德勤 -重新思考 AI 全面普及企业中的首席信息安全官(CISO)职能 Rethinking the CISO role for an AI-saturated enterprise_第1页
德勤 -重新思考 AI 全面普及企业中的首席信息安全官(CISO)职能 Rethinking the CISO role for an AI-saturated enterprise_第2页
德勤 -重新思考 AI 全面普及企业中的首席信息安全官(CISO)职能 Rethinking the CISO role for an AI-saturated enterprise_第3页
德勤 -重新思考 AI 全面普及企业中的首席信息安全官(CISO)职能 Rethinking the CISO role for an AI-saturated enterprise_第4页
德勤 -重新思考 AI 全面普及企业中的首席信息安全官(CISO)职能 Rethinking the CISO role for an AI-saturated enterprise_第5页
已阅读5页,还剩13页未读, 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

RETHINKINGTHECISOROLEFORANAI-SATURATEDENTERPRISE•PG1

RethinkingtheCISOroleforanAI-saturatedenterprise

AIispushingCISOsbeyondtheirtraditionalcybersecurityboundaries.Here’showtherolecanshiftfromowningtechrisktohelpingtheenterprisegovernitacrossfunctions.ByUpenSachdev,LynneChallender,AliZiaee,AnjaliShaikh,MichaelWilson,DianaKearns-Manolatos

Article•9-minread•03September2026•DeloitteCenterforIntegratedResearch

RETHINKINGTHECISOROLEFORANAI-SATURATEDENTERPRISE•PG2

AsartificialintelligencemovesfromcopilotstoautonomousAI

agents,manyenterprisesaredelegatingmoredecisionstosystemsthatcanaccessdataandactwithincreasingindependence.Buttheprocessforestablishingaccountabilityforthosedecisionshasnotalways

movedatthesamepace.Deloitteresearchindicatesthat80%of

automationleadersplantoaccelerateinvestmentinAIagents,whileonly21%oforganizationsreporthavingmatureagenticAI

governancecapabilities.

1

TheresultisawideninggapbetweenthefrequencyofAIdeploymentandanorganization’sreadinessto

managethepotentialrisksandoutcomeswhenAIacts.

ForchiefinformationsecurityofficersandtherestofthetechC-suite,thiscreatesapressinggovernanceproblem.AIriskincreasinglycuts

acrosscyber,operations,data,compliance,vendors,finance,andthebusinessitself.

Deloitte’s2026GlobalTechnologyLeadershipStudy

ofmorethan660seniortechnologyleaderssuggeststhatnosingle

functioncanmanageallthoseexposuresend-to-end,butsharedresponsibilityshouldn’tmeanambiguousaccountability,either.

FortheCISOinparticular,thattensioncouldreshapetherole.Asnewadversarialrisksempowerthreatactors,organizationswillstillneed

theCISOtoimplementandevolvesecuritycapabilities,buttherolealsonowhastoworkacrossdecisionsanddomainsthattheCISO

doesn’town.ThosedecisionsmayspanboththetechC-suiteandthebusiness.HowcantheCISOhelpbuildthecontrols,relationships,

governance,andintegrityneededacrossasharedresponsibilitymodel?

WithoutredefiningriskmanagementandoversightforanAI-saturatedenterprise,organizationsriskscalingAIfasterthantheycanabsorb

theconsequencesitcouldpotentiallycreate.CISOscouldhelpmove

AIgovernancefrombroadprinciplestocleardecisionrights,named

ownership,measurablecontrols,andcontinuousoversight,evenwhentherisksthemselvessitoutsidethesecurityfunction.

WheneveryoneownsAI,who

ownstheriskandtheoutcome?

AIleadershipisalreadydistributedacrossthetechC-suite.CISOs,

chieftechnologyofficers,chiefinformationofficers,andchiefdataandanalyticsofficersallbringdistinctprioritiestoAIstrategy,delivery,

performance,andaccountability(figure1).Addvendorsand

autonomousAIagentstothemix,andthelinesbetweenwhomakesadecisionandwhoisresponsibleforitsoutcomesbecomelessclear.

RETHINKINGTHECISOROLEFORANAI-SATURATEDENTERPRISE•PG3

RETHINKINGTHECISOROLEFORANAI-SATURATEDENTERPRISE•PG4

RETHINKINGTHECISOROLEFORANAI-SATURATEDENTERPRISE•PG5

RETHINKINGTHECISOROLEFORANAI-SATURATEDENTERPRISE•PG6

RETHINKINGTHECISOROLEFORANAI-SATURATEDENTERPRISE•PG7

ResponsibilityforAIoutcomescan’tbeownedneatlybyoneroleorfunction.Decisionrightscrossbusinessunits,technologyleaders,andgovernancecouncilstoday,andmanyleadersexpectthemtocontinuedoingsooverthenexttwoyears.

2

Asbusinessoperationsandthird-partyprovidersbecomemoreinterconnected,thetraditional

assumptionthatasinglefunctioncanowntechnologyriskend-to-endisincreasinglyunrealistic.

Thatmakescollaborationacrossfunctionsevenmoreimportant.Yetthefunctionsthatcouldhelptechleadersnavigaterisksthatfall

outsidetraditionaltechnologyboundariesaren’tnecessarilytheonestheyoftenconsidercentraltoachievingtheirobjectives.Forexample,just11%oftechleadersinoursurveyidentifylegal,compliance,andriskascriticaltoachievingtheirobjectivestodayandintwoyears

(figure2).ButexcludingthesefunctionsfromownershipofAI

outcomescouldleaveorganizationslesspreparedtomanagenewformsofthird-partyrisk,includingmanagingdatarights

3

and

intellectualproperty.

4

RETHINKINGTHECISOROLEFORANAI-SATURATEDENTERPRISE•PG8

Cross-functionalownershipalsoincreasinglyextendsbeyondthe

boundariesoftheenterprise.Sixty-threepercentoftechnologyleaderssurveyedreportthattheirrelianceonvendorsincreasedoverthepastyear,while62%expectthatreliancetoincreaseoverthenexttwo

years.AsorganizationsdependonmoreAIplatforms,models,

applicationprogramminginterfaces,andengineeringpartners,responsibilityforAIoutcomesspansbothagrowingnetworkofexternalvendorsandmoreinternalteams.

RETHINKINGTHECISOROLEFORANAI-SATURATEDENTERPRISE•PG9

Thisincreasinglydistributednetworkoftechprovidersandusers

meansthattheCISOrolecouldbecomelessaboutowningthoserisksandmoreaboutorchestratinghowtheyaremanaged,ensuringthe

rightownersandcontrolsareinplaceacrossfinancial,operational,

andbrandrisks.ManyCISOsareuniquelypositionedtoconnecttheseoutcomesandcommunicatethemtotheboard,workingin

coordinationwiththebusinessleaderswhodefinecorporaterisk

thresholds,AIoutcomes,andreturnoninvestmentexpectations,andthetechnologyleaderwhodeterminesthetoolsandsolutionsneededtoachievethem.

Fromsecuritygatekeepertoenterpriseriskorchestrator

ThegrowingprevalenceoftheCISOrolesuggeststhatorganizationsalreadyseesecurityandresiliencebecomingmoreimportant.Forty-ninepercentoforganizationsinoursurveyreporthavingaCISOrolein2026,upfrom31%in2023.ManyCISOsarebeingmeasuredonoutcomesthatextendbeyondcybersecurity,includingintegrationofsecurityintoAIinitiatives,organizationalsecuritycultureand

workforceawareness,andbusinessvalueenabledthroughriskreduction.AIcouldpushthatevolutionfurther.

AsAIagentsbecomemoreautonomousandalwayson,users’identityandaccessmanagementcouldbecomecoreelementsofthecontrol

planeformanagingrisk.

5

Themodelisshiftingfromsimply“whocanaccesswhat”to“who(orwhat)canaccesswhat,atwhattime,andonwhosebehalf.”CISOscouldleadtheirorganizations’efforttocreate

transparencyacrosstheentiresystem,frommanagingidentificationandaccessprocessesforbothAIagentsandhumansseekingaccesstotechplatformsandsolutions,todevelopingandowningthe

orchestrationandcontrolplanesthatmanagesystemsofauthority,control,andgovernance.

Monitoringwilllikelyalsoneedtoadapt.Organizationsneedtobe

abletodetectanomaloustooluse,privilegeescalation,unusualdata

access,goaldeviation,unexpectedinteractionsbetweenconnected

systems,andchangesinAIagentbehavior.ControlsshouldgenerateauditablelogsandsupportrapidinterventionwhenanAIagent

crossesadefinedriskthreshold.Organizationsshouldalsoestablishinadvancewhichactionsrequirehumanapproval,whichcanbe

automated,andwhicheventstriggerapause,escalation,orinvestigation.

Detectionandresponsealsoneedtohappeninnearreal-time,asAIoperations—andthethreatstargetingthem—movefaster.Asone

CISOatamajorAmericanbiopharmaceuticalcompanysaysinan

interview,“Backintheday,ifavulnerabilitygotintroduced,youhadatleastweeks.Thesedaysit’sgettingdowntohours.”

GiventherolesecurityneedstoplayinAIdelivery,moreemphasis

likelyneedstobeplacedonbuildinginsecurityfromthestart,astheAIsolutionisbeingdesignedanddeveloped.Secure-by-design

principlescanworktoembedreal-timeriskmonitoring,audittrails,andexplainabilityintotheproductlifecycle—ataskthatcould

requiremorestrategiccollaborationbetweentheproduct’schiefarchitectandtheorganization’sCISO,accordingtofindingsfromDeloitte’sGlobalFutureofCyberStudy.

6

“Compromisesofsystemsandapplicationsandenvironmentswill

happen,”theCISOatahealthcarecompanytoldusinaninterview.

“Ifyoutrytopreventeverycompromise,it’sgoingtobeveryhardtogetbusinessdoneinthecompany.Thegoalisyoubuildyourprogramsothatifasystem’scompromised,youseeitasquicklyaspossible,

youimmediatelycontainit,andyoueradicateitfromtheenvironmentbeforeithasabiggerimpactonthecompany.”

TheCISO’srole,then,islessaboutpreventingorowningeveryriskAImightintroduceandmoreabouthelpingensurethattheenterprisecanseetherisksacrossfunctions,containthem,andintervenewhen

necessary.

HowCISOscanmakesharedownershipwork

AgenticAIcanturnfragmentedaccountabilityintoreal-time

enterpriserisk.Decisionrights,escalationpaths,ownershipof

autonomous-agentoutcomes,andvendorriskallneedremappingasAIdistributesauthorityfasterthanaccountabilitycanbemanaged.

Butcross-functionalresponsibilitystillrequiresclearaccountabilityforoutcomes.Asriskleaders,CISOscanhelpdefineorganizationalrisk

thresholds,clarifyownership,andestablishtherightcontrolswith

sharedresponsibilityacrossfunctions.MultiplefunctionsmighthavearoleinmanaginganAIusecase,butoneaccountableownercan

provideclarityaboutwhoisultimatelyresponsiblefortheoutcome.

CISOshaveanopportunitytodevelopanddriveanAI-relatedriskmanagementmodelacrossfunctions.Thesefourmovescanhelp

clarifytheCISO’sroleinmakingthatmodelwork.

1.Assignclearownershipanddecisionrights.EachsignificantAIusecaseshouldhaveaclearlyidentifiedbusinessowner,

technicalowner,andriskoversightowner.Adecision-rights

mapshouldspecifywhocanapprovedeployment,whocan

pauseorrestrictthesystem,whoshouldbeconsulted,and

whoshouldbeinformed.Organizationsshouldalsoestablishinadvancewhichactionsrequirehumanapproval,which

actionscanbeautomated,andwhicheventsshould

automaticallytriggerapause,escalation,orinvestigation.TheCISOcanhelpdefinethesecuritycontrolsandescalation

requirementsaroundthosedecisionswithoutbecomingthedefaultownerofthebusinessoutcome.

RETHINKINGTHECISOROLEFORANAI-SATURATEDENTERPRISE•PG10

2.Bringcross-functionalpartnersintoAIdecisions

earlier.Security,architecture,data,privacy,compliance,

procurement,finance,andbusinessstakeholdersshould

participateearlyinAIvendoranduse-casedecisions.Earlycollaborationcanreducedownstreamredesign,approvaldelays,andunmanagedimplementationrisk.

Thisisparticularlyimportantforthird-partyrisk.Shifting

tech-vendorpricingmodelsanddata-accesstermsare

becomingsourcesofdependencyrisk.Vendorcontractscan

introducerisksrelatedtodatarightsandintellectualproperty,whilechangingpricingmodels(suchasimposingAPIfees,

data-accesscharges,ortoken-basedpricing)anddataaccess

termscancreatenewdependencies.AsHananSzwarcbord,

chiefsecurityofficeratMicronTechnology,aglobalproviderofmemoryandstoragesolutions,says,“Oneapproachcanbemakingthetoolselectionacollaborativeprocessacrossthe

organization,soit’snotjustITimposingone.”

7

ThisconveningroleoftenfallsnaturallytotheCISO,whoalreadysitsattheintersectionofsecurity,compliance,andvendorrisk,andislikelywellpositionedtobringtherightfunctionsandvendorsintotheconversation.

3.Translateriskappetiteintooperatingguardrails.Accordingtoagroupchiefinformationsecurityofficerinamajor

Japanesefinancialservicesgroup,“Inmanyorganizations,noonehasreallyclearlydefinedwhatthecyberriskappetite

shouldbe,andhowyou’regoingtocalculateit,howyou’re

goingtotrackit,andhowyou’regoingtopresentitacrosstheboard.”

8

AsAIsystemstakeonmoreautonomousactions,

organizationsneedtotranslateriskappetiteintoconcreteoperatingdecisions.TheCISOmaynotownthosebusinessdecisions,butthefunctioncanhelpmakethemenforceablethroughcontrols,monitoring,andescalationmechanisms.

4.Testwhethergovernanceworksatthespeedof

AI.DeterminewhetherAIgovernancecanfunctionasan

operatingcapability.Usescenarioplanningtotestgovernanceresilience.Regularlytesthigh-impactscenariossuchasvendoroutages,compromisedmodels,prompt-injectionattacks,or

unauthorizedAIagentactions,andtrackgovernance

effectivenessthroughmeasuressuchasownershipcoverage,

limitingsystemaccesstoonlywhat’snecessary,auditability,

andincidentresponsetimes.Thinkthroughowners,outcomes,controls,andoperatingmodelsacrossdifferentscenarios.ThiskindofscenariotestingdrawsoncapabilitiesmanyCISOs

alreadyrunforsecurityoperationsandincidentresponse,

makingthesecurityfunctionanaturalhomeforstress-testingAIgovernance.

AccordingtotheCISOatonehealthcarecompany,“An

annualstrategyandplanningexerciseisn’teffectiveanymore.Youhavetoconsistentlyberevisitingprioritiesand

understandingwhetherchangesintheworldaroundushavecausedustogobackandpivotinourstrategy.”

9

AIgovernanceeffectivenesscanalsobemeasuredthroughoperationalmetrics.Usefulmeasurescouldincludethe

percentageofAIagentsinventoriedandassignedanowner,thepercentageofAIagentswithaccesslimitedtoonlythesystemsanddatatheyneed,thetimerequiredtorevokeAIagentaccess,thepercentageofhigh-impactdecisions

supportedbyaudittrails,thenumberofunresolvedpolicyexceptions,andtheaveragetimetodetectandcontainAI-relatedincidents..

Governingriskatmachinespeed

Organizations’techresiliencecannowdependonenablingsecurityandmanagingriskatmachinespeed.ButAImakestechnologyrisksimultaneouslyacyber,compliance,vendor,andoperational

responsibility,potentiallyleavingaccountabilitygapswherethosedomainsstopandstart.

Manyorganizationswilllikelyneedtomovefromfunction-by-

functionownershipofAIriskmanagement—cyberownscyber,

complianceownscompliance—toasinglecross-domainrisk

managementprocesstiedtobusinessoutcomes.CISOsdon’tneedto

ownthegovernanceofeverypossibleriskAIcouldcreate,butthey’rewellpositionedtoconnectsecuritycontrols,monitoring,escalation,

andresilienceacrossfunctionssoorganizationalleaderscanseewhereriskexposureexists,whoownstheoutcomeofanAI-relatedrisk

event,andwheninterventionisrequired.InanAI-saturated

enterprise,theabilitytomakethatmodelworkatspeedmightbecomeadefiningpartoftheCISOrole.

RETHINKINGTHECISOROLEFORANAI-SATURATEDENTERPRISE•PG11

Methodology

Deloitte’s2026GlobalTechnologyLeadershipStudysurveyed662seniortechnologyleadersintheAmericas(includingLatinAmerica);Europe,theMiddleEast,andAfrica;andAsia-Pacificregionstounderstandhowseniortechnologyleadership

rolesandresponsibilitiesareevolving,aswellasthekeychallengesandstrategicprioritiesshaping2026andbeyond.DatawascollectedthroughanonlinesurveyfromDec.22,2025,toFeb.23,2026.

Amajorityoftherespondents(87%)wereC-suitetechleaders.Forthematicandroleanalysis,respondentsweregroupedintofourC-suitepersonasbasedontheirtitle,includingchiefinformationofficers,chieftechnologyofficers,chiefdataandanalyticsofficers,andchiefinformationsecurityofficers.Executivesrepresentedorganizationswithannualrevenuesof

US$1billionormore,includingpubliclyandprivatelyownedcompanies,aswellasnot-for-profitandgovernmententities.Primaryindustriesrepresentedincludeconsumerproductsandservices;financialservices;technology,media,and

telecommunications;energy,resources,andindustrials;lifesciencesandhealthcare;andgovernmentandpublicservices.

ContinuetheconversationMeettheindustryleaders

UpenSachdev

Principal|CyberRisk|Deloitte&ToucheLLP

DeloitteUnitedStates

AnjaliShaikh

GlobalCIOProgram&USTechExecutiveProgramsLeader|

ManagingDirector,DeloitteConsultingLLP

DeloitteUnitedStates

StevePratt

Managingprincipal,Indianapolis

Marketplace,DeloitteLLP|USTechExecutiveProgramsLeader|

Principal,DeloitteConsultingLLPDeloitteUnitedStates

LynneChallender

Managingdirector|Cyberstrategyandtransformationleader

DeloitteUnitedStates

BYUpenSachdev

DeloitteUnitedStates

AliZiaee

DeloitteUnitedStates

MichaelWilson

DeloitteUnitedStates

LynneChallender

DeloitteUnitedStates

AnjaliShaikh

DeloitteUnitedStates

DianaKearns-Manolatos

DeloitteUnitedStates

RETHINKINGTHECISOROLEFORANAI-SATURATEDENTERPRISE•PG12

ENDNOTES

1.JimRowan,NitinMittal,BeenaAmmanath,andCostiPerricos,“

StateofAIintheenterprise:Theuntappededge

,”Deloitte,January2026.

2.AnjaliShaikhandStevePratt,“

2026GlobalTechnologyLeadershipStudy

,”Deloitte,April30,2026.

3.MichaelWilson,RamRavi,DianaKearns-Manolatos,WhitneyMetzger,andDavidJarvis,“ThepricingparadoxofagenticSaaS:Whattodoabouttollgating?”DeloitteInsights,June17,2026.

4.TimMurphy,DianaKearns-Manolatos,andAdityaNarayan,“

HowbrandsaremanagingintellectualpropertyintheageofAI

,”DeloitteandTheWallStreetJournal,May23,2026.

5.DeloitteUS,“

TheAIimpactoncyberrisk:Understandingnewthreats,defenses,andtheCISO’sevolvingmandate

,”accessedAug.26,2026.

6.EmilyMossburgetal.,“

TheGlobalFutureofCyberSurvey,4thedition

,”DeloitteGlobal,Oct.21,2024.

7.KatherineNoyes,“

Micronleaders:AIhas‘turbocharged’collaboration

,”DeloitteandTheWallStreetJournal,April1,2026.

8.DeloitteinterviewconductedinDecember2025.

9.Ibid.

ACKNOWLEDGMENTS

TheauthorswouldliketothankMonikaMahtoandErikaMaguirefortheirsignificantcontributionstotheresearchanddevelopmentofthisarticle.

We’dliketothankStevePratt,VikramKunchala,andNatalieAndrusfortheirthoughtfulreviewandinputbasedontheimpactfulworkthey’redrivinginthemarket.

WeextendourappreciationtoAyushKumarforhissupportindataanalysis,aswellastothemarketingteam—JenniferRood,Saurabh

Rijhwani,AkshayPoojari,JenniferPopovich,andPratyushaPeddasomayajula—fortheirsupportinamplifyingtheimpactoftheseinsights.

Editorial(includingproductionandcopyediting):CorrieCommisso,ElisabethSullivan,ShyamiliM,AnuAugustine,andPubaliDeyDesign:MollyPiersolandSonyaVasilieff

Coverimageby:SonyaVasilieff

Knowledgeservices:RishithaBichapogu

COPYRIGHT

Copyright©2026DeloitteDevelopmentLLC.Allrightsreserved.MemberofDeloitteToucheTohmatsuLimited

AboutDeloi

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

评论

0/150

提交评论