Cybersecurity in the Era of AI: What CISOs Actually Need to Get Right
On 12 September I’m on stage in Karachi at the World CIO 200 Summit, Pakistan Edition, part of the ITCN Asia and Tech Destination Pakistan roadshow. My session is called “Cybersecurity in the Era of AI”, and I’m speaking as President of the Global CISO Forum. A forty-minute keynote forces you to cut an argument down to its spine. This post is the fuller version, written for the CISOs and CIOs who won’t be in the room.

AI didn’t wait for governance to catch up
Gartner’s 2026 Leadership Perspective Survey of 1,600 CISOs put “Enabling and Protecting AI” at the top of the CISO functional agenda for the first time this year. Sixty-five percent of respondents are focused on mitigating AI-related risk, fifty-seven percent on improving business outcomes through AI, and forty-two percent on efficiency gains. That is not a research topic any more, it is the job description. The uncomfortable part sits underneath those headline numbers: fifty-six percent cite the pace of change as their biggest obstacle, and fifty-two percent say their teams simply do not have the skills to do this properly yet.
Proofpoint’s 2026 Voice of the CISO report, based on 1,600 CISOs across sixteen countries, tells the same story from a different angle. Seventy-eight percent now consider generative AI a security risk, up from sixty percent a year earlier. That is a fast swing for an industry that usually moves slowly on sentiment. And seventy-nine percent say they are expected to manage AI-related risk without a proportional increase in resources or expertise. Boards asked for AI adoption. Nobody budgeted properly for what securing it would actually cost.
Where the exposure actually sits
Strip away the vendor slideware and the AI-era CISO agenda comes down to five things. Get these wrong and no amount of policy language fixes it.
1. Shadow AI and data governance
Staff were using public GenAI tools with corporate data long before most policies caught up. Seventy-seven percent of CISOs are concerned about customer data being lost through public GenAI tools, and seventy-eight percent of companies now block or restrict employee GenAI use, up from fifty-nine percent last year. I read that rise in restriction as a symptom, not a strategy. Blocking a tool because you cannot see how it is being used is an admission that visibility came second. Fix the visibility first, and the access decisions get easier.
2. Identity for machines, not just people
Agentic AI is creating identity sprawl faster than most IAM programmes can track it. Every autonomous agent, copilot, and automated workflow needs a credential, a scope, and an owner, the same discipline you already apply to human accounts. Most organisations do not have an answer for what happens when an AI agent is retired, or who is accountable when one acts outside its intended scope. That gap is exactly where the next serious incident is going to come from.
3. The model and its supply chain
Prompt injection, data poisoning, and third-party model risk deserve the same supplier scrutiny you already apply elsewhere. If you would not accept a vendor’s vague answer about where your data goes in a standard SaaS contract, do not accept it for an AI vendor either. Ask about training data provenance, update cadence, and what happens to the data you send them.
4. Human risk hasn’t gone away, it has mutated
Seventy-nine percent of CISOs now identify human risk as their organisation’s biggest vulnerability, up from sixty-six percent last year. Malicious insiders are the leading cause of data loss at forty-six percent, and ninety-three percent of CISOs at organisations that experienced material data loss said departing employees played a role. AI raises the stakes on both fronts. A departing employee now has tools that make exfiltration faster and harder to trace, which makes offboarding discipline a security control, not an HR formality.
5. Boards are finally listening, use the opening
Eighty-five percent of CISOs report their boards are aligned with them on cybersecurity, up from sixty-four percent in 2025. That is a rare opening, and it will not stay open by default. It closes the moment board reporting stays stuck on incident counts instead of showing which of the four areas above actually has controls in place and which do not.
The resourcing gap is the real story
I’ll put this more bluntly than the surveys do. Every CISO I talk to, including here at Morgan State, is being asked to secure a fast-expanding AI attack surface with roughly the same headcount and budget they had two years ago. That gap does not close on its own, and pretending it will is how organisations end up performing security theatre around AI policy while the actual exposure goes unaddressed. It is exactly the gap the AI Governance Framework work I do through the Global CISO Forum is built to close: not another glossy AI policy document, but a structured way to map what is actually running, who owns it, and what happens when it fails.
What I’m bringing to Karachi
At the World CIO 200 Summit I’ll be walking through this agenda with the region’s CIOs and CISOs, and pressure-testing it against what they’re actually seeing on the ground in Pakistan and the wider region. If you’re at ITCN Asia or the summit on 12 September, come find me. I’d rather hear where this framework breaks in practice than have it sound tidy from a stage.
Erdal Ozkaya
