AI & ML

The Evolving Role of CISOs: What to Expect by 2029

As the role of Chief Information Security Officers transforms, they will increasingly act as strategic enablers within businesses, balancing risk and innovation.

Aug 17, 2026 3 min read
Sign in to save

Wolfgang Goerlich, a veteran in the security field and CISO for the public sector, foresees a pivotal shift in the responsibilities of CISOs by 2029. His observations highlight a distinct trend: moving from a risk-averse posture to one that embraces calculated risks, particularly through the lenses of technology such as artificial intelligence (AI).

“The growing expectation is for the CISO to become a catalyst for innovation, actively participating in boardroom discussions and guiding executive teams on responsible technology adoption,” Goerlich stated. This marks a significant evolution since the inception of the CISO role in 1995, which has historically shifted from being a rejected source of risk to a valued advisor that helps organizations understand risk in smarter ways.

Industry consensus overwhelmingly suggests that CISOs will be propelled into greater strategic responsibilities over the coming years. While there’s a general agreement regarding this evolution, the exact nature of the changes remains a topic of debated possibilities. Across strategic planning timelines, especially those typical in three-year increments, security leaders anticipate a broadening scope for the CISO role.

According to a KPMG report, “The CISO role is being redefined in real-time.” The document emphasizes that as digital transformation, AI, and third-party integrations progress, security leaders must balance speedy responses with enterprise-level accountability. The emerging CISO will operate at an intersection of significant technological potential and growing risks, necessitating a fundamental shift within the role.

CISO as a Strategic Facilitator

The future CISO, KPMG suggests, is transitioning from a pure technologist to a business strategist, and notably, a storyteller. They’ll need to articulate complex security challenges in ways that resonate with business objectives. CISOs are becoming “strategic facilitators of secure innovation,” tasked with helping their organizations leverage technology safely and effectively.

This trend is already observable, as Goerlich reports being charged with assembling an innovation team comprised of diverse expertise, spanning architecture, engineering, and security. The recognition from leadership that including a security perspective in innovation can propel rather than hinder progress shows a progressive change in corporate attitudes. Goerlich predicts that by 2029, many CISOs will take on broader risk management duties beyond just cybersecurity.

Enabler of Business Strategy

Diana Kelley, CISO at Noma Security, echoes this sentiment, stating, “The most significant shift is CISOs morphing from defenders into enablers of business strategy.” She highlights how current roles already involve fostering business resilience and understanding strategic objectives to enhance security efforts. This alignment demonstrates a commitment to not only protect but to facilitate business growth.

However, as technology, particularly AI, becomes more integral to organizations, Kelley emphasizes the necessity for CISOs to deepen their technical knowledge, without necessarily resorting to hands-on coding. They need to be adept enough to question and assess technology implementation intricacies, ensuring governance and controls are adequately in place.

Expansion of Risk and Trust Responsibilities

Edna Conway, an industry veteran and former CISO, advocates for an expanded role for CISOs that includes enterprise-wide risk management. She suggests a title restructuring, possibly to Chief Security and Trust Officer, reflecting their overarching responsibilities. However, Conway remains skeptical about the timeline for such widespread shifts, acknowledging that the evolution would not be uniform across all organizations by 2029.

Dynamic Environment Driving Evolution

The fast-paced changes across technology landscapes and economic factors are undeniably influencing the CISO role's trajectory. Ali Waezzadah of iCOUNTER identifies these shifting demands as forcing CISOs to re-evaluate their operational approaches continually. With quicker advancements in technology deployment and adversarial tactics, he believes that CISOs will need to demonstrate agility and responsiveness more than ever before.

As Waezzadah points out, the scope of a CISO’s responsibilities will broaden significantly, compelling them to stay ahead in responding to evolving threats while supporting business objectives. By 2029, he envisions a role that is not only reactive but preemptively engaged in shaping the company’s security posture.

Strategic Architect of Business Outcomes

The evolution of the CISO role is not just about risk management; it’s also about creating business value. John White, field CISO for Torq, notes that CISOs must orchestrate security operations with efficiency. The integration of AI, both in leveraging opportunities and countering threats, compels CISOs to craft dynamic security teams that can adapt quickly to new challenges.

White articulates that the traditional model of security management will no longer suffice. The future CISO will need to reshape their teams into agile, product-oriented units capable of delivering quick responses to security incidents, with an emphasis on risk assessment and effective decision-making in times of uncertainty.

CISO as Orchestrator

Andrew Obadiaru from Cobalt forecasts that by 2029, CISOs will increasingly focus less on direct technology ownership and more on orchestrating a holistic security approach across all facets of the business—engineering, IT, legal, procurement, and executive management. He expects CISOs to prioritize continuous validation of their organization's exposure rather than relying solely on retrospective assessments.

Included in this shifting paradigm is the necessity for CISOs to manage the risks associated with AI adoption, ensuring systems remain secure even as they embrace transformative technologies. This adapted role represents both a challenge and an opportunity, as CISOs navigate the fast-evolving landscape while maintaining their core mission: to protect the organization and empower informed business decision-making.

In essence, while technology continues to change, the fundamental requirements for leadership—trust, good judgment, and clear communication—will always remain integral to a CISO's success.

Source: Michael Smith · www.csoonline.com

Comments

Sign in to join the discussion.