Everywhere you go you hear the same story. AI changed everything, attackers are faster, and governance matters. This is a narrative that 50 other CISOs could deliver.
After 20 years in cybersecurity, I have the benefit of perspective. I’ve lived through major shifts in technology: the internet, mobile, cloud … and more. To me, the interesting story is what is fundamentally different about AI vs. every other technology transition.
AI didn’t replace the CISO’s mission. Yes, it changed the speed, but good security has always been about being the team that doesn’t just protect technology but also helps enable the company to win in the market in which it competes. Just like with the internet, mobile, and cloud, confirming the company uses AI well is table stakes.
1. What my job looked like a year ago
A year ago, my priorities would have been very recognizable to any CISO: ransomware, identity, vulnerability management, third-party risk, cloud security, data protection, resilience. AI was on the agenda, but largely as an emerging technology risk. Today, it’s becoming part of almost every one of those conversations.
Last year’s world wasn’t simple. We had to protect identities, systems, applications, infrastructure and data. And now, all of those remain, but you’re dealing with systems that can consume huge amounts of information, generate new information, make recommendations, write software, automate workflows, and increasingly act on behalf of people. The old problems didn’t disappear. AI landed and sped up the clock of the existing security stack.
2. What changed, and why it wasn’t gradual
The biggest inflection point is the collapse in the cost of capability. An attacker no longer needs the same skills and time investment. Previously they’d have to invest countless hours in their coding ability or content-production effort to operate at scale and countless hours to identify and hone targets. At the same time, my own employees suddenly have powerful tools that can ingest corporate information and produce code, analysis, and content.
So, we have two simultaneous accelerations. What changed wasn’t simply that attackers got AI. Everyone got AI. And adoption happened from the bottom up. Employees didn’t wait for the enterprise AI strategy. Developers started using copilots. People experimented with public LLMs. Business functions discovered automation opportunities.
For most major enterprise technologies, security had some opportunity to prepare the environment before widespread adoption. With generative AI, adoption often arrived before governance.
3. How the mission itself changed
Historically, security asked: How do we protect this technology? But AI forces another question: How do we allow the company to use this technology safely?
That brings CISOs into questions that aren’t purely cybersecurity:
- What information can employees provide to AI systems?
- Which models and services are approved?
- What happens to prompts and uploaded data?
- Where is corporate data retained?
- How do we manage AI identities, agents, and permissions?
- How do we validate AI-generated code?
- What human oversight is required?
- How do legal, privacy, security, data governance, and compliance responsibilities intersect?
That said, CISOs need to be careful they don’t become Luddites, or the AI Police. The CISO role is helping define the security boundaries within which the company can move quickly. If the security strategy for AI is simply “don’t use it,” you’ve already lost. People will use it. Our job is to make the secure path the easiest path.
4. What I had to relearn or unlearn
One thing I’ve had to unlearn is the idea that security gets to fully understand a technology before the enterprise adopts it. With AI, adoption and experimentation are happening simultaneously with our understanding of the risks. We have to allow smart and thoughtful adoption.
Another is determinism. Security professionals grew up evaluating systems where, broadly speaking, Input A should produce Output B. Generative systems don’t behave that neatly. We’re accustomed to asking whether a control works. AI forces us to become more comfortable asking how reliably it works, under what conditions it fails, and what happens when it does. That’s intellectually interesting.
Twenty years in security teaches you pattern recognition. Now, AI reminds me that pattern recognition can become a liability when the underlying assumptions change.
Early on I assumed the principal problem would be malicious use of AI externally against us. But quickly I discovered that my biggest impact would be spent internally on data governance, internal adoption, and business enablement.
5. What’s next/advice for peers gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.First, don’t create a separate AI-security universe.Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen. Map AI into the controls you already understand: identity, data classification, least privilege, logging, third-party risk, secure development, incident response, and resilience. gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.Second, pay close attention to agents.Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen. Today’s dominant interaction is often human → model → response. The more consequential architecture is increasingly: human → agent → tools → systems → data → actions. Once AI can take actions (rather than merely generate text), authorization, identity, provenance, monitoring, and blast radius become much more important. I’m less worried about an AI saying the wrong thing than I am about an AI agent being authorized to do the wrong thing. gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.Third, protect the data layer.Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen.Models will change quickly. Vendors will change. Architectures will change. Today’s biggest AI company and hippest frontier model will be Betamax soon. Your durable security assets remain knowing what data you have, where it is, who can access it, and what they’re allowed to do with it. gar nicht mehr gibt. Hier sind die wichtigsten Erkenntnisse.Fourth, don’t measure success by how much AI you block.Die Wiederherstellung sollte bei den geschäftlichen Zielen ansetzen – nicht bei den technischen.A sophisticated security organization should enable legitimate adoption while constraining unacceptable risk. Every major technology shift creates a period where capability moves faster than control. The internet did it. Mobile did it. Cloud did it. AI is doing it at extraordinary speed.
Handling this well doesn’t require eliminating AI risk altogether. It requires deciding deliberately which risks you’re willing to take, putting boundaries around them, and still allowing the business to move.
AI hasn’t repealed the fundamentals of cybersecurity, but it is changing the economics and velocity around them. After 20 years of successive security transformations, AI may be the first one where the CISO must simultaneously defend against the technology, protect the technology, and help the business adopt the technology. That’s what makes it a challenge.
Bill O’Connellis Chief Security Officer at Commvault.