The CISO of 2029: Risk Strategist, Boardroom Adviser, AI Overseer

Four senior security leaders explain how the job of protecting a company is shifting from a technical gatekeeper role to something closer to a business co-pilot, and what that means by the end of the decade.

ThreatVectr Newsdesk· 4 min read
AI analyzing network data
Share

Key points

  • Wolfgang Goerlich, a public sector CISO and IANS Research faculty member, predicts that by 2029 more CISOs will own enterprise-wide risk, not just cyber risk.
  • A 2026 KPMG report states the CISO role "is being redefined in real-time" as AI and third-party technology ecosystems accelerate the pace of change.
  • Diana Kelley, CISO at Noma Security, says the shift from defending systems to enabling business strategy is "already happening."
  • John White, field CISO at Torq, argues the traditional security model will no longer be sufficient, and that future CISOs must build teams where AI agents do the executing and humans set the goals.
  • The title itself may change: Edna Conway, who held the role of chief security and risk officer at Microsoft Azure Infrastructure from 2020 to 2023, thinks "chief security and trust officer" or "chief security and risk officer" fits the job better.

The person in charge of keeping a company's data and systems safe has a title most people have only recently started to hear: CISO, short for Chief Information Security Officer. The role was invented in 1995. For most of its life, it meant saying no: no, you cannot plug that in; no, that software is too risky; no, we are not ready. That era is ending.

Senior security leaders interviewed by CSO Online, along with fresh research, all point to the same conclusion. By 2029, the best CISOs will spend less time blocking things and more time helping businesses take calculated risks with technology, including artificial intelligence, meaning computer systems that can perform tasks that normally require human judgment.

What is actually changing about the job?

The clearest shift is where the CISO sits in a company's decision-making. Wolfgang Goerlich, a public sector CISO and faculty member at IANS Research (a security-focused research and advisory firm), has held the role for seven years. He describes the arc neatly: the job has gone from "department of no" to "let's slow down" to "let's take smarter risks based on our understanding of them."

Goerlich already leads an innovation team that includes architects, engineers, and security staff together. His argument is simple: boards are realising that putting security leaders inside the innovation process speeds things up rather than slowing them down, because those leaders know how to price risk properly.

A 2026 KPMG report on the evolving CISO role backs this up. It describes the modern CISO as operating "at the crossroads of immense technological opportunity and unprecedented risk," and calls for the role to evolve from "pure technologist" to "strategic facilitator of secure innovation."

Will every CISO end up doing the same thing?

No, and the experts are clear on that. Some organisations will want a CISO focused mainly on defending systems and meeting regulations. Others will want someone embedded in strategy conversations at the board level. Goerlich predicts security leaders will "self-select into the right organisation in ways that fit their temperament, their skills, and their resume."

Diana Kelley, CISO at Noma Security, raises an interesting possibility: future organisations may carry two distinct security leaders, one focused on hardening defences and one focused on risk and business resilience. She also pushes back against the idea that future CISOs need no technical depth. They may not need to type commands themselves, but they must be able to question technical and architectural choices so they can say, in her words, "This is how we can govern and control this in runtime."

Ali Waezzadah, CISO at iCOUNTER, frames the pressure differently. Regulations keep changing. Adversaries keep finding new ways in. Businesses keep revising strategy. All of that lands on the same desk. "By 2029 they'll have more things they'll have to pay attention to," he says.

What does this mean for ordinary employees?

It matters who sits at the top of your company's security function. A CISO who is close to the boardroom is more likely to win budget for better security tools and training before a crisis hits, rather than after. For everyday staff, the practical result is likely to be clearer guidance on technology risks, faster responses when something goes wrong, and security policies that feel less like obstacles and more like guardrails.

If your employer asks you to complete security-awareness training, take it seriously. The humans spotting suspicious emails and unusual requests remain the first line of defence, regardless of how much the CISO's title changes.

© 2026 Threat Vectr