When global leaders gather in New Delhi for the BRICS Summit 2026, security will extend far beyond the visible layers of police deployment, protected routes, restricted zones and surveillance systems. Behind that physical security operation is a much larger digital environment connecting government infrastructure, official websites, communication systems, cloud platforms, applications, identity services, networks, endpoints and third party systems. Every one of these components can become an entry point for an adversary, and unlike a physical perimeter, a digital perimeter can be probed from anywhere in the world within seconds.
That makes cybersecurity a fundamental part of protecting a major international summit. A successful cyberattack does not necessarily have to steal classified information to create strategic consequences. An adversary could disrupt an official website, compromise an administrator account, manipulate information, conduct reconnaissance, harvest credentials, compromise a supplier or quietly establish persistent access to an important system. The challenge for Indian cybersecurity agencies is therefore not simply to block attacks, but to maintain confidentiality, integrity, availability and operational resilience across an environment that becomes exceptionally attractive to threat actors during a high profile geopolitical event.
The experience of the G20 Summit provides an important reference point. Reporting by The420.in described an enormous volume of malicious traffic targeting India’s digital infrastructure during the 2023 G20 event, including millions of attempted attacks within a minute against the official website. The reported response involved coordination among agencies including the Indian Cybercrime Coordination Centre, CERT In and the National Informatics Centre. The significance of that experience is not simply the size of the traffic. It demonstrates how a globally visible event can attract automated, distributed and persistent attempts to identify weaknesses in public facing infrastructure.
Multi Layered Cyber Defence
Every layer adds another opportunity to detect, stop and contain the attack.
and reconnaissance
and exposed services
and absorption
API protection
and Zero Trust
network detection
hunting and context
automated response
BRICS creates a uniquely attractive cyber target
International summits create a particularly valuable combination for attackers. There is a defined period of heightened activity, enormous international attention, a large number of participants and extensive dependence on digital infrastructure. Official portals, registration systems, media platforms, email accounts, mobile applications, hotel and transportation systems, temporary networks and third party technology providers can all become part of the broader attack surface. An attacker does not necessarily need to compromise the core government infrastructure if a less protected connected system can provide useful intelligence, credentials or an opportunity for disruption.
The motivation can also vary considerably. Hacktivist groups may seek visibility by launching denial of service attacks, financially motivated criminals may attempt credential theft or fraud, and state aligned actors may be more interested in intelligence collection and long term persistence. These objectives require different techniques, but they can overlap within the same campaign. A noisy DDoS attack may attract attention while a much quieter credential theft operation proceeds elsewhere, which is why security teams need to distinguish between visible disruption and covert compromise.
This changes the central question from “Can the website withstand an attack?” to “Can the entire digital ecosystem detect, contain and recover from an attack?” That is a much harder cybersecurity problem. It requires multiple defensive layers operating simultaneously, with telemetry moving between them so that an apparently isolated event can be correlated with activity elsewhere in the environment.
The first challenge is knowing what needs to be protected
Before an organization can defend its infrastructure, it needs an accurate understanding of its attack surface. For a major international event, that can be surprisingly difficult because infrastructure may be distributed across government data centres, cloud environments, content delivery networks, third party providers and temporary systems created specifically for the event. Domains and subdomains can appear quickly, applications can be deployed by different teams and APIs can expose services that are not obvious from the public website.
Attackers routinely perform reconnaissance before launching an intrusion. They can examine DNS records, certificate transparency data, publicly exposed services, application behaviour, technology fingerprints and internet accessible infrastructure to build a picture of the target environment. An abandoned subdomain pointing to an old cloud resource, an exposed administrative interface or an outdated application can become more valuable to an attacker than a heavily protected primary website.
This is why external attack surface management is increasingly important. Security teams need continuous visibility into internet facing assets, open ports, exposed services, certificates, APIs, cloud resources and third party dependencies. Asset discovery cannot be treated as a one time inventory exercise, particularly during an event where infrastructure can change rapidly. An asset that was not present during the initial security assessment can become part of the attack surface days or even hours before the event.
DDoS defence starts before malicious traffic reaches the application
Distributed denial of service remains one of the most straightforward ways to disrupt a highly visible digital service. Attackers can use large numbers of compromised devices or rented infrastructure to generate traffic designed to exhaust network bandwidth, overwhelm connection tables or consume application resources. At the network and transport layers, this may involve volumetric floods or protocol abuse. At the application layer, however, an attack can be much more difficult to identify because the requests may look similar to legitimate user activity.
A sophisticated application layer attack might repeatedly request resource intensive operations rather than simply sending enormous volumes of traffic. For example, an attacker could distribute requests across thousands of sources and target expensive search, authentication or API functions. Traditional volume based filtering may not detect such activity effectively because individual requests can appear normal even though their combined behaviour is malicious.
A resilient architecture therefore needs several controls working together. DNS security, traffic profiling, distributed denial of service mitigation, content delivery networks, rate limiting and application aware filtering can absorb or discard malicious traffic before it reaches the origin infrastructure. The objective is not simply to block as much traffic as possible. During a major international event, legitimate traffic can also increase dramatically, so defensive controls need to distinguish malicious automation from genuine demand without disrupting legitimate visitors.
The Web Application Firewall is only one part of application security
A Web Application Firewall provides an important defensive layer by inspecting HTTP and HTTPS traffic and identifying patterns associated with attacks such as SQL injection, cross site scripting, path traversal, command injection and malicious requests. It can also enforce rules around request size, known attack signatures, suspicious methods and other application behaviours. For a public facing government application, this provides an essential barrier between the internet and the underlying application infrastructure.
However, modern attackers increasingly look for ways around signature based controls. They can manipulate encoding, distribute malicious activity across many requests, exploit application logic or abuse legitimate functionality. A request can therefore be completely valid from an HTTP perspective while still being malicious from a business logic perspective.
Consider an authenticated API request made with legitimate credentials. A WAF may see a correctly formed request and allow it. But if the account suddenly accesses hundreds of sensitive records, changes privileges or begins querying resources it has never previously accessed, the activity may indicate account compromise. Detecting that requires correlation between WAF telemetry, API activity, identity analytics and user behaviour rather than relying on a single security control.
APIs have become a critical attack surface
Modern digital infrastructure is increasingly API driven. The visible website is often only the presentation layer, while authentication, registration, content management, data retrieval and administrative functions are handled through backend APIs. These interfaces can therefore expose significant functionality even when the primary web application appears well protected.
API security needs to address authentication, authorization, input validation, rate limiting, schema enforcement, token management and sensitive data exposure. One particularly important risk is broken object level authorization, where an application correctly verifies that a user is authenticated but fails to determine whether that user is actually authorized to access a particular object or record. In such circumstances, an attacker may not need to bypass authentication at all. They may simply manipulate a legitimate request to access information belonging to another user or system.
API discovery is equally important. Organizations frequently have undocumented, legacy or shadow APIs that are not included in formal application inventories. Security teams therefore need visibility into actual API traffic rather than relying entirely on documentation. During a major event, this becomes especially important because temporary integrations and new applications can introduce additional interfaces into an already complex environment.
Identity is now one of the most important security boundaries
The traditional idea of a network perimeter has changed substantially. Cloud services, remote access, mobile devices, third party integrations and distributed workforces mean that users and devices can connect from almost anywhere. As a result, identity has become one of the most valuable targets for attackers and one of the most important defensive layers for security teams.
Administrators, developers, government officials, contractors and technology vendors can all possess credentials that provide access to sensitive systems. Attackers can target those credentials through phishing, password spraying, malware, session theft and social engineering. Once a legitimate account has been compromised, the attacker may be able to operate inside the environment while generating activity that initially resembles normal user behaviour.
Strong multifactor authentication, privileged access management, least privilege, conditional access and continuous risk assessment can significantly reduce this exposure. More importantly, security teams need to evaluate context rather than treating successful authentication as proof that an activity is trustworthy. The device, location, access pattern, resource being requested and behaviour associated with the session can all contribute to determining whether an otherwise valid login represents legitimate activity or potential compromise.
Phishing becomes more convincing during a major geopolitical event
A major summit also creates an ideal environment for social engineering because employees and participants have legitimate reasons to receive sensitive communications. Invitations, schedules, travel documents, meeting links, security instructions and operational updates all create opportunities for attackers to imitate trusted organizations. A well crafted phishing message does not need to look obviously malicious if it arrives at exactly the moment when the recipient expects similar communication.
Generative AI makes this problem more difficult by reducing the effort required to create convincing and personalized content. Attackers can generate professionally written messages, translate them into different languages and tailor them to particular individuals or organizations. They can also combine publicly available information with stolen data to make fraudulent communications appear more credible.
The initial payload may be a malicious document, credential harvesting page, fake application or link to an attacker controlled service. Once credentials or a session token are obtained, the attacker can move away from the original phishing channel and begin operating through legitimate services. This is why email security alone cannot provide sufficient protection. Identity monitoring, endpoint detection, authentication analytics and user awareness need to operate as part of the same defensive architecture.
Endpoint security assumes that prevention will eventually fail
Traditional antivirus remains useful, but modern incident response requires considerably more visibility into endpoint behaviour. Endpoint Detection and Response systems can record process execution, command line activity, file changes, persistence mechanisms, network connections and other events that help analysts understand what happened on a compromised machine.
A suspicious endpoint might launch PowerShell unexpectedly, access credential stores, create scheduled tasks, establish persistence or communicate with an unusual external destination. None of these events necessarily proves that malware is present in isolation. Their sequence and relationship, however, can reveal a much stronger indication of compromise.
This is the fundamental difference between file focused detection and behavioural detection. Instead of asking only whether a particular file is known to be malicious, security teams can investigate what a device is doing, which accounts it is using, what systems it is contacting and how its behaviour differs from its established baseline. That context becomes critical when dealing with targeted attacks involving previously unseen malware or legitimate administrative tools.
Network visibility is essential for detecting lateral movement
Initial access is often only the beginning of an intrusion. Once an attacker compromises an endpoint, they may attempt to discover other systems, obtain additional credentials and move toward higher value assets. This process, commonly referred to as lateral movement, can transform a single compromised device into a broader enterprise intrusion.
Network telemetry can provide important evidence during this stage. Security teams can investigate unusual east west traffic, unexpected remote administration, abnormal DNS requests, new external destinations, suspicious authentication patterns and unusual data transfers. Network segmentation provides an additional layer of protection by limiting which systems can communicate with each other.
The principle is straightforward: compromise should not automatically provide reach. If an employee workstation can communicate freely with sensitive servers, identity infrastructure and administrative systems, a single endpoint compromise can have a much larger impact. Proper segmentation, access control and monitoring reduce that blast radius and make lateral movement more difficult.
Zero Trust reduces the consequences of compromised credentials
Zero Trust is often described as a security model in which no user, device or application is automatically trusted simply because it exists inside a network boundary. The practical implementation involves continuously evaluating access based on identity, device security, resource sensitivity, context and risk.
For high value summit infrastructure, that approach is particularly relevant. A user who normally accesses one application should not automatically receive access to unrelated systems. A vendor account should not retain unnecessary administrative privileges after its task is complete. A device that becomes non compliant should not continue to receive unrestricted access simply because it authenticated successfully earlier.
The objective is not to eliminate trust entirely. It is to make trust conditional, limited and continuously evaluated. That reduces the value of stolen credentials because possession of a username and password is no longer sufficient to unlock every connected system.
Threat intelligence provides the context behind an alert
Large security environments generate enormous amounts of telemetry. The difficult problem is determining which events represent meaningful threats. Threat intelligence helps provide context by connecting observed indicators and behaviours with known malicious infrastructure, campaigns, malware families and adversary techniques.
Indicators such as IP addresses, domains, URLs and file hashes can be useful, but they can also have a limited lifespan. Attackers can change infrastructure, rotate domains and modify malware relatively quickly. Behavioural intelligence can therefore provide greater durability. Understanding how an adversary performs reconnaissance, establishes persistence, escalates privileges, moves laterally and exfiltrates information can help defenders identify attacks even when the exact indicators have changed.
Frameworks such as MITRE ATT&CK are useful in this context because they allow observed activity to be mapped against known adversary tactics and techniques. Instead of treating an isolated PowerShell execution or unusual credential access event as a standalone alert, analysts can examine whether multiple behaviours form a sequence consistent with a broader attack pattern.
SIEM and XDR bring the signals together
A Security Information and Event Management platform can aggregate logs and telemetry from firewalls, WAFs, endpoints, authentication systems, VPNs, cloud services, applications, network infrastructure and other security controls. The real value comes from correlation. An individual failed login may be insignificant, but a failed login followed by successful authentication from an unusual device, privilege escalation, access to sensitive resources and an outbound data transfer tells a very different story.
Extended Detection and Response can complement this approach by bringing together security signals from multiple domains. Instead of investigating endpoint, identity, network and application activity in isolation, analysts can construct a broader timeline of an incident. That reduces investigation time and makes it easier to understand the attack chain.
For a major international event, this correlation becomes particularly valuable because attackers may deliberately distribute their activity across multiple systems. One control may see the authentication anomaly, another may observe suspicious endpoint behaviour and another may identify unusual network traffic. Without centralized analytics, these signals can remain disconnected.
Automation can shorten the distance between detection and containment
Security Operations Centres cannot manually investigate every event generated by a large digital environment. Security Orchestration, Automation and Response can therefore automate selected investigative and containment activities, particularly when the confidence level is high.
For example, a confirmed malicious domain could trigger a workflow that searches historical telemetry, identifies affected endpoints, blocks further communication, opens an incident and alerts an analyst. A compromised account could potentially be disabled automatically when multiple high confidence indicators indicate account takeover. Endpoint isolation can also be automated in carefully defined circumstances.
Automation must, however, be implemented with discipline. An incorrect automated decision can disrupt legitimate operations at exactly the wrong moment. Confidence thresholds, human approval for high impact actions, detailed audit trails and rollback procedures are therefore essential. The objective is not to remove humans from the security process. It is to give skilled analysts more time to focus on complex decisions.
The supply chain creates another layer of risk
The digital infrastructure supporting a major international event will rarely be operated by one organization alone. Cloud providers, telecommunications companies, application developers, managed service providers, security vendors, contractors and other technology partners can all have some level of connectivity or operational involvement.
That creates a supply chain security problem. An attacker may decide that attacking a heavily defended primary environment is inefficient and instead target a smaller supplier with weaker security controls. A compromised vendor account, remote administration tool or software dependency can potentially become a bridge into a more valuable environment.
Third party access should therefore be governed by least privilege, strong authentication, segmentation and continuous monitoring. Organizations should understand exactly which vendors can access which systems, why that access exists and how quickly it can be revoked. Software and service dependencies also need to be included in the broader attack surface assessment rather than treated as somebody else’s security responsibility.
Incident response determines whether detection becomes resilience
No credible cybersecurity architecture can guarantee that every attack will be prevented. The real measure of maturity is what happens after an attacker succeeds in reaching part of the environment.
An effective incident response capability needs clearly defined authority, escalation procedures, forensic processes and communication channels. Security teams must know who can isolate a system, disable an account, block infrastructure, preserve evidence and authorize recovery. They also need the ability to reconstruct the timeline of an attack and determine whether the adversary achieved persistence or accessed sensitive information.
Tabletop exercises are particularly valuable before a high profile event because they expose weaknesses in decision making rather than merely technical controls. Teams can rehearse scenarios involving DDoS attacks, stolen administrator credentials, compromised suppliers, website defacement, malicious applications and suspicious data transfers. The objective is to ensure that the organization does not have to invent its response process in the middle of a crisis.
Cybersecurity cooperation is becoming part of geopolitical security
The BRICS cybersecurity challenge extends beyond protecting one country’s infrastructure. The interconnected nature of modern attacks means that malicious infrastructure, compromised accounts and command and control systems can span multiple jurisdictions. An attacker targeting an Indian system may use infrastructure located elsewhere, compromise a third party in another country and exploit cloud services operated across several regions.
India’s broader BRICS agenda reflects this growing relationship between cybersecurity and geopolitical security. During meetings with National Security Advisors and senior security officials from BRICS countries in June 2026, Prime Minister Narendra Modi emphasized cooperation in areas including terrorism, cybersecurity and emerging technologies. India’s BRICS communications agenda has also identified cybersecurity and trustworthy information and communications technology among its priority areas.
This cooperation matters because cyber defence increasingly depends on information sharing, threat intelligence, coordinated response and common approaches to emerging technologies. A sophisticated cyber campaign does not stop at a national border, so defensive collaboration cannot stop there either.
What enterprises should learn from the BRICS cyber defence model
The lessons from a major international summit apply well beyond government. Financial institutions, large enterprises, technology companies, critical infrastructure operators and organizations running high visibility events face many of the same challenges. Their environments may be smaller than a national summit infrastructure, but the underlying attack techniques remain similar.
The first lesson is to maintain continuous visibility of the attack surface rather than relying on an annual assessment. The second is to build defence in depth across network, application, API, identity, endpoint, cloud and data layers. The third is to assume that credentials and individual security controls can eventually be compromised, and therefore design the environment so that a single failure does not automatically become a catastrophic breach.
The final lesson is resilience. Prevention is important, but organizations also need rapid detection, intelligent correlation, disciplined containment and tested recovery procedures. A mature security operation does not measure success solely by the number of attacks blocked. It measures how quickly it can recognize meaningful threats, how effectively it can limit their movement and how reliably it can restore normal operations.
The invisible security operation
The physical security surrounding the BRICS Summit will be visible to everyone watching the event. The cyber defence operation will be almost entirely invisible, operating across networks, identity platforms, applications, cloud environments, endpoints and security operations centres.
That invisible layer may face attacks that are noisy and obvious, such as DDoS campaigns, but it must also defend against threats that are deliberately quiet. Credential theft, reconnaissance, supply chain compromise, privilege escalation and data exfiltration can all occur without producing the kind of disruption that immediately attracts public attention.
That is why the most important concept in summit cybersecurity is not a single firewall, WAF, SIEM or endpoint platform. It is the integration of multiple defensive layers into a system capable of seeing the attack surface, understanding behaviour, correlating signals and responding before an isolated compromise becomes a wider incident.
The BRICS Summit therefore represents more than another high profile cybersecurity exercise. It demonstrates how geopolitical events are increasingly dependent on digital resilience. The physical perimeter may determine who can enter a building, but the digital perimeter determines what an attacker can reach, manipulate or disrupt from thousands of kilometres away.
How Gurucul Helps Secure High Value Events Against Evolving Cyber Threats
A multi layered defence strategy becomes significantly more effective when the telemetry generated across those layers can be brought together, analyzed in context and converted into actionable risk. This is where Gurucul fits into the architecture. Rather than replacing every individual security control at the perimeter, Gurucul can provide the analytics, behavioral detection, threat investigation and response layer that connects activity across identity, endpoints, networks, applications and security infrastructure.
🔐 Identity: Detecting Identity Based Threats
Identity is one of the most important layers in the modern attack surface because compromised credentials can allow attackers to operate through legitimate channels. Gurucul Identity Analytics provides capabilities including risk based authentication, access analytics, role and entitlement analysis, segregation of duties intelligence and risk based access certification. Gurucul also offers Gurucul Identity Threat Detection and Response (ITDR), which focuses specifically on detecting and responding to identity based attacks, including compromised, over privileged, rogue and orphaned accounts.
For a high value environment such as a major international summit, this layer can help security teams move beyond simply asking whether a user successfully authenticated. Behavioral and identity context can help determine whether the account’s activity is consistent with its established pattern, whether privileges are excessive and whether authentication or access behaviour represents elevated risk.
⌁ EDR + NDR: Connecting Endpoint and Network Behaviour
Endpoint and network controls generate some of the most valuable evidence during an active intrusion. A compromised endpoint may exhibit unusual processes, authentication activity or communications, while network telemetry can reveal reconnaissance, lateral movement or connections to suspicious infrastructure. Gurucul Open XDR is particularly relevant here because it is designed to ingest, enrich, normalize and analyze telemetry across security and non security sources, while providing unified detection and response across existing security technologies.
This makes Gurucul complementary to existing EDR and NDR technologies rather than requiring organizations to replace those controls. Endpoint, network, identity and other telemetry can be brought into a broader analytical context, allowing analysts to investigate whether apparently separate events are actually components of the same attack campaign.
◉ SIEM + Threat Intelligence: Turning Signals into Threat Context
This is one of the strongest connections to Gurucul. Gurucul Next Gen SIEM provides centralized security analytics across cloud, network, endpoint, identity and application data, while built in UEBA analyzes user and entity behaviour to identify unusual patterns and assign risk.
Gurucul’s threat research capability further strengthens this layer. Gurucul Threat Research Labs combines external intelligence, threat research, threat hunting and data science to develop detection content, threat hunting queries, indicators and countermeasures. This allows raw telemetry to be enriched with knowledge about adversary tactics, techniques and indicators, helping analysts move from isolated alerts toward a broader understanding of the attack.
⚡ SOC + SOAR: From Detection to Automated Response
The final and perhaps most important connection is the transition from detection to action. Gurucul SOAR provides automated response workflows and playbooks that can integrate with downstream security technologies to block, disable or isolate risky users and entities. Its capabilities include contextual incident investigation, automated data collection, threat hunting and targeted containment.
This creates the final loop in the security architecture: telemetry is collected, suspicious behaviour is detected, risk is prioritized, the incident is investigated and appropriate response actions can be orchestrated. Gurucul’s broader Threat Detection, Investigation and Response platform brings these capabilities together across SIEM, UEBA, SOAR and data optimization, providing a unified approach to threat detection, investigation and response.
Where Gurucul Complements the Other Layers
The important distinction is that DDoS + Edge, WAF + API and the initial DNS/attack surface controls should not be presented as Gurucul products unless a specific Gurucul offering directly provides that capability. Those controls perform important preventive functions at the perimeter and application layers. Their telemetry, however, can become valuable security data for the broader detection and response architecture.
The new security perimeter is digital. And defending it requires more than preventing attacks. It requires the ability to see the signal, understand the threat, contain the intrusion and keep operating when the attack arrives.

