Three, Four

Three in Four Security Chiefs Say They Can't See What Their AI Systems Are Doing

Published on 10/01/2026 at 03:50 | Editorial boerse-global.de

KPMG sees the CISO job shifting to broader risk strategy as AI visibility gaps, NIS-2 rules and rising cyber damage reshape security leadership.

CISO Role Redefined: AI Risk, NIS-2 Deadlines and 267 Billion Euro Losses
Three in Four Security Chiefs Say They Can't See What Their AI Systems Are Doing Illustration mit AI erstellt.

Security leadership is being rewritten in real time. According to KPMG, the job of the Chief Information Security Officer is undergoing a fundamental redefinition, driven by digital platforms, artificial intelligence and sprawling third-party ecosystems. The role is shifting toward something more strategic and more agile — and the people holding it are expected to move faster against threats while carrying broader responsibility for company-wide risk.

That responsibility increasingly means coordinating protections across departments rather than within a single security function. AI agents may soon handle operational tasks on their own, leaving humans to define and monitor the outcomes.

Wolfgang Goerlich expects CISOs to hold general risk responsibility by 2029. Diana Kelley sees a possible organisational split, with separate roles for pure defence on one side and risk and resilience management on the other.

Where the CISO's authority ends

Ahead of the ECSO CISO Meetup in Berlin, Matthias Muhlert drew a firm line around the role's remit. Business decisions — and the cyber risks that come with them — stay with the relevant department heads. The CISO's job, in his telling, is to advise, to reduce risk and to escalate when necessary.

For board reporting, Muhlert recommends plain transparency: show what has been demonstrated under which specific conditions, which assumptions remain untested, and which tests come next. Supplier access, reachability and recovery processes should be settled in advance and rehearsed in practice.

Blind spots in AI data flows

New technology is straining security teams. A global survey of more than 300 CISOs by Gigamon found that 76 percent rate limited visibility into AI data traffic as a major obstacle to deploying AI securely. Nearly half — 45 percent — assign high priority to better transparency over AI data flows in hybrid cloud environments. And 87 percent regard so-called deep observability as a basic precondition for IT security in an AI context.

Among German organisations hit by security incidents last year, 82 percent recorded AI-related events. A third, 33 percent, reported data leaking into AI systems, while 30 percent faced unauthorised AI use. At the same time, seven in ten CISOs worldwide see gaps in security knowledge at leadership level.

Confidence diverges sharply when a crisis hits. Only 27 percent of CISOs believe they could identify the cause of an incident and restore normal operations within 72 hours. Among other C-level executives, 48 percent assume they could.

Regulation tightens as losses mount

Legal deadlines are accelerating the overhaul. Germany's law implementing the NIS-2 Directive has applied since 6 December 2025, and reporting obligations for manufacturers under the Cyber Resilience Act take effect from 11 September 2026.

The rules impose binding timelines: an initial notification within 24 hours of an incident, an assessment report within 72 hours, and a final report after one month. Penalties for particularly important entities reach up to 10 million euros or two percent of worldwide turnover from the previous year.

The cost of doing nothing is already visible. Bitkom puts annual damage from cyberattacks in Germany at more than 267 billion euros. Its 2026 business protection study found that 67 percent of surveyed companies with at least ten employees were definitely affected by data theft, espionage or sabotage over the previous twelve months.

To keep pace, industry experts advise tying existing management systems closely to statutory evidence requirements — and rehearsing emergency procedures with executive management involved at least once a year.

Disclaimer...

en | boerse | 70207249 |