Sumit Dhawan headshot
Sumit Dhawan headshot

Sumit Dhawan

Chief Executive Officer

“You cannot secure the future of work without securing how people and AI interact with data.”

As Featured In

Industry Perspectives

CNBC’s Closing Bell: Clear market trend for software providers to help with AI: Proofpoint CEO

Proofpoint CEO Sumit Dhawan joined CNBC Bell to discuss how AI is reshaping and cybersecurity markets, highlighting a shift toward trusted, unified platforms for agentic adoption. He said frontier AI like Claude Mythos accelerates exploits faster than vulnerabilities can be patched, making complementary controls essential and traditional patching cycles inadequate. 

Business executive participating in CNBC interview on cybersecurity and industry trends.

AI Security

NYSE – Floor Talk: RSAC 2026: Sumit Dhawan, Proofpoint, CEO

At RSA Conference in San Francisco, Proofpoint CEO Sumit Dhawan examines how generative and agentic AI are transforming cybersecurity. He discusses emerging risks, from prompt engineering to data exposure, and explains how Proofpoint’s intent-based AI security aims to protect people, data, and AI agents as threats become sophisticated and scalable. 

Executive discussing AI security and business strategy during NYSE interview.

Agentic Workspace

NightDragon: AI and the New Threat Landscape

As AI lowers barriers for cybercriminals, attacks are more sophisticated, scalable, and language-agnostic. Proofpoint CEO Sumit Dhawan highlighted momentum from the Hornetsecurity acquisition and expanded global reach. He emphasized intent-based detection to identify threats and simplify security, and how a unified platform helps organizations stay ahead of evolving risks. 

Industry leaders discussing AI security and innovation during panel interview.

Industry Presentations

Sumit can be seen at cybersecurity, AI, and business industry events around the globe.

  • The AI Advantage: How Founders Build Durable Vertical Companies (Masterclass). Google & TiEcon Silicon Valley (May 2026)
  • How the Employee Compute Paradigm is Changing Cyber (Panel). RSA Conference (March 2026)
  • The Next Chapter: Human-centric, AI-Ready Security (Keynote). Proofpoint Protect, Global (Sept 2025-March 2026)

Sumit's bio

Sumit Dhawan is Chief Executive Officer at Proofpoint. He leads a global workforce focused on advancing human- and agent-centric security so organizations can confidently adopt AI. Proofpoint leverages unmatched threat intelligence to secure the agentic workspace—protecting people, defending data, governing AI, and using AI as a force multiplier against emerging threats. 

Sumit brings more than 25 years of experience building category-leading enterprise software companies and businesses. Before joining Proofpoint, he served as President of VMware, where he led go-to-market functions and helped drive more than $13 billion in revenue. He also served as VMware’s Chief Customer Experience Officer, overseeing global professional services, technical support, and customer success teams. 

Earlier in his career, Sumit was CEO of Instart, a cybersecurity company focused on web application performance and security, and held senior executive and general management roles at Citrix. He is a strong advocate for exceptional customer and partner experiences, diverse teams, inclusive cultures, and equitable environments. 

Sumit holds an MBA from the University of Florida’s Warrington College of Business, an MS in Computer Science from the University of Minnesota, and a BS in Computer Science from the Indian Institute of Technology. 

Industry recognition for leadership, innovation, and scaling global organizations.

Cybersecurity Excellence Awards winner badge recognizing cybersecurity achievement.
2025 Globee Awards Gold Winner badge for cybersecurity excellence.

Agentic Workspace and AI-Native Security 

What is the agentic workspace?

“The workspace has changed faster in the last two years than the previous twenty.” 

The agentic workspace is where people and AI agents work together across email, collaboration tools, SaaS, cloud, and data environments. AI agents do not just assist. They access data, make decisions, and execute tasks across systems. That expands both productivity and risk, which means security must now protect how work happens across people, agents, and data. 

What does agentic AI mean for cybersecurity architecture?

“Security has to follow behavior and data, not infrastructure.” 

Agentic AI shifts cybersecurity from infrastructure-centric to identity, behavior, and data-centric models. Work now flows across users, agents, and systems, often outside traditional boundaries. Security must continuously verify access, monitor actions in real time, and enforce controls wherever data moves. 

What does human-centric security mean today?

“Attackers do not break systems. They exploit people, and now AI agents.” 

Human-centric security means protecting people as the primary attack surface. In an AI-driven environment, that extends to the behavior of both humans and AI agents. Security must focus on how users and agents interact with data, not just the systems they use. 

What is Proofpoint’s POV on securing the future of work?

“You cannot secure the future of work without securing how people and AI interact with data.” 

The future of work is human and agentic. Security must protect both while maintaining control over how data is accessed, used, and shared. This requires a platform approach that unifies threat protection and data security across all channels. 

Macro Shift: How AI Is Reshaping Cybersecurity 

How is AI fundamentally changing cybersecurity?

“AI is compressing time on both sides of the fight.” 

AI is accelerating attackers, enabling them to scale expertise and automate campaigns. It is also augmenting defenders by improving detection and response. At the same time, AI introduces agents as a new class of actors and increases data exposure. This shifts security from protecting infrastructure to protecting people, agents, and the data they interact with.

What are the challenges and opportunities with frontier AI models?

“Real-world threat intelligence is becoming the new competitive advantage.” 

Frontier AI models compress the time between vulnerability discovery and exploitation. Attackers can move faster, but defenders can also identify and fix risk earlier. The challenge is the shrinking window between discovery and response. The organizations that win are the ones that can see threats sooner and act faster. 

Are traditional security controls obsolete with AI?

“Security is not being replaced. It is being redefined.” 

Traditional controls still matter, but they are no longer sufficient on their own. They must extend to identity, behavior, and data across humans, AI agents, and modern collaboration channels. 

Why is understanding attacker intent more important in the AI era?

“Signals tell you what happened. Intent tells you what happens next.” 

AI allows attackers to constantly change tactics, which makes static indicators less effective. Understanding intent requires analyzing behavior across users, agents, and data to detect when activity does not match expected patterns. That is how organizations move from reacting to predicting. 

Risk Layers: Data, Agents, and Social Engineering

What is the single biggest security gap created by AI agents? 

“AI does not create new risk. It exposes the risk you already have.” 

The biggest gap is uncontrolled access to data. AI agents operate at speed and scale, often with broad permissions. Without strong data governance, they can expose sensitive information faster than traditional controls can respond. 

What is the most urgent AI security risk for enterprises?

“Every AI system increases the surface area for data exposure.” 

The most urgent risk is data exposure. AI systems depend on access to large volumes of data, and each new agent expands the number of interactions with that data. Without strong controls, the risk of leakage and misuse grows quickly. 

Why is social engineering getting worse in the AI era?

“AI has made social engineering scalable.” 

Attackers can now generate highly personalized and convincing messages across email, voice, and collaboration tools at scale. What once required time and expertise can now be automated, increasing both the volume and effectiveness of attacks. 

How should companies think about prompt injection?

“Prompt injection is social engineering for AI agents."

Prompt injection is a new attack vector that manipulates how AI systems interpret and act on instructions. It should be treated like phishing, with controls focused on validating inputs, limiting data access, and detecting abnormal behavior.

How does data governance change in an AI-first enterprise? 

“If you do not understand your data, you cannot secure your AI.” 

Data governance becomes continuous and real time. Organizations need visibility into where data resides, who or what can access it, and how it is used across systems and agents. 

Execution: What CISOs Should Do

How should CISOs secure AI agents?

“If an agent can act for you, it must be secured like you.” 

CISOs should treat AI agents as high-speed, high-privilege identities. This requires strong identity controls, continuous monitoring of behavior, and strict governance of data access, along with the ability to detect when actions deviate from expected intent. 

How can organizations balance innovation and risk with AI?

“The goal is not to slow AI down. It is to make it safe to scale.” 

Organizations should enable AI with guardrails, not restrictions. That means embedding governance, data protection, and monitoring from the start so innovation can move forward without increasing unmanaged risk. 

Why are CISOs prioritizing platform consolidation right now?

“You cannot secure a modern environment with fragmented tools.” 

Fragmented security tools create blind spots and slow response times. Platform consolidation improves visibility, reduces complexity, and enables more effective defense across a rapidly expanding attack surface. 

Leadership Roles

What should boards and CEOs ask their security leaders about AI?

“AI risk is business risk.” 

Boards should ask where AI is accessing sensitive data, how AI agents are governed, how quickly threats can be detected and contained, and whether controls prevent data loss before incidents occur. Clear answers to these questions indicate whether the organization is prepared to manage AI risk. 

What is the CEO’s role in AI security?

“AI security is a leadership responsibility, not just a technical one.” 

The CEO must ensure that AI risk is treated as a core business issue. This includes setting priorities, aligning investment, and ensuring governance keeps pace with how quickly AI is being adopted. 

What is the most important leadership lesson for scaling in an AI market?

“AI security is a leadership responsibility, not just a technical one.” 

The CEO must ensure that AI risk is treated as a core business issue. This includes setting priorities, aligning investment, and ensuring governance keeps pace with how quickly AI is being adopted. 

Future of Security Operations

How is AI changing the SOC?

“The SOC is shifting from alert management to intelligence-driven operations.” 

AI is automating triage, accelerating investigations, and improving response times across large volumes of alerts. This allows security teams to focus on higher-value analysis and proactive defense.