The CISO After Cybersecurity: Governing Speed, Trust, and Enterprise Value in the Age of AI

Updated: 22 hours ago

DEW Diligence is not affiliated with KPMG; this is independent commentary.
A DEW Diligence perspective on KPMG’s 2026 Cyber and Technology Risk Survey, Balancing speed and safety: The CISO’s evolving role
KPMG’s 2026 Cyber and Technology Risk Survey captures a fundamental change underway in enterprise leadership. The Chief Information Security Officer (CISO) is no longer being measured solely by how well the organization is protected. The modern CISO is being measured by whether the enterprise can innovate, adopt technology, withstand disruption, and grow without taking unmanaged risk. That is an important distinction.
KPMG describes an environment where digital platforms, artificial intelligence, and third-party ecosystems accelerate change while also increasing the CISO’s accountability for enterprise-level risk. Its central argument is that the mandate has moved beyond protection toward disciplined judgment, setting guardrails, defining risk tolerance, and determining where speed creates value and where restraint is necessary.
DEW Diligence agrees with that direction and takes it one step further. The evolved CISO is becoming an enterprise technology-risk executive, part strategist, part risk officer, part technologist, part business operator, and part AI governor.

It is not mission creep; it is the consequence of technology becoming inseparable from the operating model of the enterprise.
Assumptions and boundaries: This analysis considers primarily medium-to-large enterprises operating in U.S. and potentially multinational regulatory environments. Regulatory requirements discussed below are mandatory only where an organization falls within their jurisdiction or scope. NIST, ISO, COBIT, COSO, FAIR, OWASP, CIS, and MITRE resources generally provide frameworks, standards, methodologies, or knowledge bases, and not necessarily universal legal mandates. Legal applicability must be determined separately.
KPMG’s central message: speed with safety
KPMG surveyed 310 U.S. security leaders from organizations with at least $1 billion in annual revenue. Its findings show why the traditional security operating model is under pressure. Eighty-three percent reported increased cyberattacks; only 24 percent reported fully integrating AI into the cybersecurity function; nearly 70 percent devote more than 11 percent of cyber budgets to AI-related initiatives; 74 percent expect cybersecurity headcount to increase by more than 11 percent; 55 percent are leveraging managed services providers for cyber threat intelligence; and only 27 percent are actively implementing post-quantum cryptography.
These numbers describe something bigger than a threat problem. They reveal an execution problem.
Organizations are simultaneously buying AI, defending AI, using AI to defend themselves, expanding their security workforces, modernizing infrastructure, expanding third-party dependencies, and attempting to prove that cybersecurity investments are reducing business risk. KPMG therefore reframes the CISO as a strategic facilitator of secure innovation; a business leader capable of translating technical complexity into business context while helping the enterprise move quickly without sacrificing trust or resilience.
That framing aligns closely with DEW Diligence's operating philosophy. Business strategy, technology, cybersecurity, risk, AI, and financial priorities should function as one defensible operating model. DEW Diligence already positions the CISO discipline around enterprise risk, measurable business consequences, security architecture/engineering, resilience, regulatory requirements, audit readiness, third-party risk, AI security, and board-level decision support.
AI changes the CISO’s unit of accountability
AI is where the evolution becomes most visible. KPMG found that security executives simultaneously view AI-powered attacks as a leading emerging threat and AI as one of cybersecurity's most promising defensive capabilities. Fifty-seven percent expect significant benefit in fraud prevention and 56 percent in predictive threat analytics. Yet only 24 percent reported full AI integration, while 53 percent reported partial implementation. KPMG identifies confidence in the accuracy, reliability, and explainability of AI as a major barrier.
The World Economic Forum's Global Cybersecurity Outlook 2026 reinforces the point. Ninety-four percent of its respondents expect AI to be the most significant driver of cybersecurity change; 87 percent identified AI-related vulnerabilities as the fastest-growing cyber risk. At the same time, 77 percent reported using AI within cybersecurity. AI security assessment has improved from 37 percent of organizations in 2025 to 64 percent in 2026, but roughly one-third still lack a process for validating AI security before deployment.
The implication for the CISO is astounding. The security boundary is no longer users, endpoints, applications, networks, and data. It includes models, prompts, retrieval systems, APIs, agents, tool permissions, machine identities, training and inference data, orchestration layers, and automated decisions. This is why AI governance cannot just be handed to the security department. The CISO should be a principal participant, but AI accountability must span the CIO, CTO, data leadership, Legal, Compliance, Privacy, Risk, Product, Internal Audit, business executives, and ultimately the governing body.
NIST's AI RMF provides the useful lifecycle logic of Govern, Map, Measure, and Manage, while ISO/IEC 42001 establishes a formal AI management system structure. MITRE ATLAS adds an adversarial perspective for AI-enabled systems, including generative and agentic AI threats. A useful distinction for executives is that human-in-the-loop is not the same thing as human accountability. Someone must remain accountable for what an AI system is permitted to do, what information it may access, how much authority it may exercise, when human intervention is mandatory, and how the organization stops or reverses its actions.
From security architecture to enterprise control architecture
KPMG also identifies technology complexity and fragmented security systems as major obstacles to predictive defense. Only 14 percent of surveyed organizations characterized their vulnerability-management posture as advanced and predictive. KPMG's answer is less about adding point products and more about greater architectural integration, centralized security data, better inventories, and convergence between security operations and continuous exposure management.
DEW Diligence would broaden that architecture slightly. The future CISO needs an enterprise control architecture connecting assets, identities, data, business processes, threats, vulnerabilities, controls, telemetry, incidents, obligations, and risk ownership. Security data becomes valuable when executives can trace a line from business objective to technology dependency to threat scenario to control to residual risk to financial/operational consequence to management decision. That is significantly more useful than a dashboard reporting thousands of vulnerabilities. There is also a caution here, as centralizing telemetry into a security data lake is not inherently an improvement if ownership, classification, access, retention, privacy, data quality, lineage, and evidentiary integrity are weak. The architecture itself must be governed.
The board conversation becomes a capital-allocation conversation
One of KPMG's strongest observations is that cybersecurity reporting has to move beyond technical activity. Forty-two percent of surveyed leaders reported difficulty demonstrating cybersecurity ROI. KPMG argues that boards need to understand consequences such as productivity loss, diminished customer trust, intellectual-property loss, operational disruption, and supply-chain impact, not just vulnerability counts and patch statistics. Nearly half of respondents are already using formal risk-quantification methods such as FAIR to improve that translation.
This is where the CISO is distinct from a traditional security manager. A board does not ultimately need to know that 17,000 vulnerabilities exist. It needs to know which risk scenarios could materially disrupt revenue, customers, operations, legal obligations, strategic initiatives, or enterprise value; whether those exposures exceed risk appetite; what management can do about them; what treatment costs; and what residual exposure remains afterward. Cybersecurity then becomes capital allocation under uncertainty.
That model also fits NIST's cybersecurity framework, NIST CSF 2.0, which deliberately elevated Govern into a sixth Framework Function and provides guidance for integrating cybersecurity risk into enterprise risk management. ISACA's COBIT framework connects enterprise information and technology to organizational goals, while COSO ERM provides the larger strategy-and-performance structure into which technology and cyber risks can be integrated.
Regulation is reinforcing the strategic CISO model
The regulatory direction mirrors KPMG's thesis that cybersecurity governance belongs in enterprise leadership.
Area | Current Anchor | Evolved CISO |
Enterprise cyber governance | NIST CSF 2.0; COBIT 2019; COSO ERM | Connect cyber risk to enterprise objectives, risk appetite, ownership, investment, and performance. These are primarily governance frameworks, not universal legal mandates. |
AI governance & security | NIST AI RMF 1.0/2.0; NIST GenAI Profile; ISO/IEC 42001; MITRE ATLAS; OWASP AISVS | Establish AI inventories, risk classification, lifecycle controls, testing, security, accountability, monitoring, and incident processes. NIST AI RMF remains voluntary and is undergoing revision; ISO/IEC 42001 is a certifiable management-system standard. |
Public companies | SEC Regulation S-K Item 106 | Applicable registrants must disclose processes for managing material cybersecurity risks, board oversight, and management's role—reinforcing the need for enterprise-level cyber governance. |
Financial services | FTC Safeguards Rule; NYDFS Part 500; EU DORA where applicable | Covered organizations face explicit expectations for qualified security leadership, risk assessment, board reporting, governance, resilience, and third-party oversight. NYDFS specifically requires the CISO to report at least annually to the senior governing body. |
Healthcare | HIPAA Rules | Covered entities and business associates must protect ePHI through administrative, physical, and technical safeguards and perform risk analysis and risk management. Importantly, HHS still identifies the 2025 modernization package as a proposed rule; the existing Security Rule remains in effect. |
Payments / digital commerce | PCI DSS v4.0.1 | Organizations handling payment-account data must operationalize security as business-as-usual across access, data protection, vulnerability management, monitoring and governance. PCI DSS v4.0.1 is the active version, with its future-dated requirements having taken effect in 2025. |
European AI operations | EU AI Act | The Regulation broadly became applicable on August 2, 2026. Most remaining provisions, including Article 50 transparency duties, applied on August 2, 2026. The Digital Omnibus deferred high-risk obligations to December 2027 (Annex III) and August 2028 (Annex I), subject to staggered provisions and exceptions. AI governance therefore carries direct compliance implications for organizations operating within scope. |
This is not an exhaustive list and can vary depending on location, business, role, and responsibilities.
This regulatory convergence changes the question from “Who runs cybersecurity?” to “Who can demonstrate that technology risk is being governed?” That evidence must survive board scrutiny, regulatory examination, customer due diligence, audit, litigation, and when things go badly, post-incident reconstruction.
What the evolved CISO needs to become
The CISO's strategic priorities now extend well beyond security operations. The role must simultaneously govern material cyber risk, strengthen resilience, simplify architecture, protect data, govern human and nonhuman identities, secure AI adoption, manage third-party concentration, prepare for cryptographic transition, develop talent, and demonstrate that security investment changes business outcomes.
Post-quantum preparation illustrates the difference between operational and strategic thinking. KPMG found only 27 percent of respondents actively implementing PQC. Since then, the practical case for action has become clearer. NIST has post-quantum standards prepared to implement and advises organizations to begin migration and not wait for cryptographically relevant quantum computers to arrive. The same evolution applies to the CISO's own capabilities.
Executive capability | What the Principal-level CISO should understand |
Business strategy & finance | Business models, FP&A, CAPEX/OPEX, ROI/TCO, portfolio management, program development, value realization, and investment trade-offs. |
ERM & governance | Risk appetite, scenario analysis, FAIR or other quantification methods, COSO, COBIT, NIST CSF & PF (Privacy Framework), internal control, assurance, and decision rights. |
AI strategy & risk | NIST AI RMF, ISO/IEC 42001, MITRE ATLAS, OWASP AISVS, AI lifecycle governance, model and data risk, LLM security, GenAI, agentic AI, human oversight, third-party AI, and secure AI architecture. |
Architecture & engineering | Cloud, identity & access (including security key and passkey modernization), Zero Trust, data architecture, APIs, DevSecOps, SaaS, OT/IoT and emerging technology — enough depth to challenge architecture, engineering, and control assumptions intelligently. |
Law, regulation & privacy | Sector-specific regulatory obligations, disclosure requirements, privacy, contractual risk, and US/Global regulatory expectations. |
Executive communication | Board reporting, crisis leadership, business cases, market competition insights, risk narratives, and the ability to express technical exposure in financial, operational, and strategic terms. |
Leadership & workforce strategy | AI security skills & talent development, organizational design, sourcing, managed services, automation, succession, and the redesign of work as AI absorbs repeatable operational tasks. |
This is not an exhaustive list and can vary depending on location, business, role, and responsibilities.
The DEW Diligence perspective
KPMG's findings make a compelling case that the CISO must evolve from defender of technology to protector of business value. DEW Diligence's extension is that the next stage goes even further, as the Principal-level CISO becomes a business technology-risk integrator. The organization does not need a security leader who says no more intelligently. It needs one who can say "yes, under these conditions, with these controls, within this risk tolerance, for this investment, with this accountable owner, and with evidence showing that the decision remains defensible over time."
That is what “speed with safety” looks like when turned into an operating model. It is also why cybersecurity, Responsible AI, enterprise architecture, financial stewardship and risk governance, and technology are converging. The organizations best positioned for the AI era will be those capable of moving deliberately fast, knowing what they are protecting, what they are risking, what they are investing, who is accountable, and when the evidence says the enterprise needs to change course.
That is the evolving mandate of the CISO: not a function beside the business, but part of its operating system.
Want more on this topic? Contact us for a consultation, and review our services for fractional & virtual CIO, CISO, and CTO executive consulting.
David E. Williams, CISM, GSTRT, GSLC
Founding Principal, DEW Diligence, LLC





Comments