Writing

AIDevCon 2026: Why Security Tools Don't Stop Real Attacks

Second edition, second talk, and this time under my own name rather than a company's. On why alert-driven security misses the attacks that matter.

C Sarath Babu speaking at AIDevCon India 2026, presenting the Why Tools Fail slide

Second edition. Same venue, same conference, different name on the badge.

Last year I spoke as a DevSecOps engineer at Hysteresis. I have left since, so this time I went as founder of Gain and Shine.

C Sarath Babu's speaker card for AIDevCon India 2026, listed as founder of Gain and Shine
12 to 13 March 2026, NIMHANS Convention Centre.

The talk: Why Security Tools Don't Stop Real Attacks and How Teams Use AI Instead.

The deck

The whole presentation, if you want to go through it yourself:

Why Security Tools Don't Stop Real Attacks. AIDevCon India 2026.

The argument

Most security tooling is built around alerts and predefined rules. That works for known attacks and it fails at everything else.

C Sarath Babu at AIDevCon India 2026 presenting the Why Tools Fail slide, covering SAST, DAST, CVE scanners and alert fatigue
The slide the whole talk hangs on.

Four failure modes, and none of them are the tool being badly built:

  • SAST reads code. It does not understand your business logic.
  • DAST throws known payloads. A novel attack walks straight through.
  • CVE scanners need a CVE. A zero-day does not have one.
  • 10,000 alerts a day. Teams stop looking.

That last one is the real problem. Every tool in the stack is technically working, and the people are drowning in output nobody can triage.

The shift

The argument was for moving from alert-based detection to behaviour-based analysis, and using AI to do the part humans cannot: watch what is actually happening in a live production system and notice when it stops looking normal.

Applied to the places that get people breached in practice:

  • Identity systems and access control
  • Secrets management
  • Monitoring in real production environments, not staging
C Sarath Babu presenting at AIDevCon India 2026, on the Excessive Access section about over-admin rights nobody audited
Excessive access. Over-admin rights nobody audited, service accounts that needed one folder.

That excessive access section is the one people came up about afterwards. Every team has an account with far more permission than its job requires, granted once and never reviewed.

Satish

I did not do this one alone. My brother Satish came with me and was part of the presentation.

C Sarath Babu at AIDevCon India 2026 with his brother Satish, the speaker wall, and the memento thanking Sarath Babu C for sharing his knowledge
Satish, the speaker wall, and the memento.

Last year Imran stood at a door he had no pass for to take photographs. This year my brother was on the inside of it with me. That is a better year.

C Sarath Babu pointing at his own photograph on the AIDevCon India 2026 speaker wall
C Sarath Babu at AIDevCon India 2026, the Thank You Speakers screen listing 60 plus experts
60+ speakers this edition, up from 45+ last year.

The memento

Last year the organisers sent me off with goodies. This year it was not a gift.

A mounted gold medallion with stars, reading Thank You Sarath Babu C for Sharing Your Knowledge & Expertise at AIDevCon India, 2nd Edition.

C Sarath Babu's AIDevCon India 2026 speaker pass reading Sarath Babu C, Gain and Shine, on an EFY Group t-shirt
Speaker. Gain and Shine.

What changed

Last year I was nervous, spoke a little fast at the start, and settled into it.

This year I knew the room. Not because the room got smaller, but because doing a thing once removes most of the fear of doing it again.

The other change is on the badge. Last year it said a company's name under mine. This year it says my own.