Wednesday, August 19



Enterprise security: Then and now

For the last two decades, enterprise security focused on fortifying data protection at its source: the systems where it resides. Beginning with castle-and-moat network perimeter security in the early 2000s, additional layers have since been added with the rise of cloud-based and mobile systems that introduced new risks, like governance and compliance, advanced persistent threat (APT) detection and response, and zero trust technology.

But there is a crucial location that’s often overlooked, one where sensitive data resides with multiple stakeholders: contracts. Contracts are where obligations live. The MSAs, NDAs, vendor contracts, and indemnity clauses decide who carries the loss when something fails. They are no longer only a legal or operations team’s responsibility; security teams have an equal role to play. The challenge? That system was hardened for a threat model built on forgery and tampering, both paper and digital, not fake identities or autonomous software. The threat has evolved, but contract workflows are yet to catch up.

That gap is expensive. The contract layer is where two of the fastest growing risk categories of 2026—synthetic identity and ungoverned AI—intersect. For most of the last decade, the security case for e-signatures was straightforward. Tamper-evident, auditable, and immune to data loss, they simply beat paper outright. That argument still holds. What has changed is the adversary and the digital defense built against it.

The growing scale of ungoverned AI and identity fakes

IBM’s 2026 Cost of a Data Breach Report averages the organizational cost of a breach in India at an all-time high of ₹25.5 crore, a 15.9% jump over the previous year’s ₹22 crore, with 26% of the cause being malicious AI. The report also found that companies save nearly $2 million in adopting AI-led security measures when compared to companies that used limited or no AI in their security automation. Strangely, the prominent cause of cyberattacks in India still happens to be phishing.

That last detail matters more than it appears. Phishing is a curated workflow attack that succeeds through plausibility and negligence. Contracts are the easiest prey. Simply add a tweaked email address, a believable invoice for countersignature, and you’re under attack.

The scale is also fearsome. Deepfakes now account for one in five biometric fraud attempts, and vendor email compromise made up around 61% of such attacks. Attackers increasingly compromise a genuine vendor account rather than spoofing one because high-friction procurement environments make cheap impersonation fail.

The identity problem is also compounding from another direction. Recent reports found that AI agents and machine identities now outnumber human identities by 109:1 in the average enterprise.

Imagine this finding from a CISO’s perspective. Attackers have concluded that the most reliable way into a contracting process is to become a legitimate counterparty rather than imitate one. This means every control that verifies the email address, the domain, or the access link is now verifying the wrong thing. Contracts can no longer rely only on authentication; they need stronger identity verification.

Most e-signature platforms today only authenticate a session, not a person. A link lands in an inbox, and whoever opens that link, from whatever device, is treated as the named signatory. None of this establishes that the human applying the signature is the human named in the agreement. For low-value internal paperwork, that trade-off is understandable. For a ₹40-crore supply agreement or a loan document, it’s a blind spot that could land the company in a dispute.

AI agents already draft, summarize, and approve documents. Though whether an autonomous process can execute a signing action is no longer a question, most contract stacks struggle with its rightful governance. Research on identity governance in 2026 found that while 92% of companies agree that governing AI agents is critical to enterprise security, only 44% have implemented any policy to do so.

This has an added, slightly more invisible layer of challenge. Contract review is a near-perfect use case for large language models. It involves dense, repetitive, and structured text that nobody enjoys reading. That’s exactly why legal and commercial teams adopted AI for it early, often outside any approval or review. Now consider what gets pasted into an unsanctioned or unlimited context AI assistant during a negotiation. Pricing, exclusivity terms, counterparty personal data, and occasionally their confidential information—precisely material covered by an NDA the organization itself signed. 2026 CISO research asserts this further: 81% of CISOs worry their AI systems are not properly governed, but only 46% reported controlling those agents’ access to corporate data. Add to that unreported employee usage of personal AI accounts for contract workflows and it creates a complex security challenge. The most sensitive text they own has already left the perimeter, voluntarily, through a browser tab.

India’s compliance countdown is ticking

Indian enterprises have a hard date attached to solving this. The DPDP Rules 2025 have a full substantive compliance due by 13 May 2027. Two of its provisions land squarely on contract infrastructure. First, compliance responsibility rests with the Data Fiduciary even where processing is carried out by a Data Processor. Second, that responsibility extends to outsourced processors, cloud and SaaS tools, group companies, and shared service centers. The price of ungoverned AI usage and inadequate verification is thus hefty with the DPDPA.

Must-have properties of a defensible contract stack

A contract workflow that survives both an attacker and an auditor needs three inevitable properties:

1. Identity proofing at the point of signature: The signer should be bound to a government-verifiable credential: an Aadhaar-linked e-sign, a national eID, a verified government photo ID, not just someone who possess access to an inbox.

2. Signature assurance tiered to transaction risk: A leave application and a mulit-million cross-border agreement should not carry the same evidentiary weight. The platform must offer flexibility with types of e-signatures like SES, AES, and QES, and let policy decide which applies where.

3. AI that operates within the trust boundary: If document intelligence requires shipping contract text to a third-party model with unclear retention, context, processing, and residency terms, it is as good as a new risk exposure.

Platforms like Zoho Sign meet these requirements without compromising ease or speed of execution.Zoho Sign supports Aadhaar eSign and is legally valid as per the Information Technology Act, 2000 with no PII retention. Beyond India, Zoho Sign integrates with Stripe Identity, Didit, emdha, Singpass, and other vendors so recipients authenticate using their government-issued ID of choice without compromising on regional compliance.

Zoho Sign also offersall the tiers of digital signatures (SES, AES, and QES), and maps signature metadata in a tamper-free audit trail. High-risk categories are secure, routine paperwork does not get slowed down, and every action is audited.

On the AI front, Zoho Sign’s assistant handles summarization, key-term extraction, milestone and risk identification, and Q&A, pulling information from within the document’s context.

The architectural point is a security level up. Zoho owns and operates its own data centers, retaining direct oversight of customer data, and runs no ad-based revenue model anywhere in its business. Zia LLM is also deployed on Zoho’s own data centers and trained without using customer data. For a CISO writing a DPDP data-flow map, that collapses the hardest questions of where the text goes, who else processes it, and whether it trains anything.

The question remains

The security review of contract workflows cannot stop at encryption and access any longer. The right test is a single question, asked of any executed agreement: Can we prove that whoever signed this is who they claimed to be, and that no ungoverned system read or stored it on the way through?

Most organizations cannot answer both today. The ones that can will find that identity and AI governance close the distance at the end of a workflow that belongs on the CISO’s roadmap.

  • Published On Aug 19, 2026 at 10:10 AM IST

Join the community of 2M+ industry professionals.

Subscribe to Newsletter to get latest insights & analysis in your inbox.

All about ETLegalWorld industry right on your smartphone!




Source link

Share.
Leave A Reply

Exit mobile version