Rising strategic role of the CISO Deloitte Insights

CISO insights

Seventy-three percent of respondents indicated that, over the prior 12 months, strategic CISO involvement in strategy conversations about key technologies had increased or significantly increased at their organizations. Therefore, it follows that in many organizations, chief information security officers (CISOs) should be involved in strategic business decision-making. High-quality data, strong governance, and end-to-end data security are essential to advance strategic decisions and build trust, particularly for AI outcomes.

However, achieving compliance can be complex, especially across overlapping global (DORA) and US-based standards (SEC, CIRCIA) spanning sectors. Blocking access when https://vevobahis581.com/general-security-alarm-device.html shadow AI is detected isn’t a scalable strategy on its own because it drives usage further underground rather than solving the underlying demand. The most common response overall when shadow AI is detected is to block access (35%) or bring the tool under governance and apply access controls (29%) with whatever solutions the team has available.

Leaders focused on data trust need to focus on sustainable data quality. It’s not too early to reassess data governance to align on what’s most critical. 33% of executives identify cloud-related threats as the top cyber threat they’re least prepared to address, ahead of third-party breach and supply-chain compromise

CISO insights

IANS News

  • Diana Kearns-Manolatos is a senior manager with Deloitte Services LP’s Center for Integrated Research, where she leads Deloitte’s global research on digital transformation.
  • More than 100 technology, cybersecurity and financial firms signed an open letter urging governments and critical infrastructure operators to prepare for a coming wave of AI-driven cyberattacks.
  • Prioritize discovery as the foundation of your strategy by mapping where agents operate, what they can connect to, and what they can do.
  • Learn more about new post-quantum cryptography standards—and how organizations should integrate these algorithms to safeguard against future quantum threats.
  • A rapidly shifting world order and threat environment―powered by recent, exponential leaps in technology―is putting cyber strategies to the test.

For many organizations, the fear of shadow IT continues to plague their security teams as new apps are introduced to their stack. In this report, we’ll help you benchmark your AI security against other organizations and provide actionable tips for safe, scalable AI adoption. Despite near-universal anxiety about AI-driven threats, fewer than half of CISOs we surveyed can confidently say they know where their agents are, what those agents can access, or what actions they’re authorized to take. Designed for security leaders, red team operators, and creators alike, we deliver the ultimate playbook for protecting your physical space, your digital assets, and your professional identity.

Expand your team with on-demand expertise

Regardless of why this shift has occurred, the good news is that a significant break toward growth-oriented CISOs could drive greater cyber maturity (defined in the survey as robust cybersecurity planning, key cybersecurity activities, effective board https://callmeconstruction.com/news/spying-on-a-cell-phone-without-touching-it-ethical-and-legal-considerations/ management, and the deployment of AI within the cyber program). “We’re seeing more CISOs elevated to the role of chief security officer, with far more executive responsibility,” observed Ian Blatchford, Asia Pacific cyber leader at Deloitte Australia. As a result, the CISO has become a unique hybrid role, according to Kearns-Manolatos, encompassing cyber risk, cybersecurity, and resilience management. This recommendation has been mainstreamed since at least the mid-2010s.1 A quick internet search on the topic, however, suggests that experts are still making the case that the role of the CISO should evolve from defense- to growth-oriented—that CISOs should play a critical role in all business decisions that involve technology. Explore insights that can help you achieve good AI governance.

Is your cybersecurity strategy keeping pace with your company’s transformation goals? Boards play a critical role in building crisis readiness to help companies withstand shocks and recover stronger in a volatile world. Examine the key differences between SEC and DORA reporting requirements. Collaborate with your risk, finance, technology, and legal teams to map regulations to current business processes.

Explore related C-suite insights

CISO insights

As technology accelerates and new threats emerge, you’re expected to lead at the pace of change. More than 100 technology, cybersecurity and financial firms signed an open letter urging governments and critical infrastructure operators to prepare for a coming wave of AI-driven cyberattacks. From daily news coverage with expert, practical advice to AI-powered search for trusted answers to your security questions, IANS keeps you focused on what matters – and what to do about it. Plain-English AI and cyber governance insights, biweekly.

Our services

US organizations show the highest breach anxiety (84%) and high concern over overprivileged agents (65%), but they’re better positioned for success because a majority of their boards (54%) see security as a business enabler. Executive leaders may recognize that identity is core to AI security, but there’s still a substantial gap between recognition of a strategy and complete alignment on its execution. With the limitations outlined above, teams are doing what they can to manage and respond to shadow AI threats wherever possible. Across maturity levels and regional differences, security leaders found common ground in their biggest barriers to securing AI. Digging into what’s fueling this anxiety, security leaders point to a few specific threats.

CISO insights

This report is based on a global survey of 306 chief information security officers (CISOs), heads of cybersecurity, and other senior security executives. Where advanced companies revoke access from rogue agents quickly (50% within minutes compared with 26% across the cohort), 18% of reactive companies can’t identify or stop them at all. Reactive companies report the most extensive shadow AI (25% compared with 13% across maturities) and are more likely to struggle to identify and stop rogue agents. The UK is furthest along in its AI governance journey, with 36% of organizations reporting advanced, fully automated governance—the highest share of https://madeintexas.net/general-security-alarm-device.html any country surveyed.

Bayiates has worked across industries such as professional services, life sciences and pharmaceuticals, software and technology, nonprofits, and arts organizations, and has a bachelor’s degree in English (magna cum laude) from Fitchburg State University. Andy Bayiates is a senior technology editor and content strategist working with Deloitte Insights, with more than 20 years of experience in journalistic storytelling/thought leadership, executive communications, script writing, and digital communications. According to the Global Future of Cyber survey, cyber-mature organizations anticipate twice the positive outcomes as their less mature peers (figure 2). Furthermore, the growing (and critical) interdependence of business and technology has highlighted the importance of folding security into strategic investment decisions, further helping to solidify the CISO’s strategic role. The evolution of the growth-oriented CISO has been gradual, likely influenced by various factors such as board-level involvement in scenario planning and risk management, the pandemic’s emphasis on organizational resilience, and the increasing fusion of technology and business operations that were also amplified by the pandemic. It’s impossible to know for sure, but according to Diana Kearns-Manolatos, technology research leader with Deloitte’s Center for Integrated Research and lead researcher on the Future of Cyber report, it could be a function of steady evolution meeting a moment of heightened opportunity and risk.

Comments are closed.