Content and Authority for AI Answers

The CISO’s AI Priority List: What Changes and What Doesn’t

The CISO’s AI Priority List - What Changes and What Doesn’t

The CISO’s AI Priority List - What Changes and What Doesn’t

Grant Yacomeni, CISO at Gigamon, explains what is and isn’t changing in the CISO’s AI priority list. This article originally appeared in Insight Jam, an enterprise IT community that enables human conversation on AI.

AI agents are quickly changing how organizations operate. They can access enterprise data, interact with applications, call external tools, and take actions with less human involvement.

Recent developments are also showing how difficult that activity can be to control. This month, OpenAI disclosed that an internal research agent found a gap in its sandbox controls and reached an external chatbot despite restrictions on internet access. Anthropic separately reported malicious actors using agent swarms to divide and execute reconnaissance and post-exploitation tasks in parallel. For CISOs, these developments reinforce a challenge that is already taking shape.

Nearly every CISO faces the same tension: their organization wants to move faster with AI adoption, while the security team must understand and manage the new risks that come with it. AI is optimizing the capabilities available to attackers and introducing more autonomous activity inside enterprise environments. According to the Gigamon Hybrid Cloud Security Survey, 41 percent of organizations experienced external attacks involving AI over the past year, while 33 percent experienced direct attacks on AI or LLM systems.

With AI changing both the business and the threat environment, it can be tempting to assume cybersecurity needs an entirely new playbook.

It needs to be changed, but not thrown out.

The fundamentals of cybersecurity remain critical to resilience. What is changing is the environment around them. CISOs need to apply those fundamentals while establishing stronger governance, improving visibility into how AI is actually being used, and building processes that can evolve as AI adoption accelerates.

Turn AI Policy Into Actionable Governance

Most organizations are establishing rules around approved AI tools, the data those tools can access, and how employees can use them. Those policies are important, but policy alone is not governance.

Governance requires understanding whether those rules are actually being followed. CISOs should be able to answer some basic questions. What AI systems are operating across the organization? Who owns them? What data can they access? What other systems can they communicate with? What actions are they authorized to take?

These questions also apply to AI tools that the security organization did not approve. Gigamon research found that 43 percent of CISOs are strengthening governance to ensure AI is used safely, and 41 percent put corporate governance at the top of their security priorities.

In practice, governance starts with understanding what has been deployed and assigning clear ownership. For example, access should match what an AI system actually needs to do, and permissions should also be reassessed as an agent’s responsibilities change.

The technology will continue to evolve, but the underlying principle is familiar: establish boundaries, enforce them, and verify that they are working.

Close Visibility Gaps Across AI Environments

CISOs cannot secure or govern activity they cannot see.

Consider an AI agent tasked with resolving a customer issue. It might retrieve information from a database, call an externally hosted model, interact with a CRM application, and then make a change to an internal system. Security teams may have logs from several of those components without having a complete view of the interaction.

Closing visibility gaps matters when something goes wrong. More than a quarter (76 percent) of CISOs say limited visibility into AI-driven traffic is a major barrier to securing AI adoption, while 46 percent say AI-driven traffic is making breaches harder to identify and investigate. Teams need to determine what the agent accessed, where data moved, which systems were involved, and whether its actions remained within approved boundaries.

To ensure organizations have a complete view of how AI operates across their infrastructure, CISOs should start by identifying where visibility breaks down in their AI environments. A useful test is whether the security team can reconstruct an agent’s activity from beginning to end: which identity it used, what data it accessed, which systems it communicated with, and what action it ultimately took.

Visibility supports more than threat detection; it provides evidence that governance controls are functioning as intended.

Do Not Let AI Distract From the Fundamentals

AI introduces new risks, but it does not eliminate the old ones.

Every major technology shift creates pressure to focus on the newest threat and the newest security technology. That can pull attention away from the practices that remain fundamental to resilience, especially for smaller teams.

Patching is one example. AI can help attackers identify weaknesses and operate at greater velocity, significantly shortening the time between enumeration and mitigation. Security teams cannot stop patching because a new AI threat dominates the news cycle. They also cannot assume that adding another tool will compensate for weaknesses in their existing security processes.

For CISOs, this means continuing to measure whether foundational practices are actually working.  One practice is “sustains and improves,” also known as lessons learned. This means measuring a team’s effectiveness against their own processes and having honest conversations afterward on how things went. The things the team did well (sustains) and areas they fell short (improves), and developing action plans from those areas for improvement. Continuous improvement is incredibly important. Simply assuming that because a process is in place, it does not always return intended results, without measuring regularly.

Being flawless at the basics is not a solution to AI risk. But if organizations cannot consistently execute those basics, they will have an even harder time defending against threats moving at AI speed.

Create a Security Foundation That Can Evolve

AI introduces new technologies, new threats, and new governance questions, but it doesn’t require CISOs to abandon what they already know about building resilient security organizations.

The strongest approach combines the old and the new: execute relentlessly on fundamentals such as vulnerability and configuration management, while developing the governance and visibility needed for AI environments. Then put the people, processes, and feedback loops behind those practices so they can evolve.

The current AI landscape can create the illusion that a CISO’s job is to choose between innovation and security, but with balance and strong governance, CISOs can build a security foundation that is both strong and adaptable enough to support both.


Share This

Related Posts

Solutions Review Events Ad

Solutions Review Thought Leaders Ad