news.mlab.sh
Back to the feed
threat-intel

CISOs Feel the Heat Over AI Risk

High
Summary

CISOs are facing increased pressure and job insecurity due to the rapid and often chaotic adoption of AI within companies. A recent Splunk survey revealed that 26% of top security executives are considering leaving their positions, driven by concerns about legal exposure, the expanding attack surface, and a lack of cybersecurity fluency among business leaders. Despite the challenges, AI is also providing security teams with increased event review capabilities and improved data correlation, but only with careful governance and a shared understanding between technical and business teams.

CISOs Feel the Heat Over AI Risk

Job pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position. The chaotic adoption of AI technologies and the resulting expansion in the cyberattack surface have added stress to the professional lives of many top cybersecurity executives, leading some to consider leaving the industry.

In fact, a quarter of security executives (26%) considered leaving their job in the past 12 months, according to a recent Splunk survey. Data drawn from two Splunk surveys found that a mix of fears around legal exposure and the increasing complexity posed by the rapid adoption of AI is leading to a maelstrom of angst. Nearly every CISO (96%) has become responsible for AI governance and risk management, while a full 78% of CISOs have concerns over personal liability that could stem from a cybersecurity incident affecting their business, according to Splunk's "The CISO Report: From Risk to Resilience in the AI Era."

"For CISOs that were already concerned about personal liability, that anxiety is likely increasing because of AI and the broadening attack surface — suddenly, lower-skilled attackers have access to new tools that allow them to do a lot of damage," Michael Fanning, CISO at Splunk, tells Dark Reading. "As companies adopt AI internally, that also poses new potential risks."

Educate Your Executive Team on AI Security

Unfortunately, AI is popping up everywhere like a virus, with many employees building applications using vibe coding and trying to integrate AI into the business at scale — even to the point of not declaring when they are using AI and creating shadow AI exposure, says TJ Marlin, CEO of Guardrail Technologies, an AI security provider. "We used to worry about people coming in the back door, and now we're opening the front door to AI, and organizations are ill-equipped," Marlin says, pointing out that there is a huge gap between how business management approaches AI and how the technical teams do. As with many tech evolutions in the past, businesses are pushing to get AI out into real-world usage as quickly as possible, and security is looked upon as a block to progress.

The AI security issue is made worse by the fact that the vast majority of C-suite executives do not understand the cybersecurity considerations in the first place, Splunk found in its survey. Nearly seven in every eight CISOs (85%) identified a lack of cybersecurity fluency among business leaders as their most significant hurdle, Splunk's Fanning says. "The path forward is a shared language, using data and business context to translate technical language into terms the whole C-suite can act on," he says.

AI: A Double-Edged Sword for Security

The cost overruns due to AI and the sheer amount of information it generates internally are giving some companies pause, and cybersecurity teams can benefit from increased caution, experts say. But while AI has created more headaches and disruption to cybersecurity governance, the technology is also helping CISOs and their security teams tackle increasingly complex security tasks. As for the former, in one survey, 87% of security professionals responded that AI is significantly increasing the workload of their teams. And indeed, data leakage, shadow AI, and the lack of visibility into the actions of AI agents are all increasing concerns, so it's important for CISOs to weigh in on how and when AI can be adopted, says Fanning.

"As companies look to roll out AI technology internally, we need to be a part of that process and advocate and build secure best practices," he says. On the positive side, the vast majority of CISOs agree that AI allows more security events to be reviewed (92%) and improves that ability to correlate multiple data streams into an analysis (89%), according to Splunk's report. And in another survey, 9 out of 10 SOC analysts said AI

Read the full article at Dark Reading