The Architecture of Trust

Lessons from SECURITY TODAY Knowledge Summit 2026
The SECURITY TODAY Knowledge Summit 2026 (STKS 2026) examined how AI, surveillance, autonomous systems, quantum threats and converging enterprise risks are transforming security. Through keynotes, expert sessions and panel discussions, the Summit explored the growing challenge of sustaining trust when protective technologies can themselves become attack surfaces. The discussions emphasised human judgment, AI control, reliable data, organisational intelligence and resilient Joint Operations Centres, highlighting that the future of security depends on technology working within strong governance and accountable human decision-making.

Like previous editions the SECURITY TODAY Knowledge Summit 2026 concluded in Mumbai on the 2nd of September 2026 on a high note.

The evolution of STKS themes over the past four years reflects the changing nature of security risk and the Summit’s continuing effort to look beyond immediate industry concerns towards the challenges that lie ahead. STKS 2023, “Expecting the Unexpected,” focused on recognising emerging risks and asking whether organisations were adequately prepared for a rapidly changing world. In 2024, “Building 360° Phygital Resilience,” the emphasis shifted towards integrating physical and digital security, operational resilience and the growing convergence of risks. STKS 2025, “Re-thinking Resilience in a Risk-Laden World,” broadened the conversation to national resilience, critical infrastructure, maritime and energy security, disinformation and indigenous capability. Building on this progression, STKS 2026, “Sustaining Trust in an AI-Driven World,” examined an even more fundamental question: as AI, autonomous systems and connected technologies increasingly influence security decisions, how can organisations build and sustain trust in the systems, information and decisions on which enterprise resilience depends?

The Summit commenced with the opening and welcome address by GB Singh, Editor-in-Chief, SECURITY TODAY, who warmly welcomed the distinguished speakers, members of the STKS Steering Committee, industry leaders, security practitioners, partners and delegates from India and overseas. In his address, he reflected on SECURITY TODAY’s more than two decades of contribution to the security industry and the evolution of the SECURITY TODAY Knowledge Summit since its inception in 2006. He highlighted the role of STKS as a forum for meaningful dialogue, knowledge exchange and forward-looking conversations on emerging security and risk challenges.

GB Singh expressed his sincere gratitude to the STKS Steering Committee for its continued contribution to shaping the Summit into a high-quality platform for meaningful industry dialogue. He acknowledged the Committee’s role in identifying emerging issues, developing the agenda and bringing relevant experts and thought leaders to the Summit. He particularly recognised the leadership of Rajan Luthra, Senior Executive Vice President, Reliance Industries Limited and Distinguished Fellow, Observer Research Foundation, Chair of the Committee. He also acknowledged the valuable contributions of Bruce McIndoe, President & Founder, WorldAware and Risk Advisor, McIndoe Risk Advisory; Dr. Firoze Zia Hussain, Chief Security Officer, Delhivery; Amit Narayan, Partner, India and South Asia, Control Risks; Ankush Maria, Global Deputy CSO, Ernst & Young; and Aman Singh, Associate Editor, SECURITY TODAY. The Committee was further strengthened this year with Col. Amit Dabas, Global Head – Brand Protection & Resilience, IHCL – Taj Hotels; Col. Shekhar Attri, APAC Regional Security Leader, Collins Aerospace; and Esti Peshin, Global Cybersecurity & AI Expert and former Vice President – Cyber Division, Israel Aerospace Industries. GB Singh placed on record his appreciation for the time, expertise and commitment of the Committee members, whose collective contribution continues to keep the STKS agenda contemporary, challenging and forward-looking.

Rajan Luthra, Chair of the STKS 2026 Steering Committee, set the intellectual context for the Summit through his opening presentation, “Anticipating Risks: 2016 → 2026 – What Can We Learn from WEF Global Risk Reports?” Drawing on the World Economic Forum’s Global Risks Reports, he examined how the nature of risk has changed over the past decade, highlighting the emergence of geoeconomic confrontation, misinformation and disinformation, societal polarisation and the growing implications of AI. He argued that the challenge is no longer simply identifying risks, but recognising how interconnected dependencies across technology, data, infrastructure, information and trust can themselves become attack surfaces. This provided a compelling context for the Summit’s central theme, “Sustaining Trust in an AI-Driven World,” and its focus on decision-making, surveillance, autonomy and enterprise resilience.

Security has traditionally been built around a fundamental proposition: that the systems, processes and people put in place to protect an organisation can be trusted to perform when they are needed most. A surveillance camera is expected to provide an accurate picture of what is happening, an access-control system is expected to distinguish between authorised and unauthorised movement, an alarm is expected to identify an abnormal event and a security professional is expected to interpret the available information and take the appropriate action. As technology has become increasingly integrated into every aspect of security operations, however, that proposition is becoming considerably more complex. The systems designed to protect an organisation are themselves becoming connected, intelligent and increasingly dependent on data, software and communications infrastructure. The result is that the very architecture of security can also become part of the attack surface.

This emerging reality provided an important backdrop to the SECURITY TODAY Knowledge Summit 2026, where the central theme of sustaining trust in an AI-driven world was examined from a remarkably wide range of perspectives. The Summit did not approach artificial intelligence merely as another technology that security departments need to adopt. Instead, the discussions repeatedly returned to the more fundamental questions surrounding decision-making, accountability, surveillance, organisational intelligence, autonomous systems, quantum threats, enterprise risk and the ability of organisations to respond coherently when multiple risks converge. In doing so, STKS 2026 presented a picture of a security environment in which the traditional boundaries between physical security, cybersecurity, technology risk, business continuity and enterprise resilience are becoming increasingly difficult to maintain.

One attendee’s three-part reflection following the Summit described this emerging challenge as the “Anatomy of Weaponised Trust”, followed by the transition “From AI Adoption to AI Control” and finally an examination of “The Architecture of Trust”. Taken together, these observations provide a useful lens through which to understand the larger message of STKS 2026. The Summit’s individual sessions may have addressed very different subjects, but collectively they examined one common issue: how organisations can continue to make reliable decisions when the speed, scale and complexity of the information environment is increasingly beyond the capacity of humans to process unaided.

The question was introduced appropriately through the opening keynote by Air Marshal Nagesh Kapoor, Director General, Centre for Airpower & Strategic Studies and former Vice Chief of Air Staff, who addressed “Human Judgment in an AI World: Who Owns the Decision?” The title itself captured one of the most consequential issues confronting security leaders. Artificial intelligence can process enormous volumes of information, identify patterns, correlate events and produce recommendations at a speed that is impossible for an individual or even a large team of people to match. But the ability of a machine to recommend or initiate an action does not remove the question of who is ultimately responsible for that action.

As AI becomes embedded in security operations, decision rights therefore become as important as technical capability. Organisations will have to establish where automated decision-making is appropriate, where human approval remains essential and under what circumstances a human operator must be able to intervene or override the system. This is particularly important in security because the consequences of an incorrect decision may extend well beyond the digital environment. A false assessment can influence the deployment of personnel, evacuation decisions, access restrictions, emergency response and business continuity. The faster machines become at processing information, the more important it becomes for organisations to be clear about the human responsibility attached to the final decision.That question of trust became even more complex in the session led by Mr. Rajan Luthra, Senior EVP, Reliance Industries Ltd and Distinguished Fellow, Observer Research Foundation, on “The Ubiquity of Surveillance & Inversion of Security”. Surveillance has historically been one of the principal instruments of protection. Organisations deploy cameras, video-management systems, analytics, access-control technologies and other sensors to create visibility over their physical environments. Yet as these technologies become increasingly connected and intelligent, they also create new opportunities for exploitation. A system that provides visibility to the security team may, if compromised, provide that same visibility to an adversary.

The industry deliberation involving Swati Samaddar of CP PLUS, Syed Ishtiyaq of Howell Protection Systems and Anand Thirunagari of Genetec brought together perspectives from the OEM, system-integration and video-analytics and AI software sides of the ecosystem. The significance of this combination was that surveillance security can no longer be considered solely in terms of the camera or the physical infrastructure. The complete technology chain matters, including software, networks, integrations, data, user privileges, device security and the processes through which information is interpreted and acted upon. The “inversion” of security occurs when the protective infrastructure itself becomes an avenue through which an attacker can observe, manipulate or disrupt the organisation.

The problem becomes even more pronounced as organisations deploy increasing numbers of sensors and generate enormous quantities of security data. The traditional assumption that more information necessarily leads to better security is increasingly questionable. Security teams can find themselves dealing with thousands of alerts and an almost continuous stream of video, access, network and operational data. The challenge is no longer simply to collect information but to determine which information is meaningful, which events require attention and how quickly a decision must be made.

This was the context in which Jeremy Verstraete, Global Vice President, UL Solutions, addressed the Summit on “Signal through the Noise: Reimagining Fire and Security with AI”. The potential of AI in this environment lies not simply in its ability to produce more alerts or analyse more data, but in its capacity to identify patterns and relationships that might otherwise remain hidden within the volume of information available to security teams. The ultimate objective is to turn data into actionable intelligence rather than simply adding another layer of information to an already overloaded security operation.

However, increased automation also introduces a different dimension of risk. When people begin to assume that an AI-generated output is inherently more objective or reliable than human judgment, automation bias can develop. A machine recommendation may acquire an authority that it has not necessarily earned. If the underlying data is incomplete, corrupted, outdated or manipulated, the sophistication of the analytical system cannot compensate for the weakness of its inputs. The attendee’s observation that “the machine stripped human friction, leaving only the illusion of velocity” captures this concern. Faster processing does not necessarily mean better decision-making if the organisation has not established confidence in the data or the assumptions behind the system.

This is why the conversation at STKS 2026 moved naturally from AI adoption towards AI control. The session “Beyond Silos: Building the Next-Generation Organizational Intelligence Function”, chaired by Esti Peshin, global cybersecurity and AI expert and former Vice President of the Cyber Division at Israel Aerospace Industries, examined the increasingly important relationship between intelligence, technology and strategic decision-making. With Col. Hasmukh Patel and Samir Kumar Jha joining the discussion, the session addressed a reality that many organisations are now confronting: threats rarely remain within the organisational department in which they first appear.

A cyber incident can quickly become an operational problem. A supply-chain disruption can create physical-security implications. Geopolitical developments can affect personnel, logistics and business continuity. Fraud can exploit weaknesses in both digital and physical processes, while AI can accelerate the creation and dissemination of misleading information. Treating these risks as separate departmental responsibilities can therefore create gaps between detection and response. Organisational intelligence increasingly requires the ability to bring together information from different functions and establish a common understanding of what the organisation is facing.

The discussion on “Autonomous Systems: Drones, Robotics & Counter-UAS”, moderated by Rajan Luthra and featuring Dr Saurav Agarwal, Dr Chaitanya Giri and Anshul Gupta, extended this convergence into the physical environment. Drones and robotic systems are no longer simply emerging technologies with limited security relevance. Their increasing autonomy introduces a different category of operational questions because machines can increasingly sense their environment, analyse information and perform physical actions with limited human intervention. Security leaders therefore have to consider not only what these systems are capable of doing but also how much operational trust can be placed in them, what happens when their inputs are compromised and where human intervention must remain available.

The Summit also looked beyond immediate AI concerns to a technological development that could fundamentally alter some of the assumptions on which today’s digital security infrastructure is based. In his keynote, “Building Trusted Security Systems When Quantum Threats Loom”, Dr G.K. Goswami, IPS, Founding Director of the Uttar Pradesh State Institute of Forensic Science, examined the implications of quantum threats for identity, encryption and security infrastructure. For security leaders, the significance of the quantum discussion lies not simply in predicting when quantum capabilities will mature, but in recognising that infrastructure being deployed today may have to remain secure for many years. Long-term security planning therefore requires organisations to consider threats that may not yet have reached their operational environment but could affect the technologies on which they increasingly depend.

The theme of converging risks came together particularly clearly in the panel discussion “Trust Beyond AI: Navigating the New Enterprise Risk Convergence”, moderated by Col. Amit Dabas of IHCL – Taj Hotels, with Dr Firoze Zia Hussain of Delhivery, Col. Shekhar Attri of Collins Aerospace and Amit Narayan of Control Risks. Geopolitics, regulation, supply chains, fraud and AI were considered not as independent subjects but as interconnected elements of enterprise risk. This reflects the changing role of the contemporary security leader. Security is increasingly being asked to provide the organisation with an integrated understanding of risk rather than simply protecting premises, personnel or assets within a defined physical boundary.

The practical expression of this integrated approach emerged in the expert session on “Designing & Operating 1st Global Joint Operations Centre”, presented by Bruce McIndoe, President & Founder, WorldAware and Risk Advisor, McIndoe Risk Advisory, together with Brig. Satish Penghal, Head of Joint Operations Centre, Reliance Industries. The Joint Operations Centre represents an attempt to bring information, technology, expertise, processes and decision-making together within a common operational environment. Its effectiveness, however, does not depend simply on the number of screens or the sophistication of the technology deployed. It depends on whether the information reaching the centre can be trusted, whether the organisation has defined how information is escalated, whether decision rights are clear and whether the people operating the centre are capable of acting within the available window of impact.

This is where the concept of “Certainty Management”, referred to in the post-Summit reflection, becomes particularly relevant. Security organisations can rarely eliminate uncertainty. They can, however, improve the quality and reliability of the information available to decision-makers, establish appropriate levels of confidence, identify gaps and ensure that uncertainty itself becomes part of the decision process. A mature security operation should therefore be able to distinguish between what it knows, what it believes, what it suspects and what it does not know. That distinction becomes increasingly important when AI systems are generating recommendations at machine speed.

Trust, consequently, cannot be something that an organisation attempts to establish after an incident has occurred. It has to be developed through the routine operation and testing of systems. Data governance, device protection, cybersecurity controls, service-level agreements, escalation procedures, system testing and business continuity arrangements may not attract attention when everything is functioning normally, but they determine how an organisation performs when conditions deteriorate. The principle of “degrading gracefully” is particularly important in this context. A security system that fails openly and communicates that it is unavailable may be more useful than one that continues to display information that is incomplete, stale or misleading.

This places a significant responsibility on security leaders. As technology becomes more capable, the temptation will be to assume that automation can compensate for organisational weaknesses. It cannot. AI can accelerate analysis, but it cannot repair poor governance. Analytics can identify anomalies, but they cannot create trustworthy data where the underlying information is compromised. A JOC can bring information together, but it cannot compensate for unclear decision rights. Autonomous systems can extend operational capability, but they also introduce new questions about accountability and control.

The central message emerging from STKS 2026 was therefore not a rejection of technology but a more mature understanding of how technology must be integrated into security. The future will undoubtedly involve greater use of AI, intelligent surveillance, autonomous systems, advanced analytics and increasingly sophisticated command-and-control environments. The challenge for security leaders is to ensure that these technologies strengthen rather than weaken human decision-making.

Ultimately, the architecture of trust rests on the relationship between technology, information and human judgment. Machines will increasingly determine how quickly information is collected, correlated and presented. They may increasingly recommend what should be done and, in some environments, may eventually initiate actions themselves. But organisations will still need people who understand the context, challenge assumptions, recognise uncertainty and accept responsibility for consequential decisions.

That is perhaps the most significant question raised by STKS 2026. The future of security will not be determined merely by how quickly organisations adopt AI, but by how thoughtfully they establish the boundaries within which AI operates. The real measure of an intelligent security system will not be how much it can automate, but whether it enables an organisation to make better decisions, retain accountability and respond effectively when the information environment becomes uncertain, contested or compromised.

In an era when trust itself can become an attack surface, building that capability is no longer simply a technology challenge. It is becoming one of the defining responsibilities of security leadership.

The closing remarks were delivered by Ms. Aman Singh, Associate Editor, SECURITY TODAY and Co-Convenor, STKS 2026, who thanked all the speakers, Partners, delegates and members of the Steering Committee for their contribution to the Summit, while also acknowledging the highly interactive and attentive audience, with many delegates seen taking notes and engaging deeply with the sessions and the speakers. She also highlighted the valuable networking opportunities that enabled security leaders and professionals to connect and exchange experiences. A special word of appreciation was reserved for Ms. Varsha Avadhny, CEO, Vibe Consulting, Bengaluru, who had enrolled as a delegate but stepped in as the MC at the last moment following an unfortunate accident involving the professional MC and members of her team the previous day. With over 25 years of experience in crime prevention, workplace violence, insider threats, risk culture and change management, Varsha readily took on the responsibility on the morning of STKS 2026 and helped the Summit navigate an unexpected crisis with professionalism and grace.

Previous articleUK organisations ill-equipped to contain rogue AI agents
Next articleMangaluru prison jammers to be fine-tuned without affecting security