SG Sunil Gentyala
Contact
IEEE Senior Member · AI, Agentic Security & Post-Quantum Cryptography Research

Sunil Gentyala

Twenty years in enterprise security teach you something certifications alone never will: the distance between a well-designed control and a resilient one is measured not in policy documents, but in decisions made under pressure, at scale, with incomplete information. That gap is where Sunil Gentyala's career has lived.

He is Lead Cybersecurity and AI Security Consultant at HCLTech, where he manages offshore and onshore resources spanning multi-cloud security (Azure, AWS, GCP), enterprise identity and access management, application security, and AI/ML security for Fortune 500 clients including Uber, Disney, and Royal Caribbean. He serves as HCLTech's designated expert representative to the Cloud Security Alliance.

As a scholarly researcher, his agentic AI security work has moved from internal tooling to externally cited reference material. AegisSwarm-Core, his zero-trust governance framework for autonomous multi-agent AI networks, was published by the Cloud Security Alliance and has been cited independently — including by security researcher Asaf Nakash as "one of the few serious attempts to contain coordinated multi-agent systems." His broader agentic AI portfolio spans the GSH Framework (Governed Security Hunting, threat hunting mapped to MITRE ATLAS and NIST CSF 2.0), TRACE-MAS (cryptographically secured multi-agent LLM pipelines), ARGUS (autonomous LLM vulnerability discovery), PRAVAL (agentic vulnerability assessment), and CausalNetTwin (causal digital-twin reasoning for network security) — alongside scholarly work on agentic AI governance published in the ISACA Journal and analyzed in CIO.com.

His post-quantum and quantum-adjacent security research addresses the migration problem enterprises are only beginning to confront. QuantumShieldEdge is a hybrid QKD-integrated federated learning framework for secure consumer IoT at the network edge (target venue, IEEE CCNC 2027), demonstrating 85.2% accuracy under 20% Byzantine participation versus 71.4% for vanilla FedAvg. ContextGuard-MCP-PQC, approved by IEEE ICSCSA 2026 and pending publication on IEEE Xplore once the conference concludes, applies RFC 9794's PQ/T hybrid terminology to Model Context Protocol across four security layers, hardening handshakes with hybrid ML-KEM/ML-DSA constructs against harvest-now-decrypt-later and downgrade attacks. His SC World analysis of enterprise post-quantum HTTPS migration is paired with hrpq-gap-scan, an open-source tool auditing HRPQ preload and cookie-scoping downgrade gaps. His research also extends into gate-based quantum computing itself: with Floriano Caprio, Matteo Tortora, and Paolo Soda, he co-authored a CIBB 2026 paper applying the Quantum Approximate Optimization Algorithm (QAOA) to clinical risk factor selection, executed on a 54-qubit superconducting quantum processor.

His research spans adversarial machine learning, MCP vulnerability analysis, post-quantum cryptography, and agentic AI governance. He holds over 20 years of enterprise PKI and security architecture experience and has published across CSO Online, Dark Reading, SC World, Cyber Defense Magazine, and BiometricUpdate.com. He holds a #FoundryExpert designation across IDG/Foundry publications (CSO Online, CIO.com, Computerworld) and has been featured on Decoded: The Cybersecurity Podcast.

He is an IEEE Senior Member (No. 101760715, ORCID: 0009-0005-2642-3479), active ISACA Professional Member (ID: 2297870), MBCS (British Computer Society, Professional Member No. 995177441), an ACM Professional Member (No. 6835079), a CIISec Affiliate (Chartered Institute of Information Security, No. 220270), and is pursuing IET Fellowship (FIET).

RESEARCH FOCUS
Agentic AI Security Offensive & Defensive AI Security Post-Quantum Cryptography Zero-Trust Architecture MCP Security Adversarial Machine Learning Quantum Key Distribution Quantum Optimization (QAOA) AI Governance Zero-Knowledge Proofs
20+
Years of security experience
15
Research publications
26
Industry articles
13
Cross-media citations

▣Featured Research & Projects

ContextGuard
Zero-trust middleware framework for Model Context Protocol (MCP) security.
GSH Framework
Governed Security Hunting: agentic AI threat hunting mapped to MITRE ATLAS and NIST CSF 2.0.
AegisSwarm-Core
Zero-trust governance for autonomous multi-agent AI networks. Published by the Cloud Security Alliance, cited externally as a reference implementation.
SybilShield-Core
Composite trust scoring framework for Sybil attack mitigation in permissionless blockchain networks.
CADLP
Context-aware DLP proxy that detects and redacts credentials, PII, and proprietary code before prompts reach external LLM APIs.
TRACE-MAS
Unified cryptographic framework securing multi-agent LLM pipelines against drift, spoofing, and prompt injection.
CausalNetTwin
Causal digital-twin framework for network security reasoning, targeting IEEE INFOCOM 2027.
PRAVAL
Ten-phase agentic vulnerability-assessment framework, IEEE TrustCom 2026.
ZKP-RA
Zero-knowledge proof reasoning anchors mitigating memory poisoning in autonomous agentic DeFi. Groth16 zk-SNARKs, ~182ms proofs.
ArchForge
Open-source system design workbench with 60+ interactive patterns and a real-time capacity calculator.
DockerDNA
Layer-by-layer container security analysis — secrets detection, CIS Docker Benchmark compliance, SBOM, and SARIF output.
LaptopAI-Agent
Fully local, privacy-first autonomous AI agent — LangGraph reasoning loop, Ollama, ChromaDB RAG, MCP tool integration.
40+ open-source security and AI research projects in total — see the full list on GitHub.

◷Timeline

2026 September
Published Agentic Security Validation Framework for Retrieval-Augmented and Tool-Enabled Large Language Model Systems (ARGUS) — IEEE ICCVBIC 2026, DOI: 10.1109/ICCVBIC71195.2026.11689544, with a companion open-source implementation, ARGUS
2026 September
Admitted as Professional Member (MBCS) of the British Computer Society, No. 995177441
2026 September
Joined the Chartered Institute of Information Security (CIISec) as an Affiliate member, No. 220270
2026 September
2026 August
Reviewer-credited in Post-Quantum Cryptography Key Management — Cloud Security Alliance, published artifact of the CSA Cloud Key Management Working Group
2026 August
Published The Ghost Applications: How OAuth Client ID Spoofing Enumerates Microsoft Entra Accounts Without a Successful Sign-In — Cloud Security Alliance, companion to the CSO Online article above
2026 August
Completed second peer review for the European Journal of Computer Sciences and Informatics (EJCSI)
2026 July
Reviewer-credited in Navigating Identity and Access Management (IAM): Standards and Protocols — Cloud Security Alliance, published artifact of the CSA Identity and Access Management Working Group
2026 May
Quoted in Non-Stop Agentic AI Action Has Teams Assembling to Face the Threat — BiometricUpdate.com, on enterprise AI agent infrastructure security gaps
2026 April
🥉 Bronze — Cybersecurity Professional of the Year at the 2026 Cybersecurity Excellence Awards
2026 April
Shortlisted for Cyber Security Influencer of the Year at the Cyber Security Awards 2026
2026 April
Nominated for the Alan Turing Cyber Leadership Award at the National Cyber Awards — under expert judging panel review
2026 April
Published MCP security analysis at SC World on Model Context Protocol attack vectors and zero-trust mitigations
2026 April
Submitted multi-venue paper package — A Post-Quantum Migration Taxonomy for Model Context Protocol — to IEEE TIFS, ACM QSec, and Elsevier FGCS
2026 March
Expert commentary cited in Zscaler-SquareX Deal Boosts Zero Trust, Secure Browsing Capabilities — Dark Reading, on browser-centric zero-trust enforcement architecture
2026 March
CSA Peer Review completed — MLOps Key Activities, Cloud Security Alliance
2026 March
Published LLM Jailbreak Survey to Zenodo (DOI: 10.5281/zenodo.19241166) and SSRN
2026 March
Completed peer review for the European Journal of Computer Sciences and Informatics (EJCSI); registered on Web of Science / Publons
2026 March
GSH Framework reached v1.0.0-beta with full playbook set and CI workflow
2026 February
Published The Sentinel Intelligence: A CISO's Guide to Sovereign Security in the Age of AGI — Cyber Defense Magazine, introducing the SI architectural framework
2026 February
Published Why 2025's Agentic AI Boom Is a CISO's Worst Nightmare — CSO Online, on indirect prompt injection, memory poisoning, and agentic denial-of-service exploits
2026 February
CSA Peer Review completed — IAM Standards and Protocols
2026 February
CSA Peer Review completed — Post-Quantum Cryptography Key Management
2026 February
ContextGuard published at GitHub with v1.0.0-ieee-submission release tag
2026 April
Invited as peer reviewer at the Cyber Defense Review — peer-reviewed scholarly journal of the U.S. Army Cyber Institute at West Point — and completed review of a submitted manuscript the same month
2026 April
Joined ACM as a Professional Member, No. 6835079
2026 January
Submitted paper to IEEE SmartNets 2026 — Identity 3.0 and Zero-Trust for Critical Infrastructure, introducing the IMM-CI maturity model (EDAS ID 69662X)
2026 January
Elevated to IEEE Senior Member — No. 101760715
2025 December
Featured on Decoded: The Cybersecurity Podcast — Browser Zero Trust: Hardening Security Controls (41 min); also on Apple Podcasts
2025 December
Published Hardening Browser Security with Zero-Trust Controls — CSO Online, six-principle browser zero-trust framework with NIST SP 800-207 and CISA Maturity Model alignment
2025 December
Completed BCS Fellowship application (Experiential route)
2025 November
Published Beyond Silos: How DDI-AI Integration Is Redefining Cyber Resilience — CSO Online, on AI-driven predictive threat detection via DDI integration
2025 November
Submitted paper to IEEE QCE26 — Post-Quantum Zero-Trust Migration Framework (QZTMF), co-author John Martin (HCLTech Auckland), QNET track
2025 October
ISACA Journal article — Governing Agentic AI via MCP and COBIT 2019 / NIST CSF 2.0, co-authored with Praveen Kumar Mannam (Salesforce)
2025 September
Zero-trust data pipelines paper submitted to JRTCSE, co-authored with Sunil Kumar Mudusu (Church Mutual Insurance)
2025 July
Appointed as HCLTech designated expert representative to the Cloud Security Alliance

▤Publications

IEEE Xplore
A Multi-Stage NLP Framework for Enterprise Data Protection in Public LLM Interactions
Sunil Gentyala, Nimmagari Tejasri, Sunil Kumar Mudusu
IEEE ICIRCA 2026 — IEEE Xplore
SybilShield-Core: A Composite Trust Scoring Framework for Sybil Attack Mitigation in Permissionless Blockchain Networks
Sunil Gentyala, K Sanjeevaiah, Suresh Kumar Darisi
IEEE ICICDS 2026, Paper ID ICICDS-690 — DOI: 10.1109/ICICDS70526.2026.11604799
The Metamorphosis of Access: Strategic Imperatives for Identity 3.0 and Zero Trust Integration in Critical Infrastructure
Sunil Gentyala, Floriano Caprio, Sunil Kumar Mudusu, Suresh Kumar Darisi, Satish Kumar Allani
IEEE SmartNets 2026, EDAS #1571252869 — DOI: 10.1109/SmartNets69662.2026.11604842
A Zero-Trust Supply Chain Security Framework for Model Context Protocol-Based AI Systems
Sunil Gentyala, Ch. Srinivas, Raghu Dhumpati
IEEE ICCBI 2026 — DOI: 10.1109/ICCBI68589.2026.11619741
Agentic Security Validation Framework for Retrieval-Augmented and Tool-Enabled Large Language Model Systems (ARGUS)
Sunil Gentyala, N. Sudhakar Reddy, Kothapalli Chaitanya Deepthi, Pathapati Saroja, Kammara Venkatarangaiah Achari, Ruhisulthana Shaik
IEEE ICCVBIC 2026 — DOI: 10.1109/ICCVBIC71195.2026.11689544
A Post-Quantum Security Framework for Model Context Protocol Using ContextGuard
Sunil Gentyala, P. Krishna Sunil, Vamshi Lande, Akhila Kasturi, Suresh Kumar Darisi, Ruhisulthana Shaik
IEEE ICSCSA 2026, Paper ICSCSA-011 — approved, to be indexed on IEEE Xplore once the conference concludes (Aug 19–21, 2026)
A Unified Mathematical Framework for Secure Multi-Agent Large Language Model Pipelines (TRACE-MAS)
Sunil Gentyala, Y. Geetha Reddy, Manasa Pendyala, Vishnu Gatla, Sundarigari Manoj, Ruhisulthana Shaik
IEEE ICSCSA 2026, Paper ICSCSA-168 — accepted, conference Aug 19–21, 2026
CyberFuse-CI: Adversarially Resilient Vulnerability Detection Through Heterogeneous Multi-Source Data Fusion and LLM-Augmented Reasoning
Sunil Gentyala, Sunil Kumar Mudusu, Praveen Kumar Mannam
IEEE ICETCI 2026, EDAS #1571273793 — accepted, conference Aug 19–22, 2026
Governing Heterogeneous API Gateway Estates Through Policy-as-Code: An Engineering Management Perspective
Sunil Gentyala, Floriano Caprio, Praveen Kumar Mannam, Angajala Tejaswi, Rakesh Prakash, Akhila Kasturi
IEEE TEMSCON GLOBAL 2026, EDAS #145 (1571270844)
AdaptFlow: A Self-Optimizing AI-Driven Data Pipeline Architecture for Real-Time Inference at Scale
Sunil Kumar Mudusu, Sreepal Reddy Bolla, Sunil Gentyala
IEEE ICETM 2026, DOI: 10.1109/ICETM68138.2026.11648130
Temporal Probabilistic Modeling with Uncertainty-Aware LSTM Networks for Self-Aware Fault Detection and Prognostics in Autonomous Aerospace Systems
Rakesh Prakash, Soujanya Jagadeesh, Sunil Gentyala
IEEE MetroAeroSpace 2026, DOI: 10.1109/MetroAeroSpace69299.2026.11646653
Adaptive Neural Control for Multi-UAV Swarm Coordination: Trajectory Tracking, Collision Avoidance, and Wind Disturbance Rejection
Rakesh Prakash, Soujanya Jagadeesh, Sunil Gentyala
IEEE MetroAeroSpace 2026, DOI: 10.1109/MetroAeroSpace69299.2026.11646672
Other Peer-Reviewed Venues
Quantum-Assisted Clinical Risk Factor Selection for Diabetes Readmission Prediction
Floriano Caprio, Matteo Tortora, Paolo Soda, Sunil Gentyala
CIBB 2026 — Quantum Artificial Intelligence for Bioinformatics and Biostatistics track
Zero-Trust Data Pipelines for AI Systems: A Framework for Secure, Verifiable, and Auditable Data Engineering
Sunil Kumar Mudusu, Sunil Gentyala
JRTCSE, Vol. 14, No. 2, pp. 10–25 (Mar–Apr 2026) — DOI: 10.70589/JRTCSE.2026.14.2.2
On Auditing MCP Deployments
Sunil Gentyala, Praveen Kumar Mannam
ISACA Journal — in editorial review, 2026
13 conference papers accepted in 2026 (8 published on IEEE Xplore), plus journal work. See IEEE Xplore author profile and ORCID for the complete record.
See all publications on Zenodo, ORCID, and the IEEE Xplore author profile.

⚖Peer Review & Editorial Service

ARIIA 2026 — 2nd International Conference on Augmented Reality, Intelligent Systems & Industrial Automation
Dayananda Sagar University, Bengaluru — Taylor & Francis / Routledge proceedings, December 2026
IEEE ICETCI 2026 — International Conference on Emerging Techniques in Computational Intelligence
Mahindra University & École Centrale School of Engineering, Hyderabad — IEEE Computational Intelligence Society, August 2026
NEleX 2026 — 2nd International Conference on Next Generation Electronics
VIT Vellore — co-sponsored by IEEE Madras Section, ANRF, May 2026
IDEA 2026
Reviewed via Microsoft CMT, May 2026
IEEE ICTMOD 2026
EDAS-managed review, August-September 2026
BTS-I2C 2026 — 3rd Beyond Technology Summit on Informatics International Conference
EDAS-managed review, September 2026
The Cyber Defense Review
Peer-reviewed scholarly journal of the U.S. Army Cyber Institute, West Point, April 2026
IEEE Transactions on Information Forensics and Security
European Journal of Computer Sciences and Informatics
EJCSI, 2026 — registered on Web of Science / Publons
Cloud Security Alliance
Working-group artifact review — see Timeline for individual credits
35 manuscripts reviewed across 10 venues since late 2025, spanning IEEE-sponsored conferences, an EDAS/CMT-managed program, a U.S. Army Cyber Institute journal, and Cloud Security Alliance working groups.

✎Industry Articles

CSO Online
Sunil Gentyala
CSO Online, September 2026
Sunil Gentyala
CSO Online, August 2026
Sunil Gentyala
CSO Online, April 2026
Sunil Gentyala
CSO Online, February 2026
Sunil Gentyala
CSO Online, January 2026
Sunil Gentyala
CSO Online, December 2025
Sunil Gentyala
CSO Online, November 2025
Sunil Gentyala
CSO Online, October 2025
Cloud Security Alliance
Sunil Gentyala
Cloud Security Alliance, August 2026 — companion to the CSO Online article above
Sunil Gentyala
Cloud Security Alliance, June 2026
Sunil Gentyala
Cloud Security Alliance, April 2026
Sunil Gentyala
Cloud Security Alliance, March 2026
Sunil Gentyala
Cloud Security Alliance, January 2026
CIO
Sunil Gentyala
CIO, July 2026
Sunil Gentyala
CIO, June 2026
Sunil Gentyala
CIO, January 2026
Security Boulevard
Sunil Gentyala
Security Boulevard, June 2026
Sunil Gentyala
Security Boulevard, November 2025
Cyber Defense Magazine
Sunil Gentyala
Cyber Defense Magazine, April 2026
Sunil Gentyala
Cyber Defense Magazine, February 2026
SC World
Sunil Gentyala
SC World, July 2026
Sunil Gentyala
SC World, March 2026

🎙Media Coverage & Podcast Features

LinkedIn, CSO Online (official account), September 2026 — promoting his GenAI/LLM/RAG pen-testing guide; CSO Online editor Ed Murray engaged directly in the comments, asking how conventional AppSec testing should adapt to probabilistic LLM outputs without generating false positives
LinkedIn, Cloud Security Alliance (official account), August 2026 — CSA's own comment thanks its "subject matter reviewers who always help us improve our work," naming Sunil Gentyala directly alongside the review team
Dark Reading — expert commentary on browser-centric zero-trust enforcement architecture
BiometricUpdate.com, May 2026 — quoted on enterprise AI agent infrastructure security gaps and deployment risks
Decoded: The Cybersecurity Podcast, December 2025 (41 min) — full episode based on CSO Online article • Apple Podcasts
LinkedIn, Asaf Nakash — names AegisSwarm-Core directly as "one of the few serious attempts to contain coordinated multi-agent systems" • companion Spotify episode on Context Window: AI Security Podcast
Agentic Threat Tracker, 24 July 2026 — incident-tracker entry on the CSA "Securing the Swarm" analysis, names AegisSwarm-Core directly ("introduces AegisSwarm, a proposed open-source reference implementation for zero-trust multi-agent security")
LinkedIn newsletter, Mariano Mattei (Founder & Principal AI Architect, Mattei Systems), August 2026 — Executive Insight and Recommended Action sections built around the CSO Online OAuth client ID spoofing article
IIM Calcutta alumnus — shares the CSO Online OAuth client ID spoofing article, reproducing its Figure 1 attack-and-detection workflow with attribution
NewesTek, August 2026 — republishes the CSO Online OAuth client ID spoofing article's Figure 1 attack-and-detection workflow with attribution
DevOps channel — links back to the CSO Online OAuth client ID spoofing article as the original source
HazeTec, August 2026 — summarizes the CSO Online OAuth client ID spoofing article, linking back to the original
Threads — shares the CSO Online OAuth client ID spoofing article