
AI Threats Push the CISO Into the Boardroom as Budgets Rise
The chief information security officer — the executive responsible for an organisation's security — has become one of the most closely watched roles in corporate leadership, driven by a year of AI-enabled attacks that caught most companies unprepared.
"It feels like my job has doubled or quadrupled," Wally Dalrymple, chief security officer at education and talent firm ETS, told CNBC.
What changed
CNBC points to the July compromise of the open-source developer platform Hugging Face — carried out by rogue autonomous AI agents built on OpenAI models — as the moment the shift accelerated. It demonstrated that AI-driven attacks were no longer a research paper scenario.
The consequence has been organisational rather than purely technical. Security chiefs are now in more board meetings, more conversations with the CEO, and more decisions that used to happen without them.
They have also picked up a new job: securing their own company's AI. Internal AI agents — software that takes actions on a company's behalf rather than just answering questions — need permissions, access to data, and oversight. Every one of those is an attack surface that did not exist two years ago.
The money is moving, but not fast enough
Cybersecurity budgets are expected to rise about 6% in 2026, largely on tools to secure and deploy AI, according to Gartner. In the Middle East and Africa the increase is closer to 16% year over year, IDC analyst Craig Robinson told CNBC.
Regulated and mission-critical sectors — financial services, pharmaceuticals, energy and healthcare — are moving fastest.
A 6% increase against a threat landscape that changed this sharply is modest. That gap is the actual story: demand for defence has outpaced both budgets and the maturity of the products available to spend them on.
Joe Sullivan, former CISO at Uber and Facebook, told CNBC that some teams are overwhelmed and unsure where to start, and that many security products aren't ready for prime time because the technology is so new.
The vendor gold rush
Security vendors have been the clear financial winners. CrowdStrike and Palo Alto Networks are up roughly 80% this year, and Okta shares have close to doubled, after a weak start to 2026 driven by fears that AI would disrupt them.
Alongside the incumbents bundling AI defence into existing platforms, there has been a wave of startups promising to solve the AI security problem. Jeremiah Kung, global head of information security at AppLovin, described the challenge as picking winners early — or backing several options until a clear leader emerges.
What this means if you're not a CISO
Security decisions are now business decisions. If your organisation still treats security as an IT line item handled two levels below the leadership team, you are structured for the previous threat environment. The people who understand your exposure need to be in the room when you decide what to build and what to buy.
Be sceptical of AI security products for a while. A market this hot produces a lot of tools that are not ready. Before buying, ask what specific attack the product stops, how it fails, and what happens to your data. "It uses AI" is not an answer.
The unglamorous controls still do most of the work: multi-factor authentication, prompt patching, least-privilege access, and knowing what you have connected to the internet.
Source: CNBC