Most CISOs Are Not Confident About AI Security. Here Is What Separates the Ones Who Are.
A new survey finds only 41% of chief information security officers feel optimistic about managing AI risks over the next two years. The gap between the hopeful and the worried comes down less to technology and more to whether the boss actually listens.

Key points
- 41% of the 113 chief information security officers (CISOs, meaning the executives responsible for a company's cybersecurity) surveyed by IANS Research in April and May 2025 said they feel optimistic about managing AI security risks over the next 24 months.
- 38% of the same group expressed pessimism, a near-even split that surprised several outside analysts.
- IANS identified six organisational signals that separate confident CISOs from worried ones, all centred on leadership support rather than current technical controls.
- Analysts warn that feeling ready and actually being secure are not the same thing.
- Third-party AI risk, meaning danger from AI tools built into vendor software rather than tools a company chose itself, was flagged as a significant blind spot.
What did the survey actually find?
Slightly more CISOs feel hopeful than fearful about AI security, but only just. IANS Research, a security-focused advisory firm, polled 113 CISOs and found the field almost evenly divided: 41% optimistic, 38% pessimistic, with the rest somewhere in the middle.
The factors that predicted optimism were not technical. CISOs felt better about the future when their senior leadership understood AI risk, when someone in the organisation clearly owned AI governance, when the CISO personally controlled the AI security budget, when the security team used AI tools effectively in its own work, and when staffing levels were sufficient. In short, the survey, first covered by CSO Online, found that confidence tracks with organisational power and support, not with how mature the company's security controls already are.
Should that optimism be trusted?
Several analysts urge caution. Rock Lambros, director of AI standards and governance at security firm Zenity, points out a built-in survey problem: a CISO who rates their own programme as efficient is unlikely to rate their own risk as critical two questions later. People stay consistent with themselves, which can make results look rosier than the underlying reality.
Sanchit Vir Gogia of Greyhound Research draws a sharper line. Leadership support, budget control, and clear governance show whether a CISO has room to act. They do not show whether the AI systems running inside the company are actually under control. Justin Greis, CEO of consulting firm Acceligence, was blunter: "Almost half of the CISOs are optimistic about the AI security future? Who the heck are these people? The enterprise CISOs I talk with are white-knuckling their way through the fastest-moving security challenge of their careers."
What are the real gaps?
Pearl Almeida of Info-Tech Research Group identifies two problems that cut across all six IANS factors.
First, most senior leaders, including security leaders, cannot explain how an AI agent (a piece of software that takes actions on its own, calling other tools and making decisions) actually works. If you cannot describe the mechanism, she argues, you cannot correctly size the risk.
Second, governance ownership means little if security is bolted onto a process after the fact rather than built in from the start. Naming an owner only works when that owner accepts real accountability, including the possibility that security staff could pause their workflow during an incident.
Brian Levine of FormerGov adds a third gap: third-party AI risk. Many companies are running AI models they did not choose directly, models pulled in through vendor software or used by staff without approval. Governance frameworks that focus only on internally built AI miss this entirely.
Common questions
Does this affect ordinary employees or customers?
Yes, indirectly. When companies rush AI tools into use without proper controls, errors and data exposures become more likely. Customers and employees whose data those companies hold carry the downstream risk.
What should organisations actually do right now?
Analysts broadly agree on a starting point: map every AI tool in use, including those inside vendor products, identify what data each tool can reach, and assign someone with genuine authority and accountability to oversee each one.



