Skip to content

Posts tagged ‘CISOs’

34% of enterprises govern AI with policies they only partly follow. Gartner’s first AI Governance Hype Cycle shows CISOs what to fund first.

Gartner Hype Cycle for AI Governance, 2026, showing AI cybersecurity governance, AI governance platforms, and agentic AI risk innovations plotted across the innovation trigger, peak, trough, slope, and plateau phases. Please click on the graphic to expand for easier reading.

Gartner’s 2026 AI Leaders Effectiveness Survey found that 34% of organizations have well-defined AI governance structures and policies for managing risks, ethics, and compliance. Those same organizations report only partial adherence to the rules they wrote, while another 22% still rely on basic or ad hoc policies. Only 7% qualify as recognized leaders in ethical AI.

That gap between writing the policy and living by it is what Gartner’s first Hype Cycle for AI Governance, 2026 is built to address. Published July 21, 2026, the inaugural cycle plots 32 innovations and ranks each by benefit rating and years to mainstream adoption. CISOs and enterprise architects get a planning map that builds on Gartner’s forecast that agentic AI will overtake chatbot spending by 2027. Throughout this post, I use “rogue agents” as my editorial shorthand for unsanctioned AI agents operating outside governance perimeters.

The two clusters that carry the security agenda

The report organizes its 32 innovations around six enterprise trends. Two carry the security agenda. Agentic AI oversight and life cycle governance is the first, grouping agentic AI governance, agent development life cycle, AI agent identity, AI engineering, AI gateways and AI governance platforms under one trend. Advancing AI security is the second, covering AI TRiSM, AI cybersecurity governance, disinformation security, zero-trust data governance, mechanistic interpretability and AI product attribution and transparency. Together they define where governance stacks connect to identity systems, traffic controls and incident response playbooks. For how these gaps show up in spending data, see my analysis of Gartner’s $248.9B security forecast.

Five innovations that pay off in under two years

Table 1, the Priority Matrix, ranks every innovation by benefit rating and adoption timeline. Only five entries land in the “Less Than 2 Years” column. Responsible AI sits alone in the Transformational row, Gartner’s highest rating. AI guardrails, data access governance, digital ethics and ontologies all carry High benefit ratings at the same timeline. Gartner calls these the near-term priorities for scalable governance. CISOs should fund them first.

Please click on the image to expand for easier reading.

The two-to-five-year column is the densest band. Thirteen innovations carry a High benefit rating there, including agentic AI governance, AI agent identity, AI TRiSM, zero-trust data governance and third-party risk management. That band is where CISOs will build governance stacks over the next several budget cycles. For context on spending already flowing to AI-related capabilities, see my breakdown of Gartner’s $244.2B security forecast.

Where AI cybersecurity governance actually lands

AI cybersecurity governance carries a Moderate benefit rating at the Innovation Trigger, five to ten years from mainstream adoption. That placement may surprise CISOs who expected Gartner to rate it higher. The profile’s key goals are to prevent shadow AI, minimize attack surfaces and ensure visibility and response to incidents. The placement is a market signal, not a dismissal. Tooling is early, but the need is urgent enough that CISOs should treat AI cybersecurity governance as an architecture requirement today.

What the Priority Matrix tells your board

The report leads with two strategic planning assumptions that carry board-level weight. Enterprises implementing AI governance will outperform ungoverned competitors in AI adoption by 25% by 2029. The downside is just as concrete. Autonomous agents identifying minor consumer rights violations and turning them into lawsuits will increase corporate settlement costs by 15% over the same period. Growth-oriented executives respond to the first number. Risk-averse ones respond to the second.

Turning the curve into controls

Start by mapping your AI agent footprint, sanctioned and unsanctioned, across SaaS platforms, internal applications and shadow IT. From there, match the Hype Cycle’s innovations to four governance domains. The identity and access layer runs on AI agent identity and AI governance platforms. Data classification draws on AI guardrails, data access governance and zero-trust data governance, while AI gateways and AI TRiSM handle traffic mediation. Agent risk management anchors in agentic AI governance and the agent development life cycle. Build all four as shared services. For how agent sprawl is reshaping security spending, see my roundup of agentic AI forecasts and market estimates, 2026.

What these numbers add up to

Gartner’s inaugural Hype Cycle for AI Governance puts 32 innovations on the curve. Only five reach mainstream adoption in under two years. The security-relevant capabilities cluster in the two-to-five-year band, which means CISOs have a narrow window to build governance stacks before agent footprints outpace controls. The 34% adherence stat is the warning, and the Priority Matrix is the roadmap out of it.

This post is my personal reflection on Gartner’s AI governance research from a CISO and enterprise architecture perspective. It does not represent any employer or client.

Source: Gartner, Hype Cycle for AI Governance, 2026, Svetlana Sicular, Var Shankar, Lauren Kornutick, Sumit Agarwal, 21 July 2026, G00854164.

Top Ten Insights from Forrester’s 2024 Cybersecurity Budget Benchmarks

Top Ten Insights from Forrester's 2024 Cybersecurity Budget Benchmarks

CISOs are being asked to do a lot more with less as their businesses are going all-in on new digital businesses that demand identity-based security while keeping budgets tight for securing infrastructure against attacks.

Cybersecurity budgets are, on average, just 5.7% of IT annual spending. That’s tight for many security teams. CISOs are rising to the challenge, however, and delivering revenue gains by protecting new digital businesses while keeping infrastructure safe. Achieving that is a quick way for CISOs to advance their careers.

Cybersecurity needs funding to match its business growth potential

The good news is that more CEOs and boards see cybersecurity as a business enabler. The challenge for CISOs, however, is that cybersecurity still gets funded purely for its defensive value – not its upside potential to drive growth.

Many security teams struggle to make ends meet in their budgets while still staying responsive to internal teams’ needs. Forrester’s 2024 Cybersecurity Benchmarks Global Report shows just how tight budgets can get for a CISO and their team. Project-related work and incident management are a constant balancing act for security teams, and keeping them both in check is key to staying under budget.

Top Ten Insights

Cybersecurity budgets are on the low side compared to the growing complexity of threats and risks organizations face.

That’s forcing CISOs to be selective about what they spend on and how they allocate limited resources. Add to that the average spend of $1,070 per enterprise user and $157,000 per cybersecurity employee, and cybersecurity teams have little, if any, room for inefficiencies.

The following are the top ten insights from Forrester’s latest cybersecurity benchmark report:

  • CISOs need to move out of the IT organization and report to their CEOs and board of directors to have a chance at a more realistic budget. Forrester finds that cybersecurity budgets increase when CISOs report directly to the CEO or board of directors. CISOs who can articulate the business value of cybersecurity, demonstrating how it can drive revenue and support strategic goals, are more likely to secure the necessary funding. This shift also reflects a growing recognition of cybersecurity’s strategic importance beyond mere IT operations.
  • Software will dominate cybersecurity budgets in 2024. The report reveals that 35.9% of cybersecurity budgets globally are allocated to software. This trend is particularly pronounced in large enterprises with up to 74,999 employees, where 39.4% of the budget is dedicated to software. Smaller organizations, conversely, spend a higher percentage on outsourcing services due to limited in-house capabilities, which underscores the scalability challenges smaller firms face in maintaining robust cybersecurity defenses.
Top Ten Insights from Forrester's 2024 Cybersecurity Budget Benchmarks

Source: Forrester 2024 Cybersecurity Benchmarks Global Report

  • Cybersecurity spending per user keeps climbing, reaching $1,070. This is another budget constraint CISOs have to factor into their total operations plans for a given year. Forrester notes that “the cybersecurity spend per enterprise user ranges from an average of $947 at extra-large organizations (75,000 or more users) to $1,210 at small organizations (fewer than 10,000 users).
  • Personnel costs consume 28% of the typical security budget. The report highlights that organizations are spending an average of $157,593 per cybersecurity employee. Full-time employees make up 73.5% of security teams, with the global average cost per contracted full-time equivalent (FTE) reaching $194,613. This significant expenditure on personnel underscores the critical role of skilled professionals in maintaining effective cybersecurity defenses.
Top Ten Insights from Forrester's 2024 Cybersecurity Budget Benchmarks
Source:  Forrester 2024 Cybersecurity Benchmarks Global Report
  • System Defense is the leading functional spend category in 2024. Forrester finds that 29% of functional spending is in System Defense alone. The funding levels approved for this category reflect the critical need to protect endpoints and mobile devices against increasingly sophisticated attacks. With adversaries innovating faster than enterprises can keep up, System Defense is a must-have to protect new digital businesses and infrastructure. The following graphic shows cybersecurity spending by functional domain.
Top Ten Insights from Forrester's 2024 Cybersecurity Budget Benchmarks
Source:  Forrester 2024 Cybersecurity Benchmarks Global Report
  • Identity and Access Management (IAM) takes up 21% of functional spending in the typical budget. Identity-driven attacks take many forms, from mass phishing to whale phishing, where senior executives of a company are targeted with tailored campaigns IAM also enhances operational efficiency and fraud reduction, making it a strategic investment for many organizations. Its broad applicability across both internal and customer-facing applications drives its substantial share of the cybersecurity budget.
  • Security analytics and incident handling reach 13% and 14%, respectively. Forrester notes that each of these separate services accounts for a relatively low percentage of the overall cybersecurity budget. Still, most organizations combine spending on these two categories into “detection and response.” Both areas combined equal 26% of the overall security budget, on average.
  • Getting compliance and governance right is a growing concern for many CISOs who are willing to spend their budget to stay in good standing with the SEC. The Security and Exchange Commission’s Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure adopted on July 26, 2023. The rules adopted by the SEC define a standardized process for cybersecurity disclosures for public companies. These rules require companies to disclose material cybersecurity incidents on Form 8-K or Form 6-K within four business days of determining the incident’s materiality. Additionally, companies must include cybersecurity risk management, strategy, and governance information in their annual reports (Forms 10-K and 20-F). The rules also mandate the use of Inline XBRL for tagging these disclosures.
  • Incident handling is on average, 13.5% of a global cybersecurity budget. This category is the most unpredictable, as it deals with responding to intrusions and breaches that cannot be forecasted. Spending on incident handling varies by company size, with small organizations (fewer than 10,000 employees) aligning with the global average of 13.5%. Larger organizations tend to allocate slightly less, likely due to more extensive preventative measures and diversified cybersecurity resources.
  • Privacy is core to customer trust today and gets funded, even in tough budgeting cycles. The two departments that use privacy-related solutions the most frequently are legal and marketing, which dedicate on average 12% of a cybersecurity budget to them. Forrester notes that this 12% figure is not the total privacy spend of an organization. Rather, the report says, “Data privacy spans multiple areas of the organization, including marketing and legal. Its share of the security budget doesn’t represent the total spending on privacy-related initiatives across the entire technology estate.

Balancing the scales of cybersecurity budgeting

The bottom line is that cybersecurity is a business decision and needs to be funded with that mindset. Organizations need to see the CISO role as a more board-level one so they can share their technology expertise in helping to manage risk.

It’s time for cybersecurity to be funded as a growth engine, not just one used for deterrence alone.

CISOs can balance the scales by looking for an opportunity to elevate their role to a CEO direct report and, ideally, be on the board to help guide their companies through an increasingly complex threat landscape.

The Pandemic Is Teaching Enterprises How To Mind The Cybersecurity Gap

The Pandemic Is Teaching Enterprises How To Mind The Cybersecurity Gap

  • 30% of US and UK remote workers say their organizations don’t require them to use a secure access tool, including VPN, to log into corporate databases and systems, according to Ivanti’s 2021 Secure Consumer Cyber Report.
  • Plus, 25% of remote workers in the US and UK aren’t required to have specific security software running on their devices to access certain applications while working remotely.
  • And one in four US remote workers use their work email and passwords to log in to consumer websites and apps.

Cybersecurity gaps have continued to widen during the pandemic. A noteworthy survey by Ivanti illustrates exactly how remote workers are putting organizations at risk and where enterprise security is falling short, making those cybersecurity gaps challenging for CISOs to close. Ivanti’s 2021 Secure Consumer Cyber Report outlines the challenges that cybersecurity and IT teams have faced when securing remote workers in what’s being described as the “Everywhere Workplace.” Based on interviews with more than 2,000 US and UK respondents working from home in November 2020, the survey shows that authentication and endpoint security needs to improve across all devices that employees use.

IT Organizations Need Help Closing Their Cybersecurity  Gaps

Of the many lessons learned from 2020, among the most valuable are how virtual workforces need self-diagnosing and self-remediating endpoints, while IT organizations need improved unified endpoint management (UEM) as part of a zero-trust strategy. Bad actors continue to target remote workers’ privileged access credentials to gain access and exfiltrate customer, financial and proprietary data, including intellectual property. Ivanti’s survey provides insights into where cybersecurity gaps need attention first:

  • The most challenging threat surface to protect is a person’s identity because it’s exposed across so many threat surfaces, including personal and work devices, consumer websites, and IoT devices in homes. The pandemic is proving identities are the new security perimeter. A person’s cell phone, personal tablet, and laptop is a real-time digital definition of a person’s identity. Nearly half (49%) of US remote workers use personal devices for their jobs, often without two-factor authentication enabled. The graphic below shows how organizations can close this cybersecurity gap by adopting UEM as part of their go-forward initiatives in 2021 and beyond:

The Pandemic Is Teaching Enterprises How To Mind The Cybersecurity Gap

  • Lack of consistent security software and password standards is a big contributor to US and UK organizations’ cybersecurity gaps today. One in four remote workers can access enterprise resources without any security software in place. An even more surprising finding is that 30% of remote workers in the US and UK can access corporate data without a secure access tool or VPN connection. If a remote worker’s identity is compromised, there’s a one in three chance that their organization will be breached, enabling cyberattackers to move laterally through the company’s systems:

The Pandemic Is Teaching Enterprises How To Mind The Cybersecurity Gap

  • Protecting remote workers’ identities & devices at scale requires Zero Trust. Automating as many tasks as possible while providing a continuous and seamless user experience is the surest way to close cybersecurity gaps. Getting rid of passwords and automating two-factor authentication using Zero Sign-On (ZSO), a core part of the Ivanti platform, is proving essential today. Zero Sign-On relies on proven biometrics, including Apple’s Face ID, as a secondary authentication factor to gain access to work email, unified communications and collaboration tools, and corporate-shared databases and resources. CISOs and their teams also need to consider how mobile threat defense can better secure personal devices against phishing, device, network, and malicious app threats. Late last year, MobileIron (now part of Ivanti) received its second mention in two years in the Forrester Wave™: Zero Trust eXtended Ecosystem Platform Providers, Q3 2020. The Forrester Wave graphic is shown below:

The Pandemic Is Teaching Enterprises How To Mind The Cybersecurity Gap

  • In conclusion, enterprise cybersecurity gaps are widening due to a combination of risky consumer behavior and a lack of consistent security for mobile workforces. And these gaps will only increase as employees increasingly work from anywhere, using their personal devices to connect to corporate resources. To secure and enable the future of work, organizations need to start implementing and maturing an end-to-end zero trust security model today by leveraging new technologies and protecting their current security technology investments.