
Kavitha Mariappan
Chief Transformation Officer
Rubrik

August 2026
This is sponsored content.
Sixteen months into her tenure as Rubrik’s Chief Transformation Officer, Kavitha Mariappan says the most rewarding aspect of her role is the depth of her conversations with CIOs and CISOs: “The leaders I learn the most from are the ones willing to share what they’re genuinely worried about.” It’s also the community that has formed around those conversations, she adds.
“Conviction has shaped everything I’ve done,” Kavitha says. Her journey has taken her from engineering roles to sales and go-to-market strategy, leading product management and marketing teams, and, most recently, spearheading transformation initiatives at Zscaler.
Transformation is only meaningful when it's tied to outcomes that actually matter to the people you're serving.
Each stage of her career, she notes, has offered a unique perspective on a core question: “How do you help organizations use technology to their advantage, rather than just deploy it?”
At Rubrik, Kavitha says, “That question has never mattered more. The stakes are existential. When a CISO is grappling with what agentic AI means for their recovery posture, or a CIO is trying to build governance for systems that operate faster than any dashboard can reflect, those are the conversations where real thinking happens, and I get to be part of them every day.”
A Defining Moment: AI’s Transformative Role
These conversations are unfolding during a pivotal time in technology. Kavitha puts it plainly: “We are in the middle of a shift from prevention-first thinking to resilience-first economics. Markets still reward efficiency and growth, but increasingly, value will be determined by how quickly an organization can recover when something breaks, and how much trust it can maintain with customers and regulators in the process.”
AI adoption at many organizations is outpacing governance, policy and even understanding, leaving many enterprises with “systems they can’t fully observe, govern, or restore,” she says. The shift toward agentic AI, systems that take autonomous actions across enterprise infrastructure, has moved from a theoretical concern to present reality. “Organizations that treat resilience as a prerequisite for AI adoption build a fundamentally stronger foundation than those who address it later,” she explains.
Kavitha has recently addressed emerging agentic AI risks at several Gartner C-Level Community Executive Summits. In her keynote for the DACH CIO & CISO Community Executive Summit, “A Resilient Path Through Emerging Agentic AI Risks,” she referenced Gartner’s prediction that by 2028, 15% of daily business decisions will be made autonomously by AI agents – introducing a new category of risk that many organizations are not yet prepared to manage.
Her session focused on three key areas: establishing resilience standards for AI agents that align with enterprise risk, developing strategies to detect and contain unintended or rogue agent behavior, and creating playbooks for rapid rollback when AI disrupts business workflows. As Kavitha notes, “Organizations are experiencing these scenarios today, and most don't have recovery plans in place.”
Key Focus Areas for Technology & Security Leaders
Based on her conversations with CIOs and CISOs, Kavitha names two organizing themes as key focus areas, recovery and identity, with resilience as the opportunity for leaders who move deliberately. Kavitha explains that recovery has evolved into “an enterprise assurance topic, not an IT activity,” calling it “one of the most significant shifts I’ve seen in the last two years.”
Boards are now asking CISOs to demonstrate that they can recover, and how fast.
Kavitha points out that identity has become another central focus. She cites Rubrik Zero Labs research indicating that “up to 90% of attacks have an identity component.” The challenge now extends far beyond human users, as non-human identities – such as machine accounts, APIs, service principals, and AI agents – “have multiplied faster than most organizations’ ability to govern them.” Many enterprises have no clear picture of how many non-human identities they are running, what those identities can access, or what happens to permissions when something goes wrong.
On the resilience opportunity, Kavitha emphasizes that CIOs and CISOs who take proactive steps have the chance to “build resilience infrastructure now that compounds over time.” She notes that the most effective organizations are already identifying their “minimally viable organization,” or the essential identities, configurations, and permissions that must be recoverable, rather than waiting for a crisis to force these decisions under pressure.
When asked where IT and security leaders should direct even greater attention, Kavitha points to recovery risk, describing it as “the risk that doesn't show up on balance sheets, but it keeps me up at night.”
Kavitha notes that the pace of digital transformation often outstrips organizations’ readiness to recover from disruptions, creating a gap “wider than most leaders realize.” She points out that few have tested their recovery plans under real-world conditions, such as compromised identities, corrupted backups, or intense time pressure.
She observes that “identity is missing from the recovery plan.” While teams may be able to rebuild servers, they often struggle to quickly restore trust, federation, or conditional access, leaving users unable to access critical resources. Kavitha also highlights a common misconception: that having backups is the same as having a recovery capability. She stresses that testing is essential to close this gap, yet most organizations have not done so under realistic scenarios.
Another important area of focus for security leaders, according to Kavitha, is board readiness. She is finding that CISOs are “increasingly being asked to present on AI risk and cyber resilience,” yet there often isn’t a shared framework guiding these discussions. “Developing that common language, what questions boards should ask and what answers should satisfy those questions, is still unfinished work for the industry,” she says.
Leading with Purpose: Focus and Excitement for the Future
In terms of her top priorities, Kavitha is focused on “establishing AI resilience as a recognized discipline,” emphasizing the need for a shared framework to guide how organizations protect, govern, and recover from AI-driven incidents. She notes that this work is already underway, citing Rubrik’s involvement in the Cloud Security Alliance’s AI Resilience Center of Excellence, and she is eager to help define “the standards that practitioners will actually use.”
Kavitha also prioritizes expanding community programs that connect CXOs and foster open, candid dialogue. She is committed to developing the next generation of leaders, too, particularly through initiatives like Rubrik’s Women in AI, Security and IT program.
Kavitha sees today’s cyber leadership as fundamentally transformative, emphasizing the importance of “communicating risk in the language of business, national interest, and public trust.” She notes that these conversations are now taking place at the highest levels, moving from the end of the agenda to a top priority for organizations and governments alike.
What excites her most is the way the security community is coming together to address these challenges. “The peer conversations I’m part of, between CISOs sharing what’s actually working, CIOs building new governance frameworks in real time, practitioners developing playbooks the industry will run on for the next decade, that collective problem-solving is some of the most impressive leadership I’ve witnessed in my career,” she shares.
Kavitha is leading a session on resilience at the upcoming Gartner Global CISO Community Executive Summit, “The Resilience Gap — When Downtime Becomes a Brand Crisis.” If you are a member of the Gartner Global CISO Community, register to join the session here. If you are not yet a member of Gartner CISO Communities, apply to join here.
By CISOs, For CISOs®
Find your local community and explore the benefits of becoming a member.