The CISO of 2029: Risk Strategist, Boardroom Adviser, AI Overseer

Four senior security leaders explain how the job of protecting a company is shifting from a technical gatekeeper role to something closer to a business co-pilot, and what that means by the end of the decade.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
An executive boardroom table with a security leader presenting on a large display screen showing AI risk analytics, business metrics, and strategic threat dashb
Share

Key points

  • Wolfgang Goerlich, a public sector CISO and IANS Research faculty member, predicts that by 2029 more CISOs will own enterprise-wide risk, not just cyber risk.
  • A 2026 KPMG report states the CISO role "is being redefined in real-time" as AI and third-party technology ecosystems accelerate the pace of change.
  • Diana Kelley, CISO at Noma Security, says the shift from defending systems to enabling business strategy is "already happening."
  • John White, field CISO at Torq, argues future CISOs must build teams where AI agents do the executing and humans set the goals.
  • The title itself may change: Edna Conway, who served as chief security and risk officer for Azure Infrastructure at Microsoft from 2020 to 2023, thinks "chief security and trust officer" fits the job better.

The person responsible for keeping a company's data and systems safe has a title most people have only recently started to hear: CISO, short for Chief Information Security Officer. The role was invented in 1995. For most of its life, it meant saying no. That era is ending.

Senior security leaders interviewed by CSO Online, along with fresh research, all point the same way. By 2029, the best CISOs will spend less time blocking things and more time helping businesses take calculated risks with technology, including artificial intelligence, meaning computer systems that can perform tasks that normally require human judgment.

What is actually changing about the job?

The clearest shift is where the CISO sits in a company's decision-making. Wolfgang Goerlich, a public sector CISO and faculty member at IANS Research (a security-focused research and advisory firm), has held the role for seven years. He describes the arc plainly: the job has gone from "department of no" to "let's slow down" to "let's take smarter risks based on our understanding of them."

Goerlich already leads an innovation team that brings architects, engineers and security staff together. His argument: boards are realising that putting security leaders inside the innovation process speeds things up, because those leaders know how to price risk properly.

A 2026 KPMG report on the evolving CISO role backs this up, calling for the position to evolve from "pure technologist" to "strategic facilitator of secure innovation." We first covered KPMG's research on the changing security leadership landscape on 17 August 2026.

Will every CISO end up doing the same thing?

No. Some organisations will want a CISO focused mainly on defending systems and meeting regulations. Others will want someone embedded in strategy at board level. Goerlich predicts security leaders will self-select into organisations that match their temperament, skills and career history.

Diana Kelley, CISO at Noma Security, raises a concrete possibility: future organisations may carry two distinct security leaders, one focused on hardening defences and one focused on risk and business resilience. She also pushes back against the idea that future CISOs need no technical depth. They may not need to type commands themselves, but they must be able to interrogate technical and architectural choices so they can say, in her words, "This is how we can govern and control this in runtime."

Ali Waezzadah, CISO at iCOUNTER, frames the pressure differently. Regulations keep changing. Adversaries keep finding new ways in. Businesses keep revising strategy. "By 2029 they'll have more things they'll have to pay attention to," he says.

Edna Conway, who ran security and risk for Microsoft's Azure Infrastructure division before going on to lead EMC Advisors, thinks the title should reflect a broader mandate. "Chief security and trust officer" or "chief security and risk officer" fits better, she argues, though she isn't certain all that will arrive before 2029.

That uncertainty is the honest read here. The direction is clear; the pace is not. Organisations that treat the CISO as a boardroom peer are already ahead, and those that keep the role buried in IT will feel the gap widen as AI multiplies both the opportunity and the exposure.

What does this mean for ordinary employees?

It matters who sits at the top of your company's security function. A CISO close to the boardroom is more likely to win budget for better tools and training before a crisis, not after. Our earlier story on Charles Blauner, who ran security at JPMorgan and Citigroup, made the same point: leadership access determines whether security shapes decisions or just reacts to them.

For everyday staff, the practical result is likely to be clearer guidance on technology risks, faster responses when something goes wrong, and security policies that feel less like obstacles. The humans catching suspicious emails remain the first line of defence, whatever the CISO's title says.

© 2026 Threat Vectr