{"id":9152,"date":"2026-08-17T08:25:00","date_gmt":"2026-08-17T08:25:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9152"},"modified":"2026-08-17T08:25:00","modified_gmt":"2026-08-17T08:25:00","slug":"what-the-ciso-role-will-look-like-in-2029","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9152","title":{"rendered":"What the CISO role will look like in 2029"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/jwgoerlich\/\">Wolfgang Goerlich<\/a> has spent his career in security and has been a CISO for the past seven years.<\/p>\n<p class=\"wp-block-paragraph\">Like many long-term security execs, Goerlich has seen plenty of changes within the profession. He\u2019s bracing for more.<\/p>\n<p class=\"wp-block-paragraph\">\u201cFor the future I see growing the role of CISO to be the pacesetter for innovation, to be in the board room and executive conversations advising them on how to take smart, calculated risks with technology, including AI,\u201d says Goerlich, who is now a public sector CISO and a faculty member with IANS Research.<\/p>\n<p class=\"wp-block-paragraph\">Goerlich sees this as the next step for a role that has continuously evolved since its inception in 1995.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIt\u2019s gone from the \u2018department of no\u2019 to \u2018let\u2019s slow down\u2019 to \u2018let\u2019s take smarter risks based on our understanding of them,\u2019\u201d he adds. \u201cHow exciting is this? To be the one to say, \u2018You want to take more risk? Let us help you. We can help you make smarter decisions.\u2019\u201d<\/p>\n<p class=\"wp-block-paragraph\">Goerlich isn\u2019t the only one with such observations. Others similarly believe that the responsibilities assigned to the typical CISO will change in the upcoming years.<\/p>\n<p class=\"wp-block-paragraph\">Despite a broad consensus on change, predictions vary on how that change will play out in terms of the CISO\u2019s roles and responsibilities. Mirroring the traditional three-year look for strategic planning at many organizations, security leaders see a range of possibilities for the CISO position evolving by 2029. Regardless, all agree that the CISOs of tomorrow will have to work at a faster pace, contend with more threats, and bear more strategic responsibility than they do today.<\/p>\n<p class=\"wp-block-paragraph\">Research confirms this outlook.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe CISO role is being redefined in real-time,\u201d states a 2026 KPMG report on <a href=\"https:\/\/kpmg.com\/us\/en\/articles\/2026\/cybersecurity-technology-risk-survey-ciso-resilience.html\">the evolving CISO role<\/a>. \u201cAs digital platforms, artificial intelligence (AI), and third-party ecosystems accelerate the pace of change, security leaders are increasingly expected to enable response speed while assuming accountability for enterprise-level risk.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The report goes on to say, \u201cThe modern CISO operates at the crossroads of immense technological opportunity and unprecedented risk. This requires a fundamental evolution of the CISO role itself.\u201d<\/p>\n<h2 class=\"wp-block-heading\">CISO as \u2018strategic facilitator\u2019<\/h2>\n<p class=\"wp-block-paragraph\">KPMG offers ideas on what\u2019s ahead, writing that the future CISO must evolve \u201cfrom that of a pure technologist to one of a business leader and, critically, a storyteller who can translate complex threats into a business context.\u201d They must become \u201ca strategic facilitator of secure innovation, whose mission is to help the business move at speed in a trusted, safe manner.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Some CISOs already serve as that strategic facilitator for secure innovation, with researchers and current security chiefs saying they expect a greater percentage of CISO positions to take on that work in the coming years.<\/p>\n<p class=\"wp-block-paragraph\">Goerlich is experiencing that shift already, having been tasked with standing up an innovation team that includes architecture and engineering professionals as well as security practitioners.<\/p>\n<p class=\"wp-block-paragraph\">Moreover, his research at IANS has brought him into contact with other CISOs who are leading or co-leading innovation. CEOs and boards increasingly recognize that having security in those leadership roles accelerates \u2014 rather than slows \u2014 innovation because \u201csecurity knows how to help them take risks,\u201d he says.<\/p>\n<p class=\"wp-block-paragraph\">In fact, Goerlich believes more CISOs will <a href=\"https:\/\/www.csoonline.com\/article\/4159317\/cisos-reshape-their-roles-as-business-risk-strategists.html\">have responsibility for enterprise risk in general<\/a>, in addition to cyber risk, by 2029.<\/p>\n<p class=\"wp-block-paragraph\">That said, Goerlich doesn\u2019t expect that to be a universal truth. The CISO role will vary from one organization to another in 2029, as it does today, he says, with some more focused on risk and others more tactical.<\/p>\n<p class=\"wp-block-paragraph\">Security leaders will \u201cself-select into the right organization in ways that fit their temperament, their skills, and their resume,\u201d he says.<\/p>\n<h2 class=\"wp-block-heading\">\u2018Enabler of business strategy\u2019<\/h2>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/dianakelleysecuritycurve\/details\/experience\/\">Diana Kelley<\/a>, CISO at Noma Security, has a similar take on what\u2019s ahead. \u201cThe biggest change that is happening is that CISOs are moving more from defender role and compliance to enabler of the business strategy.\u201d<\/p>\n<p class=\"wp-block-paragraph\">She adds, \u201cIt\u2019s becoming more about how to enable the business, how to understand strategically what the business is doing so I can make the business more resilient. It\u2019s already happening. We\u2019ve already seen some CISOs move to being a strategic trust officer and strategic risk partner.\u201d<\/p>\n<p class=\"wp-block-paragraph\">On the other hand, Kelley also thinks that, thanks in large part to AI, CISOs will need to sharpen their technical chops for the job ahead of them. \u201cI don\u2019t mean CISOs need hands on the keyboard, but they do need to be able to interrogate technically and architecturally what the organization is doing with technology so they can say, \u2018This is how we can govern and control this in runtime,\u2019\u201d she explains.<\/p>\n<p class=\"wp-block-paragraph\">In fact, Kelley suggests that in the future there may be two different types of security leaders in an organization \u2014 one focused on shoring up defenses and the <a href=\"https:\/\/www.csoonline.com\/article\/4200382\/how-cisos-can-rise-to-the-business-resilience-challenge.html\">other focused on risk and resilience<\/a>.<\/p>\n<h2 class=\"wp-block-heading\">Expansion to risk and trust<\/h2>\n<p class=\"wp-block-paragraph\">Longtime security exec <a href=\"https:\/\/www.linkedin.com\/in\/ednaconway\/\">Edna Conway<\/a> also believes the CISO role will continue to morph.<\/p>\n<p class=\"wp-block-paragraph\">Conway, a former CSO who had CISOs reporting to her, thinks CISOs should expand their responsibilities beyond information security risk to include <a href=\"https:\/\/www.csoonline.com\/article\/566417\/enterprise-risk-management-erm-putting-cybersecurity-threats-into-a-business-context.html\">enterprise risk<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">As such, she thinks the title should be chief security and trust officer or chief security and risk officer. She knows something about that: She herself was chief security and risk officer for Azure Infrastructure at Microsoft from 2020 to 2023.<\/p>\n<p class=\"wp-block-paragraph\">However, Conway, now CEO of EMC Advisors and chief operating and risk officer for TPO Group, isn\u2019t sure all that will happen by 2029.<\/p>\n<h2 class=\"wp-block-heading\">\u2018Dynamic environment\u2019 driving CISO evolution<\/h2>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/aliwzz\/\">Ali Waezzadah<\/a>, CISO at iCOUNTER, sees today\u2019s \u201cdynamic environment\u201d \u2014 from evolving IT infrastructure to geopolitics to the economy \u2014 as driving the next evolution of the position.<\/p>\n<p class=\"wp-block-paragraph\">More specifically, he sees changing (and increasing) work around managing teams, securing technology, supporting the business direction and strategy, and ensuring compliance with regulatory, security, and governance standards.<\/p>\n<p class=\"wp-block-paragraph\">The background and experience of security workers is changing, he contends. New technologies are being deployed increasingly faster. Adversaries <a href=\"https:\/\/www.csoonline.com\/article\/3819176\/top-5-ways-attackers-use-generative-ai-to-exploit-your-systems.html\">constantly develop new techniques<\/a>. The regulatory environment is in flux. And the business itself continues to <a href=\"https:\/\/www.cio.com\/article\/3618308\/whatever-happened-to-the-three-year-it-roadmap.html\">experiment and revise strategies at shorter intervals<\/a>. \u201cThose are the things that will force the CISO to adapt,\u201d he adds.<\/p>\n<p class=\"wp-block-paragraph\">All that is regularly reshaping both the day-to-day actions of the CISO and the remit that falls under the title. That, in turn, is forcing security leaders to be more agile than ever before, Waezzadah says.<\/p>\n<p class=\"wp-block-paragraph\">\u201cBy 2029 they\u2019ll have more things they\u2019ll have to pay attention to,\u201d he predicts. \u201cHow and what CISOs have to protect is rapidly changing, and they have to be much more prepared for a dynamic landscape. They need to be more nimble and flexible.\u201d<\/p>\n<h2 class=\"wp-block-heading\">\u2018Strategic architect of business outcomes\u2019<\/h2>\n<p class=\"wp-block-paragraph\">Of course, change is not new to CISOs as they\u2019ve seen their mandate expand over the past decades, says <a href=\"https:\/\/www.linkedin.com\/in\/johnwhiteciso\/\">John White<\/a>, field CISO for security tech company Torq.<\/p>\n<p class=\"wp-block-paragraph\">The upcoming years will require CISOs to build and manage an operation that can move at lightning speed, a consequence of AI\u2019s use by the organization and its adversaries, White says. To do that, CISOs must build and manage a <a href=\"https:\/\/www.csoonline.com\/article\/4042494\/how-ai-is-reshaping-cybersecurity-operations.html\">new type of security department<\/a>, one where <a href=\"https:\/\/www.csoonline.com\/article\/4064158\/agentic-ai-in-it-security-where-expectations-meet-reality.html\">agents execute and human workers define and oversee outcomes<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe traditional security model we\u2019re used to is no longer going to be sufficient for what\u2019s upon us, and the CISO role will evolve to be a more agile, product-oriented role and to be someone who can pull holistic teams together quickly to engineer responses,\u201d he says, adding that CISOs will need strong risk skills and business acumen to do all that.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/torq.io\/blog\/ciso-role-ai-changing\/\">In an online post<\/a>, he writes \u201cThe CISO of the near future is less a chief technologist and more a strategic architect of business outcomes, designing human-machine teams that reimagine the target operating model in response to both risk and opportunity.\u201d<\/p>\n<h2 class=\"wp-block-heading\">CISO as orchestrator<\/h2>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/andrew-obadiaru-cism-crisc-mcp-793b963\/\">Andrew Obadiaru<\/a>, CISO at Cobalt, a security services company, also believes \u201cby 2029 the CISO will be even more of a business leader than a technical leader.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u201cSecurity will increasingly be measured by how quickly organizations can identify, validate, and reduce risk,\u201d he says. \u201cThe CISO will be responsible for enabling the business to adopt AI safely, managing software supply chain risk, and ensuring the organization can continuously validate its security posture in an environment where attackers are operating at machine speed.\u201d<\/p>\n<p class=\"wp-block-paragraph\">As a result, Obadiaru sees the CISO role becoming \u201cless about owning security technology and more about orchestrating security across engineering, IT, product, legal, procurement, and the executive team.\u201d<\/p>\n<p class=\"wp-block-paragraph\">He expects three main priorities to dominate the role in the future: continuously validating organizational exposure rather than relying on assessments; ensuring AI is adopted securely across the enterprise; and <a href=\"https:\/\/www.csoonline.com\/article\/4172697\/7-tips-for-accelerating-cyber-incident-recovery.html\">accelerating remediation<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">CISOs will have to act faster, too. \u201cAs a result, CISOs will spend less time reviewing individual technical findings and more time building automated decision-making processes, resilient engineering practices, and governance models that allow organizations to respond safely at machine speed,\u201d Obadiaru says.<\/p>\n<p class=\"wp-block-paragraph\">And they\u2019ll have to change their operating model. \u201cSecurity has always been about managing uncertainty. What\u2019s changing is the speed at which uncertainty develops,\u201d he says. \u201cAI is accelerating vulnerability discovery, software development, and attacker innovation simultaneously. That means the CISO must evolve from managing security programs to managing adaptive security systems.\u201d<\/p>\n<p class=\"wp-block-paragraph\">However, he believes the fundamental mission will stay the same.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe CISO\u2019s responsibility is still to protect the organization\u2019s ability to operate by understanding risk, communicating it effectively, and helping the business make informed decisions,\u201d he adds. \u201cTechnology evolves, but leadership, trust, sound judgment, and clear communication remain constant requirements.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Wolfgang Goerlich has spent his career in security and has been a CISO for the past seven years. Like many long-term security execs, Goerlich has seen plenty of changes within the profession. He\u2019s bracing for more. \u201cFor the future I see growing the role of CISO to be the pacesetter for innovation, to be in [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9153,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9152","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9152"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9152"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9152\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9153"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9152"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9152"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9152"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}