Skip to content
Tech News
← Back to articles

CISOs Feel the Heat Over AI Risk

read original more articles
Why This Matters

The rapid adoption of AI in the cybersecurity landscape is increasing the burden and stress on CISOs, raising concerns over legal liability, attack surface expansion, and operational complexity. This shift underscores the urgent need for robust AI governance and risk management strategies within organizations, impacting both industry standards and consumer trust in AI-driven security solutions.

Key Takeaways

The chaotic adoption of AI technologies and the resulting expansion in the cyberattack surface have added stress to the professional lives of many top cybersecurity executives, leading some to consider leaving the industry.

In fact, a quarter of security executives (26%) considered leaving their job in the past 12 months, according a recent column written by Splunk field chief information security officer (CISO) Kirsty Paine. Data drawn from two Splunk surveys found that a mix of fears around legal exposure and the increasing complexity posed by the rapid adoption of AI is leading to a maelstrom of angst. Nearly every CISO (96%) has become responsible for AI governance and risk management, while a full 78% of CISOs have concerns over personal liability that could stem from a cybersecurity incident affecting their business, according to Splunk's "The CISO Report: From Risk to Resilience in the AI Era."

Related:Agentic AI: Taming the Unpredictable

"For CISOs that were already concerned about personal liability, that anxiety is likely increasing because of AI and the broadening attack surface — suddenly, lower-skilled attackers have access to new tools that allow them to do a lot of damage," Michael Fanning, CISO at Splunk, tells Dark Reading. "As companies adopt AI internally, that also poses new potential risks."

In June, a survey found that two-thirds of security professionals found their job more complex today than two years ago, thanks to overwhelming workloads and keeping up with new technologies like AI, and employees adding shadow AI to the mix. But unfortunately, in the near term, CISOs are unlikely to get relief. The top security executives are being tasked with greater responsibility for AI governance, are held to more strict requirements for incident disclosure, and have to deal with a lack of monitoring and best practices around autonomous agents, says Fanning.

"To be successful, CISOs need to understand how agents call [out to] tools, how they authenticate, [and] what they connect to," he says. "These are all concepts we've worked on throughout our careers, but AI adds a new dimension with an accelerated adoption rate, adding to that challenge."

Educate Your Executive Team on AI Security

Unfortunately, AI is popping up everywhere like a virus, with many employees building applications using vibe coding and trying to integrate AI into the business at scale — even to the point of not declaring when they are using AI and creating shadow AI exposure, says TJ Marlin, CEO of Guardrail Technologies, an AI security provider.

Related:Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife

"We used to worry about people coming in the back door, and now we're opening the front door to AI, and organizations are ill-equipped," Marlin says, pointing out that there is a huge gap between how business management approaches AI and how the technical teams do. As with many tech evolutions in the past, businesses are pushing to get AI out into real-world usage as quickly as possible, and security is looked upon as a block to progress.

... continue reading