CISO Insights, Lessons Learned, Frameworks & Best Practices for Leaders
As technology accelerates and new threats emerge, you’re expected to lead at the pace of change. More than 100 technology, cybersecurity and financial firms signed an open letter urging governments and critical infrastructure operators to prepare for a coming wave of AI-driven cyberattacks. From daily news coverage with expert, practical advice to AI-powered search for trusted answers to your security questions, IANS keeps you focused on what matters – and what to do about it. Plain-English AI and cyber governance insights, biweekly.
- From technical deep dives to strategic frameworks, we cover the full spectrum of modern security challenges.
- Even more worrisome, 21% of organizations use shared credentials or service accounts with broad permissions to govern AI access, and nearly the same amount (20%) leave agent management to the team that deployed them on an ad hoc basis.
- As technology accelerates and new threats emerge, you’re expected to lead at the pace of change.
- With the limitations outlined above, teams are doing what they can to manage and respond to shadow AI threats wherever possible.
- It’s not too early to reassess data governance to align on what’s most critical.
However, achieving compliance can be complex, especially across overlapping global (DORA) and US-based standards (SEC, CIRCIA) spanning sectors. Blocking access when shadow AI is detected isn’t a scalable strategy on its own because it drives usage further underground rather than solving the underlying demand. The most common response overall when shadow AI is detected is to block access (35%) or bring the tool under governance and apply access controls (29%) with whatever solutions the team has available.
This report is based on a global survey of 306 chief information security officers (CISOs), heads of cybersecurity, and other senior security executives. Where advanced companies revoke https://lievell.com/10-tips-to-build-an-effective-business-backup-strategy.html access from rogue agents quickly (50% within minutes compared with 26% across the cohort), 18% of reactive companies can’t identify or stop them at all. Reactive companies report the most extensive shadow AI (25% compared with 13% across maturities) and are more likely to struggle to identify and stop rogue agents. The UK is furthest along in its AI governance journey, with 36% of organizations reporting advanced, fully automated governance—the highest share of any country surveyed.
- This showcase episode breaks down how GeneratePolicy.com utilizes advanced Claude AI models to solve the compliance “cold start” with rapid, automated policy drafting across 420+ custom templates.
- Rethink contingency planning to help identify, prepare, and prevent events that may disrupt your business.
- Boards play a critical role in building crisis readiness to help companies withstand shocks and recover stronger in a volatile world.
- As a result, the CISO has become a unique hybrid role, according to Kearns-Manolatos, encompassing cyber risk, cybersecurity, and resilience management.
- Bayiates has worked across industries such as professional services, life sciences and pharmaceuticals, software and technology, nonprofits, and arts organizations, and has a bachelor’s degree in English (magna cum laude) from Fitchburg State University.
- Consider identity solutions tailored to managing AI agents, such as Okta for AI Agents, to reduce shadow AI sprawl from day one.
IANS News
Regardless of why this shift has occurred, the good news is that a significant break toward growth-oriented CISOs could drive greater cyber maturity (defined in the survey as robust cybersecurity planning, key cybersecurity activities, effective board management, and the deployment of AI within the cyber program). “We’re seeing more CISOs elevated to the role of chief security officer, with far more executive responsibility,” observed Ian Blatchford, Asia Pacific cyber leader at Deloitte Australia. As a result, the CISO has become a https://tradesolutionspro.com/top-20-cybersecurity-companies-you-need-to-know-in-2025.html?noamp=mobile unique hybrid role, according to Kearns-Manolatos, encompassing cyber risk, cybersecurity, and resilience management. This recommendation has been mainstreamed since at least the mid-2010s.1 A quick internet search on the topic, however, suggests that experts are still making the case that the role of the CISO should evolve from defense- to growth-oriented—that CISOs should play a critical role in all business decisions that involve technology. Explore insights that can help you achieve good AI governance.
Explore related C-suite insights
Seventy-three percent of respondents indicated that, over the prior 12 months, strategic CISO involvement in strategy conversations about key technologies had increased or significantly increased at their organizations. Therefore, it follows https://www.imfirewall.us/securing-educational-networks-via-wfilter-content-filters-and-antivirus-defenses/ that in many organizations, chief information security officers (CISOs) should be involved in strategic business decision-making. High-quality data, strong governance, and end-to-end data security are essential to advance strategic decisions and build trust, particularly for AI outcomes.
IANS launches MCP server delivering practitioner-validated intelligence directly into clients’ AI tools. Learn More
- While more mature organizations worry less about AI-enabled security breaches and reactive orgs are most likely to be extremely worried (32%), many of these reactive teams are making the trade-off to move fast.
- The data shows that, as of 2024, most CISOs now actively contribute their expertise to business decisions involving technology, leading to a more cohesive approach to IT, and potentially more positive business outcomes.
- The most common response overall when shadow AI is detected is to block access (35%) or bring the tool under governance and apply access controls (29%) with whatever solutions the team has available.
- We break down the complex legal and operational realities that companies, app stores, and developers must navigate to secure sensitive consumer data in a highly fragmented regulatory landscape.
- “We’re seeing more CISOs elevated to the role of chief security officer, with far more executive responsibility,” observed Ian Blatchford, Asia Pacific cyber leader at Deloitte Australia.
- Japan reports the highest share of CISOs who are “extremely worried” about AI-driven breaches (29%)—more than any other market surveyed.
For many organizations, the fear of shadow IT continues to plague their security teams as new apps are introduced to their stack. In this report, we’ll help you benchmark your AI security against other organizations and provide actionable tips for safe, scalable AI adoption. Despite near-universal anxiety about AI-driven threats, fewer than half of CISOs we surveyed can confidently say they know where their agents are, what those agents can access, or what actions they’re authorized to take. Designed for security leaders, red team operators, and creators alike, we deliver the ultimate playbook for protecting your physical space, your digital assets, and your professional identity.
Deixe um comentário