CISO Insights: Voices in Cybersecurity CISO Marketplace

CISO insights

Japan reports the highest share of CISOs who are “extremely worried” about AI-driven breaches (29%)—more than any other market surveyed. Meanwhile, 55% of companies can revoke AI agent access within hours in the event of a breach—but even responding in hours is far too slow, as AI systems can execute harmful actions instantly. The majority of security leaders aren’t feeling especially confident in securing their agents today, but not all companies (or regions) are at the same point in their journeys.

US organizations show the highest breach anxiety (84%) and high concern over overprivileged agents (65%), but they’re better positioned for success because a majority of their boards (54%) see security as a business enabler. Executive leaders may recognize that identity is core to AI security, but there’s still a substantial gap between recognition of a strategy and complete alignment on its execution. With the limitations outlined above, teams are doing what they can to manage and respond to shadow AI threats wherever possible. Across maturity levels and regional differences, security leaders found common ground in their biggest barriers to securing AI. Digging into what’s fueling this anxiety, security leaders https://power-at-work.com/exploring-the-potential-of-blockchain-technology-in-ensuring-transparency-in-construction-equipment-maintenance/ point to a few specific threats.

This report is based on a global survey of 306 chief information security officers (CISOs), heads of cybersecurity, and other senior security executives. Where advanced companies revoke access from rogue agents quickly (50% within minutes compared with 26% across the cohort), 18% of reactive companies can’t identify or stop them at all. Reactive companies report the most extensive shadow AI (25% compared with 13% across maturities) and are more likely to struggle to identify and stop rogue agents. The UK is furthest along in its AI governance journey, with 36% of organizations reporting advanced, fully automated governance—the highest share of any country surveyed.

CISO insights

Okta

CISO insights

CISOs in Germany report the highest confidence in agent oversight but have some of the lowest actual governance maturity (58% developing or reactive). So having them in your directory, having the governance process over them where they have a human manager who’s responsible for what data they have access to, what scopes they can act in, or decisions they can make.” Even more worrisome, 21% of organizations use shared credentials or service accounts with broad permissions to govern AI access, and nearly the same amount (20%) leave agent management to the team that deployed them on an ad hoc basis. Closing that gap will require board buy-in—but Japanese boards are among the most likely globally to treat AI security as a compliance hurdle rather than a business enabler, making it harder for CISOs to secure the investment they need. They’re also twice as likely (12%) to report they have no consistent approach to governing agent identity compared with the global average (6%).

Regardless of why this shift has occurred, the good news is that a significant break toward growth-oriented CISOs could drive greater cyber maturity (defined in the survey as robust cybersecurity planning, key cybersecurity activities, effective board management, and the deployment of AI within the cyber program). “We’re seeing more CISOs elevated to the role of chief security officer, with far more executive responsibility,” observed Ian Blatchford, Asia Pacific cyber leader at Deloitte Australia. As a result, the CISO has become a unique hybrid role, according to Kearns-Manolatos, encompassing cyber risk, cybersecurity, and resilience management. This recommendation has been mainstreamed since at least the mid-2010s.1 A quick internet search on the topic, however, suggests that experts are still making the case that the role of the CISO should evolve from defense- to growth-oriented—that CISOs should play a critical role in all business decisions that involve technology. Explore insights that can help you achieve good AI governance.

However, achieving compliance can be complex, especially across overlapping global (DORA) and US-based standards (SEC, CIRCIA) spanning sectors. Blocking access when shadow AI is detected isn’t a scalable strategy on its own because it drives usage further underground rather than solving the underlying demand. The most common response overall when shadow AI is detected is to block access (35%) or bring the tool under governance and apply access controls (29%) with whatever solutions the team has available.

  • The blueprint for the secure agentic enterprise offers a practical framework for standing up this kind of governance model.
  • For many organizations, the fear of shadow IT continues to plague their security teams as new apps are introduced to their stack.
  • Less than half of CISOs feel confident they can identify all of the agents in their environment (47%), control what their agents interact with (46%), or authorize individual tool calls using context and intent clues (45%).
  • A joint biennial report (8th edition) from Deloitte and the National Association of State Chief Information Officers (NASCIO)
  • Where advanced companies revoke access from rogue agents quickly (50% within minutes compared with 26% across the cohort), 18% of reactive companies can’t identify or stop them at all.
  • Build a repeatable process to evaluate, onboard, and govern new AI tools quickly, so sanctioned, secure options can compete with the speed employees want.

CISO insights

For many organizations, the fear of shadow IT continues to plague their security teams as new apps are introduced to their stack. In this report, we’ll help you benchmark your AI security against other organizations and provide actionable tips for safe, scalable AI adoption. Despite near-universal anxiety about AI-driven threats, fewer than half of CISOs we surveyed can confidently say they know where their agents are, what those agents can access, or what actions they’re authorized to take. Designed for security leaders, red team operators, and https://chicagonewsblog.com/cqr-how-to-protect-your-business-from-threats-with-a-penetration-testing-service.html creators alike, we deliver the ultimate playbook for protecting your physical space, your digital assets, and your professional identity.

As technology accelerates and new threats emerge, you’re expected to lead at the pace of change. More than 100 technology, cybersecurity and financial firms signed an open letter urging governments and critical infrastructure operators to prepare for a coming wave of AI-driven cyberattacks. From daily news coverage with expert, practical advice to AI-powered search for trusted answers to your security questions, IANS keeps you focused on what matters – and what to do about it. Plain-English AI and https://wapreview.mobi/computer-network-security-tutorial cyber governance insights, biweekly.

  • It touches every part of the business and demands precision, transparency, and strategic oversight.
  • Persistent gaps in monitoring, controls, and governance are now magnified by geopolitical pressure.
  • This recommendation has been mainstreamed since at least the mid-2010s.1 A quick internet search on the topic, however, suggests that experts are still making the case that the role of the CISO should evolve from defense- to growth-oriented—that CISOs should play a critical role in all business decisions that involve technology.
  • The survey data was finalized in June 2026 in partnership with the research firm Apprize360 Intelligence.

Global Human Capital Trends

“I love my teams using AI, but it’s almost like the AI tools are designed to make you want to overshare them.” This fear of AI-driven breaches is especially acute among US-based CISOs, with 84% of respondents feeling extremely or very worried (compared with 57% of CISOs globally). “When we talk about governance, we’re talking about treating those AI identities as first-class identities.

Leave a Reply

Your email address will not be published. Required fields are marked *