Issue 011 organization name it2026 evidence
Cyber risk is ranked in the top three and delegated out of the leadership team
The risk is acknowledged at the top and treated as a technical problem for the security function, so the decisions that actually determine exposure - product design, speed targets, what gets built - are taken elsewhere.
The pattern is well described and recent: chief executives recognise the threat as a first-order business risk and still hand it to a CISO or CIO as a specialist matter rather than holding it as a leadership responsibility. It matters because the security function does not control the variables that set the exposure. It does not choose the latency target that gets a guardrail disabled, or the launch date that skips a review. Ownership has to sit where those trades are made.
How to fix it — 1 approach, 3 steps
Hold the risk where the trade-offs are made
Put accountability for AI security exposure with the executives who set launch dates, latency targets and product scope, not only with the function that implements controls.
Done when An executive who is not the CISO is named accountable for AI security exposure, and the approval record for the most recent AI-enabled product contains a security position.
- Name the executive accountable for AI security exposure who is not the CISO.
- Require a security position in the approval for any new AI-enabled product.
- Report exposure to the board against business decisions, not control counts.
The evidence — 4 documents
| Organization | Document | Position |
|---|---|---|
| Boston Consulting GroupConsultancy · August 2026 | How CEOs should manage escalating cybersecurity risks in the age of AIOur reading Reports that most chief executives place cyber threats among the top three business risks while still treating them as a strictly technical matter to delegate, rather than a responsibility of the whole leadership team.Recognised as a top risk, delegated as a technical issue | names it |
| AWSHyperscaler · April 2025 | Navigating the security landscape of generative AIOur reading Argues the opposite of consolidation: train people inside the delivery and data science teams to run their own reviews and to recognise when to escalate, on the reasoning that a single central function becomes the gate every review waits at, and that each hand-off across an organizational boundary costs something. Offers its own internal programme as the worked example, and is explicit that the posture has to be enablement rather than refusal.Spread the function rather than concentrate it | proposes a fix |
| Boston Consulting GroupConsultancy · August 2026 | How CEOs should manage escalating cybersecurity risks in the age of AIOur reading Proposes building security into the design of new products and services and empowering a cross-functional team to act during incidents, which places the decision where the trade-offs are made.Security inside product design | proposes a fix |
| FS-ISACInstitution · April 2026 | Preparing the enterprise for AI-enabled vulnerability discoveryOur reading Moves the accountability off the security function and onto the people who own and fund the systems: patch velocity and how current a platform is kept become objectives measured alongside whether the system performs, and remediation speed is reported to governance committees and to the board as operational risk rather than as a security update. Says outright that leaders across business, technology and resilience have to reset what they consider business as usual, which is the part a delegated model never asks of them.Put remediation speed in the objectives of whoever owns the system | proposes a fix |