
In this exclusive interaction with Catalyst, Sanjay Katkar, Co-Founder and Joint Managing Director of Quick Heal Technologies, reflects on the early days of India’s antivirus industry, the journey of building “Made in India, trusted globally” security platforms, and the responsibilities cybersecurity leaders carry as digital dependence deepens at population scale.
You built India’s first-generation antivirus at a time when cybersecurity wasn’t even a boardroom topic. What conviction kept you going when the market itself didn’t yet exist?
In the early 1990s, there was no cybersecurity market in India when we developed virus removal tools. There were no discussions around Cyber risk and digital safety. We witnessed customers with infected systems, lost data, and stopped working businesses.
My convictions come from something very basic. Many global antivirus products were too slow and were not designed for Indian conditions, and every new computer that entered India was infected. If we could understand these infections and fix them quickly, that itself had value, even if the market did not yet exist.
Quick Heal was first shipped on floppy disks without any consideration of scale, valuation, or an IPO. There was only one question that truly mattered: can this user return to work today? Whether it was a small business in Nashik or a bank branch in Pune, the problem was real and urgent.
Despite high piracy and low sales, the feedback from early users kept us going. Rather than numbers, it mattered when someone said Quick Heal had fixed an issue no other had been able to fix.
Gradually, this trust from Quick Heal users turned into a business.
Quick Heal and Seqrite didn’t just create products—they helped put India on the global cybersecurity map. What does building a “Made in India, trusted globally” security company truly take?
For me, Made in India is more than a slogan. It is a responsibility. In other words, a product built in Pune must meet the same standards as any product built globally in the cybersecurity field. Ideally, it should satisfy a CIO in Europe, a regulator in India, as well as an independent test lab anywhere in the world.
It is a challenging task that begins with ownership of the issue from beginning to end. We have always placed a high priority on deep research and product development in India. There was no intention of assembling or rebranding technology from elsewhere. With Seqrite Labs, our teams study real threats at scale and develop detection and response capabilities from scratch. This ensures that we truly own intellectual property.
I proudly add that Seqrite Labs is India’s largest malware analysis facility, processes telemetry from over 8 million endpoints and hundreds of millions of detections to train our engines like GoDeep.AI.
Most importantly, building global trust requires patience; you cannot rush credibility in cybersecurity.
Having studied threats across India’s diverse digital footprint, what unique cybersecurity challenges do Indian enterprises and governments face compared to global counterparts?
India’s cybersecurity challenge is very different from most global markets because of our digital technology adoption.
One side of this picture is occupied by large enterprises, banks, and PSUs as well as critical infrastructure using advanced technologies such as cloud, hybrid environments, and operational technology. In contrast, we have millions of small institutions and citizens who came online directly through their mobile phones, often without ever using a desktop or having received basic digital security training. As a result, the security landscape is very uneven. Most attacks still originate from older on-premises systems that have not been upgraded or patched regularly.
We are also seeing a rapid rise in cloud misuse, identity-based attacks, and social engineering attacks. In addition to digital payments, identity systems, and local languages, many attacks are designed specifically for Indian users.
Our India Cyber Threat Report 2026 reveals 265.52 million detections in 2025, with Trojans, file infectors, and worms dominating. In addition, there is a surge in cryptojacking and AI-assisted phishing that specifically exploits UPI, Aadhaar, and vernacular social engineering.
Sector maturity is another challenge. Education, healthcare, and manufacturing are targeted because they run open networks, depend on legacy systems, and have limited security budgets. In many cases, basic controls like incident response, backups, and regular patching are still weak or inconsistent.
The real issue in India is not just the number of attacks, but the widening gap between how rapidly we have digitized and how slowly security practices have evolved.
As India digitizes at population scale, what kind of cyber warfare scenarios should we realistically be preparing for?
As India digitizes at a population scale, we need to think beyond cybercrime as just fraud or ransomware. Risks are becoming broader and more strategic.
Future cyberwarfare will not always look like a single large attack. Many small, coordinated actions will take place at the same time. This may include attempts to disrupt essential services, cause confusion, or undermine public trust in digital systems. At the same time, an attack may target power, transport, healthcare, financial systems, or government platforms, using a combination of old vulnerabilities and new technology.
Artificial intelligence is one of the most important trends we are already witnessing in cyber-attacks. This includes automated reconnaissance, very convincing phishing messages, and deep-fake-based misinformation aimed at specific individuals or groups. In addition to stealing data, these attacks create doubt and confusion.
Another major risk comes from supply chain weaknesses. When attackers compromise one trusted system or vendor, they can gain access to many organizations at once. The impact is wider and harder to control.
Preparing for these scenarios requires more than reacting to an incident. The key is to build strong threat intelligence, test our defences regularly through drills and simulations, and improve coordination between government agencies, enterprises, and security providers. Cybersecurity at this scale is not just about protection. We need to maintain trust and ensure continuity in a digital society.
What responsibility do cybersecurity leaders carry today, not just to customers, but to society at large, as digital dependence deepens?
Leaders of cybersecurity organizations today are responsible for more than just customers or contracts. Since digital systems are becoming increasingly common in banking, healthcare, education, and governance, we are custodians of digital trust.
It is our responsibility to build secure, reliable, and simple products. Users should be protected without fear. Risk communication is just as important as technical solutions.
We also have a duty to work closely with regulators and policymakers. Innovation, privacy, and long-term resilience should be balanced rather than compliance viewed as a checkbox exercise.
Another significant responsibility is building awareness and capability. India’s digital future depends on how well we prepare our people. That means creating opportunities for young talent from Tier two and Tier three cities, spreading cyber awareness in local languages, and investing in practical education. Through initiatives like Cyber Shiksha for Cyber Suraksha and the Quick Heal Academy, we focus on skilling, awareness, and hands-on learning. This is so that more people can take part in the digital economy.
Cybersecurity cannot be viewed only as a business. It protects trust, enables inclusion, and keeps society functioning smoothly in a digital world.
If you were to build Quick Heal from scratch today, what would you do differently in a world dominated by cloud, AI, and zero trust?
Even if I were building Quick Heal from scratch today, the core philosophy would remain the same. Solve real problems deeply, particularly in the context of India.
What would change is how we build and sequence things. Today, I would design the company as a cloud native platform from day one. Instead of thinking only about the endpoint first, I would start with data and visibility. To learn continuously from real world threats, I would collect telemetry across endpoints, networks, cloud workloads, and identities.
Additionally, I would invest in managed security services much earlier. A large number of mid-sized organizations and public sector organizations do not have large security teams. They want outcomes, not tools. From the very beginning, detection, response, and monitoring would be a priority.
From a market perspective, I would build global partnerships early, while keeping core research and product development rooted in India. Today, it is imperative to combine global collaboration with local depth.
As a result, the mission would remain unchanged. Ensure that users and organizations are protected from real threats. However, the foundation would be cloud-based, AI-based, and identity-focused from the very beginning.
What is your boldest vision for Quick Heal and Seqrite’s role in the global cybersecurity ecosystem by 2030?
By 2030, my vision is that Quick Heal and Seqrite are seen not only as successful Indian companies, but as trusted contributors to global cybersecurity.
I would like us to be known for building intelligent security systems that prevent attacks at scale, not just react to them. Our focus will be on using AI and deep research to reduce risk for millions of users, enterprises, and public institutions across different parts of the world.
Another key part of the vision is our contribution. Seqrite Labs should play a meaningful role in global threat research and intelligence sharing, especially around risks that affect emerging economies. Western markets are often at the center of global security discussions. I believe India and the Global South have valuable perspectives that need to be heard.
In addition, we strive to be a trusted partner for governments and regulated industries that are concerned with security, sovereignty, and long-term resilience, while remaining interoperable globally.
If by 2030, engineers working from cities like Pune or other parts of India are quietly helping protect critical systems across continents, and doing it with integrity and depth, that would be a legacy worth building.
Looking Ahead
As India’s digital footprint expands at unprecedented scale, cybersecurity is emerging as a matter of national trust, economic resilience, and societal stability. The path forward demands more than reactive defences—it calls for deep research, indigenous innovation, responsible use of AI, and close collaboration between industry, government, and academia. Organisations that balance global standards with local context, invest in skills and awareness, and focus on prevention rather than response will be best positioned to secure the future. In this journey, cybersecurity stands not merely as a technology function, but as a foundational enabler of confidence, inclusion, and continuity in an increasingly digital world.
All Content Rights Reserved by Catalyst.








