks secure by monitoring for threats, detecting security issues, and responding to cyberattacks.

  • What is The Modern SOC book about? 

The Modern SOC, how security operations centers are evolving and the challenges facing security teams.

  • How can I get cybersecurity training in Ahmedabad, India? 

Cyber Octet offers hands-on cybersecurity training programs covering AI security, ethical hacking, VAPT, GRC, and compliance.

 

Join Our Club

Enter your Email address to receive notifications | Join over Million Followers

Previous Article
FBI Removes Accenture Contract

FBI Removes Accenture Contractor Following ShinyHunters Data Breach