Founder & CEO, Corix Partners | Board Advisor | Non-Exec Director | Author “The Cybersecurity Spiral of Failure and How to Break out of It”

For the past couple of years, the business world has been trying to figure out what to do with generative AI (GenAI). Largely because of the hype and FOMO surrounding this technology, the topic has dominated the agenda for many leadership teams.

In many cases, I think chief information security officers (CISOs) have not been as central in discussions as they should be, with the debate around AI often hijacking their priorities. Because of this, some in this position may be tempted to jump on the GenAI bandwagon and capitalize on the heightened executive interest. But the question is how to best do this.

While my earlier article critiques the broader issue of AI hype as potentially undermining cybersecurity practices, here I would like to offer specific guidance for CISOs on how to navigate an increasingly AI-driven business landscape while still effectively integrating cybersecurity considerations.

Navigating The Boardroom With AI And Cybersecurity

First, I believe CISOs must avoid repeating historical situations where cybersecurity was seen as at odds with business needs and the CISO simply as the “person who says no.” Opposing the AI tidal wave we are currently seeing—on any ground, valid or not—will likely not be heard.

I think CISOs should also avoid forcing their way into the boardroom through fear, uncertainty and doubt; the topic is potentially too serious for that and more importantly, it does not warrant it.

Overall, it can be helpful to keep in mind how AI and cybersecurity have several characteristics in common:

• Data, and data integrity, in particular, are central to both.

• Governance is also central to both, in the case of AI to ensure its ethical and responsible use.

• Regulators are stepping up their game in both areas, pushing the topic up the list with audit and compliance departments.

Effective Communication Strategies For CISOs In The AI Era

CISOs need to understand that AI is grabbing the top executives’ attention because its use cases are being put in a language that they can understand and relate to: Productivity gains in call centers, removal of manual tasks in back offices, etc.

Many CISOs have long been trapped in an unproductive dialogue with senior stakeholders, presenting outdated, risk-driven, bottom-up and ROI-focused use cases that have consistently missed the mark.

Business leaders must understand that cybersecurity is simply a central and natural dimension of any AI strategy:

• Data poisoning, whether malicious or negligent, can lead to wrong results and wrong decisions, with potentially catastrophic consequences in some sectors (defense, healthcare etc.).

• The illegal use of personal or copyrighted data to train AI algorithms in breach of legislations or regulations can lead to legal action, reputational damage and heavy fines, not to mention personal liability in some cases.

• Without a clear policy on AI use within the enterprise, the influence of hype and FOMO will persist across business units, leading to the rise of shadow AI—much like shadow IT emerged over a decade ago to bypass the perceived rigidity and slow response of IT departments.

Making AI Policy A Priority For CISOs

This realization is required now; not next year or whenever someone feels like paying attention.

A solid policy approach that documents how AI usage can remain secure, ethical and responsible—and outlines how these aspects will be governed and executed across the enterprise—should intentionally involve the CISO along with other key stakeholders. This, in my opinion, is the agenda that CISOs should be championing.

This is not useless bureaucracy; AI, like cybersecurity, is inherently a matter where cross-silo interactions must be embedded. This does not happen naturally or organically in the large enterprise, which is almost by essence siloed, territorial and political. Those cross-silo interactions need to be engineered, fostered and properly governed; otherwise, they do not happen.

CISOs, working with CIOs and CDOs who share a similar interest, should see the policy route as the best mid- to long-term way for them to secure their rightful seat at the table from which they can protect their own interests and priorities—as well as those of the business.

As I wrote almost a decade ago concerning cybersecurity, sound governance remains key. It is not a piece of useless consultant jargon but an essential piece of the jigsaw. When it comes to AI, this is what will make enterprises successful or not within the technological space.

Forbes Business Council is the foremost growth and networking organization for business owners and leaders. Do I qualify?

Read the full article here

Share.
Leave A Reply