Meet the CISO: A new front line star in the AI cybersecurity war

55 minutes ago 5
Chattythat Icon

Mustafau | Istock | Getty Images

The stakes have never been higher for senior cybersecurity leaders at top companies.

"It feels like my job has doubled or quadrupled," said Wally Dalrymple, chief security officer at global education and talent solutions firm ETS.

"It's coming at us so fast and at such large volumes," he said.

Artificial intelligence has catapulted the chief information security officer out of the server room and into the boardroom, forcing leaders to address a rapidly changing threat landscape while navigating shifting budgets and business needs.

The July hack by rogue OpenAI autonomous agents on open-source developer platform Hugging Face accelerated the shift and proved that the era of advanced AI hacks had arrived. It also demonstrated the lengths agents will go to accomplish a goal.

In the weeks since, the list of agent-led attacks has swelled, with Reuters reporting Friday that another swarm of OpenAI agents broke containment in May and commandeered a German website.

The startup paused some of its AI research and training after the Hugging Face attack, but the security incidents haven't stopped OpenAI from releasing new products. The company announced the rollout of its latest GPT-6 Astra model this week despite previously warning of 'Critical' cyber capabilities.

And the pace of model releases with specialized cyber features hasn't slowed, with Google debuting Gemini 3.8 Flash Cyber and Anthropic rolling out Fable 5.1 and Mythos 5.1 this week as well.

"The ground under our feet is shifting," said Dell security chief John Scimone. "It's completely changing the variables, the safe assumptions that we've been able to rest on for decades."

"Worth their weight in gold"

There's one major silver lining to all the added stress: The hiring market is blazing for CISOs with the chops and technical skills to tackle the AI world.

Qualified candidates who check the boxes are easily landing pay packages exceeding seven figures, but recruiters have to move fast, said Michael Piacente, managing partner and cofounder of executive cybersecurity search firm Hitch Partners.

Piacente said his team is often working 18-to-20-hour days, but still losing a candidate a week per search to other offers. He hasn't seen dynamics comparable to this since the introduction of the cloud.

"It was more of a slow drift," Piacente said. "It wasn't everything, all at once together like AI is."

For years, companies viewed deep cybersecurity expertise and government or compliance experience as coveted skills for a CISO. In the age of AI, those qualifications are only the bare minimum.

With AI proliferation, CISOs are not only responsible for keeping the bad guys out but also tasked with governing internal AI agents and data control.

Technical background, including experience with AI security building and risks, has become nonnegotiable for businesses, said JC Christian, president at boutique executive recruiting firm Christian & Timbers.

"A lot of CISOs that could cover the boxes a couple of years ago probably aren't going to be prepared for the world that we're in today," Christian said.

AI-proven CISOs also need strong communication skills and the confidence to present to the boardroom or weigh in on major business decisions, including mergers and acquisitions.

That's shifting the organizational structure, giving many security chiefs a direct line to the CEO instead of the chief information officer, said Meredith Griffanti, global head of cybersecurity and data privacy communications at FTI Consulting.

Barclays analyst Saket Kalia, for example, told CNBC this week that he heard from a CISO who went from meeting with the CEO once a month to three times a week.

CISOs with crisis management experience, strong business acumen and the ability to present on stage at industry conferences like Black Hat are "worth their weight in gold," Griffanti said.

Barclays' Saket Kalia reacts to Palo Alto Q4 results

"Spidey senses"

The pressure is squarely on CISOs to quickly deploy AI defenses, but urgent demand doesn't necessarily mean the budgets or tools have caught up.

Cybersecurity budgets are expected to jump 6% in 2026, driven largely by new tools to secure and implement AI, according to Gartner data. In some parts of the world, the spend is higher, with the Middle East and Africa on pace to increase 16% year over year, said IDC analyst Craig Robinson.

Mission-critical sectors like financials, pharmaceuticals, energy and healthcare are scrambling to reinforce cyber defenses before attackers deploy the latest AI tools.

"Some security teams are just so overwhelmed they don't know where to start, and when it comes to security products, they're not ready for prime time," because the technology is so new, said Joe Sullivan, former CISO at Uber and Facebook, who runs a cyber consulting business.

Top cybersecurity vendors have emerged as major winners, with recent earnings from CrowdStrike and Okta showing a surge in demand for AI defense. After languishing in the early part of the year amid broader fears of AI disruption, the stocks have roared back. CrowdStrike and Palo Alto Networks are up about 80% this year, while Okta shares have roughly doubled.

While longstanding all-in-one incumbents are appealing to customers through bundling, there has been an explosion in startups promising to tackle the AI problem.

That's forcing many CISOs to put their "Spidey senses" to the test to scope out the winners or back several solutions until a clear standout emerges, said Jeremiah Kung, global head of information security at AppLovin.

Dalrymple said the scope of decisions and the pressure to perform have never been more daunting.

"I feel the weight of the world of figuring out how to do it myself," he said.

 Fortalice Solutions' Theresa Payton

Read Entire Article