版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
RETHINKINGTHECISOROLEFORANAI-SATURATEDENTERPRISE•PG1
RethinkingtheCISOroleforanAI-saturatedenterprise
AIispushingCISOsbeyondtheirtraditionalcybersecurityboundaries.Here’showtherolecanshiftfromowningtechrisktohelpingtheenterprisegovernitacrossfunctions.ByUpenSachdev,LynneChallender,AliZiaee,AnjaliShaikh,MichaelWilson,DianaKearns-Manolatos
Article•9-minread•03September2026•DeloitteCenterforIntegratedResearch
RETHINKINGTHECISOROLEFORANAI-SATURATEDENTERPRISE•PG2
AsartificialintelligencemovesfromcopilotstoautonomousAI
agents,manyenterprisesaredelegatingmoredecisionstosystemsthatcanaccessdataandactwithincreasingindependence.Buttheprocessforestablishingaccountabilityforthosedecisionshasnotalways
movedatthesamepace.Deloitteresearchindicatesthat80%of
automationleadersplantoaccelerateinvestmentinAIagents,whileonly21%oforganizationsreporthavingmatureagenticAI
governancecapabilities.
1
TheresultisawideninggapbetweenthefrequencyofAIdeploymentandanorganization’sreadinessto
managethepotentialrisksandoutcomeswhenAIacts.
ForchiefinformationsecurityofficersandtherestofthetechC-suite,thiscreatesapressinggovernanceproblem.AIriskincreasinglycuts
acrosscyber,operations,data,compliance,vendors,finance,andthebusinessitself.
Deloitte’s2026GlobalTechnologyLeadershipStudy
ofmorethan660seniortechnologyleaderssuggeststhatnosingle
functioncanmanageallthoseexposuresend-to-end,butsharedresponsibilityshouldn’tmeanambiguousaccountability,either.
FortheCISOinparticular,thattensioncouldreshapetherole.Asnewadversarialrisksempowerthreatactors,organizationswillstillneed
theCISOtoimplementandevolvesecuritycapabilities,buttherolealsonowhastoworkacrossdecisionsanddomainsthattheCISO
doesn’town.ThosedecisionsmayspanboththetechC-suiteandthebusiness.HowcantheCISOhelpbuildthecontrols,relationships,
governance,andintegrityneededacrossasharedresponsibilitymodel?
WithoutredefiningriskmanagementandoversightforanAI-saturatedenterprise,organizationsriskscalingAIfasterthantheycanabsorb
theconsequencesitcouldpotentiallycreate.CISOscouldhelpmove
AIgovernancefrombroadprinciplestocleardecisionrights,named
ownership,measurablecontrols,andcontinuousoversight,evenwhentherisksthemselvessitoutsidethesecurityfunction.
WheneveryoneownsAI,who
ownstheriskandtheoutcome?
AIleadershipisalreadydistributedacrossthetechC-suite.CISOs,
chieftechnologyofficers,chiefinformationofficers,andchiefdataandanalyticsofficersallbringdistinctprioritiestoAIstrategy,delivery,
performance,andaccountability(figure1).Addvendorsand
autonomousAIagentstothemix,andthelinesbetweenwhomakesadecisionandwhoisresponsibleforitsoutcomesbecomelessclear.
RETHINKINGTHECISOROLEFORANAI-SATURATEDENTERPRISE•PG3
RETHINKINGTHECISOROLEFORANAI-SATURATEDENTERPRISE•PG4
RETHINKINGTHECISOROLEFORANAI-SATURATEDENTERPRISE•PG5
RETHINKINGTHECISOROLEFORANAI-SATURATEDENTERPRISE•PG6
RETHINKINGTHECISOROLEFORANAI-SATURATEDENTERPRISE•PG7
ResponsibilityforAIoutcomescan’tbeownedneatlybyoneroleorfunction.Decisionrightscrossbusinessunits,technologyleaders,andgovernancecouncilstoday,andmanyleadersexpectthemtocontinuedoingsooverthenexttwoyears.
2
Asbusinessoperationsandthird-partyprovidersbecomemoreinterconnected,thetraditional
assumptionthatasinglefunctioncanowntechnologyriskend-to-endisincreasinglyunrealistic.
Thatmakescollaborationacrossfunctionsevenmoreimportant.Yetthefunctionsthatcouldhelptechleadersnavigaterisksthatfall
outsidetraditionaltechnologyboundariesaren’tnecessarilytheonestheyoftenconsidercentraltoachievingtheirobjectives.Forexample,just11%oftechleadersinoursurveyidentifylegal,compliance,andriskascriticaltoachievingtheirobjectivestodayandintwoyears
(figure2).ButexcludingthesefunctionsfromownershipofAI
outcomescouldleaveorganizationslesspreparedtomanagenewformsofthird-partyrisk,includingmanagingdatarights
3
and
intellectualproperty.
4
RETHINKINGTHECISOROLEFORANAI-SATURATEDENTERPRISE•PG8
Cross-functionalownershipalsoincreasinglyextendsbeyondthe
boundariesoftheenterprise.Sixty-threepercentoftechnologyleaderssurveyedreportthattheirrelianceonvendorsincreasedoverthepastyear,while62%expectthatreliancetoincreaseoverthenexttwo
years.AsorganizationsdependonmoreAIplatforms,models,
applicationprogramminginterfaces,andengineeringpartners,responsibilityforAIoutcomesspansbothagrowingnetworkofexternalvendorsandmoreinternalteams.
RETHINKINGTHECISOROLEFORANAI-SATURATEDENTERPRISE•PG9
Thisincreasinglydistributednetworkoftechprovidersandusers
meansthattheCISOrolecouldbecomelessaboutowningthoserisksandmoreaboutorchestratinghowtheyaremanaged,ensuringthe
rightownersandcontrolsareinplaceacrossfinancial,operational,
andbrandrisks.ManyCISOsareuniquelypositionedtoconnecttheseoutcomesandcommunicatethemtotheboard,workingin
coordinationwiththebusinessleaderswhodefinecorporaterisk
thresholds,AIoutcomes,andreturnoninvestmentexpectations,andthetechnologyleaderwhodeterminesthetoolsandsolutionsneededtoachievethem.
Fromsecuritygatekeepertoenterpriseriskorchestrator
ThegrowingprevalenceoftheCISOrolesuggeststhatorganizationsalreadyseesecurityandresiliencebecomingmoreimportant.Forty-ninepercentoforganizationsinoursurveyreporthavingaCISOrolein2026,upfrom31%in2023.ManyCISOsarebeingmeasuredonoutcomesthatextendbeyondcybersecurity,includingintegrationofsecurityintoAIinitiatives,organizationalsecuritycultureand
workforceawareness,andbusinessvalueenabledthroughriskreduction.AIcouldpushthatevolutionfurther.
AsAIagentsbecomemoreautonomousandalwayson,users’identityandaccessmanagementcouldbecomecoreelementsofthecontrol
planeformanagingrisk.
5
Themodelisshiftingfromsimply“whocanaccesswhat”to“who(orwhat)canaccesswhat,atwhattime,andonwhosebehalf.”CISOscouldleadtheirorganizations’efforttocreate
transparencyacrosstheentiresystem,frommanagingidentificationandaccessprocessesforbothAIagentsandhumansseekingaccesstotechplatformsandsolutions,todevelopingandowningthe
orchestrationandcontrolplanesthatmanagesystemsofauthority,control,andgovernance.
Monitoringwilllikelyalsoneedtoadapt.Organizationsneedtobe
abletodetectanomaloustooluse,privilegeescalation,unusualdata
access,goaldeviation,unexpectedinteractionsbetweenconnected
systems,andchangesinAIagentbehavior.ControlsshouldgenerateauditablelogsandsupportrapidinterventionwhenanAIagent
crossesadefinedriskthreshold.Organizationsshouldalsoestablishinadvancewhichactionsrequirehumanapproval,whichcanbe
automated,andwhicheventstriggerapause,escalation,orinvestigation.
Detectionandresponsealsoneedtohappeninnearreal-time,asAIoperations—andthethreatstargetingthem—movefaster.Asone
CISOatamajorAmericanbiopharmaceuticalcompanysaysinan
interview,“Backintheday,ifavulnerabilitygotintroduced,youhadatleastweeks.Thesedaysit’sgettingdowntohours.”
GiventherolesecurityneedstoplayinAIdelivery,moreemphasis
likelyneedstobeplacedonbuildinginsecurityfromthestart,astheAIsolutionisbeingdesignedanddeveloped.Secure-by-design
principlescanworktoembedreal-timeriskmonitoring,audittrails,andexplainabilityintotheproductlifecycle—ataskthatcould
requiremorestrategiccollaborationbetweentheproduct’schiefarchitectandtheorganization’sCISO,accordingtofindingsfromDeloitte’sGlobalFutureofCyberStudy.
6
“Compromisesofsystemsandapplicationsandenvironmentswill
happen,”theCISOatahealthcarecompanytoldusinaninterview.
“Ifyoutrytopreventeverycompromise,it’sgoingtobeveryhardtogetbusinessdoneinthecompany.Thegoalisyoubuildyourprogramsothatifasystem’scompromised,youseeitasquicklyaspossible,
youimmediatelycontainit,andyoueradicateitfromtheenvironmentbeforeithasabiggerimpactonthecompany.”
TheCISO’srole,then,islessaboutpreventingorowningeveryriskAImightintroduceandmoreabouthelpingensurethattheenterprisecanseetherisksacrossfunctions,containthem,andintervenewhen
necessary.
HowCISOscanmakesharedownershipwork
AgenticAIcanturnfragmentedaccountabilityintoreal-time
enterpriserisk.Decisionrights,escalationpaths,ownershipof
autonomous-agentoutcomes,andvendorriskallneedremappingasAIdistributesauthorityfasterthanaccountabilitycanbemanaged.
Butcross-functionalresponsibilitystillrequiresclearaccountabilityforoutcomes.Asriskleaders,CISOscanhelpdefineorganizationalrisk
thresholds,clarifyownership,andestablishtherightcontrolswith
sharedresponsibilityacrossfunctions.MultiplefunctionsmighthavearoleinmanaginganAIusecase,butoneaccountableownercan
provideclarityaboutwhoisultimatelyresponsiblefortheoutcome.
CISOshaveanopportunitytodevelopanddriveanAI-relatedriskmanagementmodelacrossfunctions.Thesefourmovescanhelp
clarifytheCISO’sroleinmakingthatmodelwork.
1.Assignclearownershipanddecisionrights.EachsignificantAIusecaseshouldhaveaclearlyidentifiedbusinessowner,
technicalowner,andriskoversightowner.Adecision-rights
mapshouldspecifywhocanapprovedeployment,whocan
pauseorrestrictthesystem,whoshouldbeconsulted,and
whoshouldbeinformed.Organizationsshouldalsoestablishinadvancewhichactionsrequirehumanapproval,which
actionscanbeautomated,andwhicheventsshould
automaticallytriggerapause,escalation,orinvestigation.TheCISOcanhelpdefinethesecuritycontrolsandescalation
requirementsaroundthosedecisionswithoutbecomingthedefaultownerofthebusinessoutcome.
RETHINKINGTHECISOROLEFORANAI-SATURATEDENTERPRISE•PG10
2.Bringcross-functionalpartnersintoAIdecisions
earlier.Security,architecture,data,privacy,compliance,
procurement,finance,andbusinessstakeholdersshould
participateearlyinAIvendoranduse-casedecisions.Earlycollaborationcanreducedownstreamredesign,approvaldelays,andunmanagedimplementationrisk.
Thisisparticularlyimportantforthird-partyrisk.Shifting
tech-vendorpricingmodelsanddata-accesstermsare
becomingsourcesofdependencyrisk.Vendorcontractscan
introducerisksrelatedtodatarightsandintellectualproperty,whilechangingpricingmodels(suchasimposingAPIfees,
data-accesscharges,ortoken-basedpricing)anddataaccess
termscancreatenewdependencies.AsHananSzwarcbord,
chiefsecurityofficeratMicronTechnology,aglobalproviderofmemoryandstoragesolutions,says,“Oneapproachcanbemakingthetoolselectionacollaborativeprocessacrossthe
organization,soit’snotjustITimposingone.”
7
ThisconveningroleoftenfallsnaturallytotheCISO,whoalreadysitsattheintersectionofsecurity,compliance,andvendorrisk,andislikelywellpositionedtobringtherightfunctionsandvendorsintotheconversation.
3.Translateriskappetiteintooperatingguardrails.Accordingtoagroupchiefinformationsecurityofficerinamajor
Japanesefinancialservicesgroup,“Inmanyorganizations,noonehasreallyclearlydefinedwhatthecyberriskappetite
shouldbe,andhowyou’regoingtocalculateit,howyou’re
goingtotrackit,andhowyou’regoingtopresentitacrosstheboard.”
8
AsAIsystemstakeonmoreautonomousactions,
organizationsneedtotranslateriskappetiteintoconcreteoperatingdecisions.TheCISOmaynotownthosebusinessdecisions,butthefunctioncanhelpmakethemenforceablethroughcontrols,monitoring,andescalationmechanisms.
4.Testwhethergovernanceworksatthespeedof
AI.DeterminewhetherAIgovernancecanfunctionasan
operatingcapability.Usescenarioplanningtotestgovernanceresilience.Regularlytesthigh-impactscenariossuchasvendoroutages,compromisedmodels,prompt-injectionattacks,or
unauthorizedAIagentactions,andtrackgovernance
effectivenessthroughmeasuressuchasownershipcoverage,
limitingsystemaccesstoonlywhat’snecessary,auditability,
andincidentresponsetimes.Thinkthroughowners,outcomes,controls,andoperatingmodelsacrossdifferentscenarios.ThiskindofscenariotestingdrawsoncapabilitiesmanyCISOs
alreadyrunforsecurityoperationsandincidentresponse,
makingthesecurityfunctionanaturalhomeforstress-testingAIgovernance.
AccordingtotheCISOatonehealthcarecompany,“An
annualstrategyandplanningexerciseisn’teffectiveanymore.Youhavetoconsistentlyberevisitingprioritiesand
understandingwhetherchangesintheworldaroundushavecausedustogobackandpivotinourstrategy.”
9
AIgovernanceeffectivenesscanalsobemeasuredthroughoperationalmetrics.Usefulmeasurescouldincludethe
percentageofAIagentsinventoriedandassignedanowner,thepercentageofAIagentswithaccesslimitedtoonlythesystemsanddatatheyneed,thetimerequiredtorevokeAIagentaccess,thepercentageofhigh-impactdecisions
supportedbyaudittrails,thenumberofunresolvedpolicyexceptions,andtheaveragetimetodetectandcontainAI-relatedincidents..
Governingriskatmachinespeed
Organizations’techresiliencecannowdependonenablingsecurityandmanagingriskatmachinespeed.ButAImakestechnologyrisksimultaneouslyacyber,compliance,vendor,andoperational
responsibility,potentiallyleavingaccountabilitygapswherethosedomainsstopandstart.
Manyorganizationswilllikelyneedtomovefromfunction-by-
functionownershipofAIriskmanagement—cyberownscyber,
complianceownscompliance—toasinglecross-domainrisk
managementprocesstiedtobusinessoutcomes.CISOsdon’tneedto
ownthegovernanceofeverypossibleriskAIcouldcreate,butthey’rewellpositionedtoconnectsecuritycontrols,monitoring,escalation,
andresilienceacrossfunctionssoorganizationalleaderscanseewhereriskexposureexists,whoownstheoutcomeofanAI-relatedrisk
event,andwheninterventionisrequired.InanAI-saturated
enterprise,theabilitytomakethatmodelworkatspeedmightbecomeadefiningpartoftheCISOrole.
RETHINKINGTHECISOROLEFORANAI-SATURATEDENTERPRISE•PG11
Methodology
Deloitte’s2026GlobalTechnologyLeadershipStudysurveyed662seniortechnologyleadersintheAmericas(includingLatinAmerica);Europe,theMiddleEast,andAfrica;andAsia-Pacificregionstounderstandhowseniortechnologyleadership
rolesandresponsibilitiesareevolving,aswellasthekeychallengesandstrategicprioritiesshaping2026andbeyond.DatawascollectedthroughanonlinesurveyfromDec.22,2025,toFeb.23,2026.
Amajorityoftherespondents(87%)wereC-suitetechleaders.Forthematicandroleanalysis,respondentsweregroupedintofourC-suitepersonasbasedontheirtitle,includingchiefinformationofficers,chieftechnologyofficers,chiefdataandanalyticsofficers,andchiefinformationsecurityofficers.Executivesrepresentedorganizationswithannualrevenuesof
US$1billionormore,includingpubliclyandprivatelyownedcompanies,aswellasnot-for-profitandgovernmententities.Primaryindustriesrepresentedincludeconsumerproductsandservices;financialservices;technology,media,and
telecommunications;energy,resources,andindustrials;lifesciencesandhealthcare;andgovernmentandpublicservices.
ContinuetheconversationMeettheindustryleaders
UpenSachdev
Principal|CyberRisk|Deloitte&ToucheLLP
DeloitteUnitedStates
AnjaliShaikh
GlobalCIOProgram&USTechExecutiveProgramsLeader|
ManagingDirector,DeloitteConsultingLLP
DeloitteUnitedStates
StevePratt
Managingprincipal,Indianapolis
Marketplace,DeloitteLLP|USTechExecutiveProgramsLeader|
Principal,DeloitteConsultingLLPDeloitteUnitedStates
LynneChallender
Managingdirector|Cyberstrategyandtransformationleader
DeloitteUnitedStates
BYUpenSachdev
DeloitteUnitedStates
AliZiaee
DeloitteUnitedStates
MichaelWilson
DeloitteUnitedStates
LynneChallender
DeloitteUnitedStates
AnjaliShaikh
DeloitteUnitedStates
DianaKearns-Manolatos
DeloitteUnitedStates
RETHINKINGTHECISOROLEFORANAI-SATURATEDENTERPRISE•PG12
ENDNOTES
1.JimRowan,NitinMittal,BeenaAmmanath,andCostiPerricos,“
StateofAIintheenterprise:Theuntappededge
,”Deloitte,January2026.
2.AnjaliShaikhandStevePratt,“
2026GlobalTechnologyLeadershipStudy
,”Deloitte,April30,2026.
3.MichaelWilson,RamRavi,DianaKearns-Manolatos,WhitneyMetzger,andDavidJarvis,“ThepricingparadoxofagenticSaaS:Whattodoabouttollgating?”DeloitteInsights,June17,2026.
4.TimMurphy,DianaKearns-Manolatos,andAdityaNarayan,“
HowbrandsaremanagingintellectualpropertyintheageofAI
,”DeloitteandTheWallStreetJournal,May23,2026.
5.DeloitteUS,“
TheAIimpactoncyberrisk:Understandingnewthreats,defenses,andtheCISO’sevolvingmandate
,”accessedAug.26,2026.
6.EmilyMossburgetal.,“
TheGlobalFutureofCyberSurvey,4thedition
,”DeloitteGlobal,Oct.21,2024.
7.KatherineNoyes,“
Micronleaders:AIhas‘turbocharged’collaboration
,”DeloitteandTheWallStreetJournal,April1,2026.
8.DeloitteinterviewconductedinDecember2025.
9.Ibid.
ACKNOWLEDGMENTS
TheauthorswouldliketothankMonikaMahtoandErikaMaguirefortheirsignificantcontributionstotheresearchanddevelopmentofthisarticle.
We’dliketothankStevePratt,VikramKunchala,andNatalieAndrusfortheirthoughtfulreviewandinputbasedontheimpactfulworkthey’redrivinginthemarket.
WeextendourappreciationtoAyushKumarforhissupportindataanalysis,aswellastothemarketingteam—JenniferRood,Saurabh
Rijhwani,AkshayPoojari,JenniferPopovich,andPratyushaPeddasomayajula—fortheirsupportinamplifyingtheimpactoftheseinsights.
Editorial(includingproductionandcopyediting):CorrieCommisso,ElisabethSullivan,ShyamiliM,AnuAugustine,andPubaliDeyDesign:MollyPiersolandSonyaVasilieff
Coverimageby:SonyaVasilieff
Knowledgeservices:RishithaBichapogu
COPYRIGHT
Copyright©2026DeloitteDevelopmentLLC.Allrightsreserved.MemberofDeloitteToucheTohmatsuLimited
AboutDeloi
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 湖北省黄冈市浠水县第二实中等校2026-2027学年九年级上学期9月阶段检测英语试题(含答案)
- 水产罐头加工工岗位技能考试试卷及答案
- 少儿跆拳道老师岗位教学考试试卷及答案
- 化工工艺试验工岗前纪律考核试卷含答案
- 合成氨二氧化碳回收工安全生产规范评优考核试卷含答案
- 竖窑球团焙烧工诚信品质知识考核试卷含答案
- 2026年施工员考试试题及答案
- 硫酸生产工保密强化考核试卷含答案
- 运动场草坪管理师岗前基础验收考核试卷含答案
- 中药酒(酊)剂工安全行为测试考核试卷含答案
- 涂装安全考试题及答案
- 安徽省江南十校2026-2027学年高三上学期9月综合素质检测 英语试题+答案
- 27.2 反比例函数的图象和性质 课件(24张) 2026-2027学年人教版九年级数学上册
- 2026年教师资格证中学生物学科教学设计全真模考卷
- 2026-2031年中国多射流熔融3D打印机行业市场调查研究及发展前景预测报告
- 光伏提水灌溉系统工程设计方案
- 2026年高考北京卷化学高考真题(含答案解析)
- 丹参种植项目实施方案
- 2026年秋统编版小学道德与法治五年级上册(全册)教学设计(新教材 附目录p113)
- 2026-2027学年第一学期小学一年级数学教学计划
- 《人工智能导论》课件-02AI对话提示词(Prompt)构建
评论
0/150
提交评论