{"id":9610,"date":"2026-09-30T08:25:00","date_gmt":"2026-09-30T08:25:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9610"},"modified":"2026-09-30T08:25:00","modified_gmt":"2026-09-30T08:25:00","slug":"whatever-happened-to-the-36-month-it-security-roadmap","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9610","title":{"rendered":"Whatever happened to the 36-month IT security roadmap?"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Insight Global\u2019s John Dickson had a problem familiar to many CISOs today.<\/p>\n<p class=\"wp-block-paragraph\">Employees were embracing AI tools faster than his security team could track them, and new AI agents and service integrations spread rapidly across the environment alongside them. Dickson and his security org had plans to build visibility into those <a href=\"https:\/\/www.csoonline.com\/article\/2132294\/what-are-non-human-identities-and-why-do-they-matter.html\">non-human identities<\/a> (NHIs), tracking what they could reach and how they behaved. It just wasn\u2019t supposed to happen for another year.<\/p>\n<p class=\"wp-block-paragraph\">Dickson didn\u2019t wait. His team immediately built AI discovery, observability, control, and reporting, including visibility into NHIs such as service accounts and AI agents. He paired the work with a cross-functional AI assurance function built around what he calls \u201cthe Department of Know, not the Department of No.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Every quarter now, Dickson and his security team formally reassess their strategy against what\u2019s changed in the threat landscape and the staffing firm\u2019s business, then shift the horizon out another three months. \u201cAn annual review means you\u2019re making decisions on assumptions that may be a year old,\u201d he says. \u201cA quarterly cadence keeps the strategy anchored to where things are today rather than where they were.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Security leaders like Dickson are finding that they can no longer treat a roadmap as something they set once a year and revisit at the next planning cycle. In its <a href=\"https:\/\/www.evanta.com\/resources\/ciso\/survey-report\/top-3-priorities-for-cisos-in-2026\">2026 Leadership Perspective Survey<\/a> of more than 1,000 CISOs, Gartner defines agility for security and risk leaders as the ability to rapidly reprioritize roadmaps and investments to address shifting business risks.<\/p>\n<p class=\"wp-block-paragraph\">As a result, leading CISOs are bifurcating traditional two- to three-year security roadmaps into two speeds. Principles, compliance commitments, and major architectural bets still get planned years out. Tools and day-to-day tactics are revisited monthly, weekly, sometimes in the moment.<\/p>\n<p class=\"wp-block-paragraph\">Ambiguity has become the baseline. \u201cWe are operating with more genuine uncertainty than at any point I can remember,\u201d says Chris Cochran, field CISO and vice president of AI security at SANS Institute, the cybersecurity training and research organization. \u201cIn that environment, intellectual flexibility is a decisive competitive advantage.\u201d<\/p>\n<h2 class=\"wp-block-heading\">When quarterly is too slow<\/h2>\n<p class=\"wp-block-paragraph\">When AI agents built by citizen developers at Grafana Labs started surfacing misconfigurations and incomplete controls nobody had caught, CISO <a href=\"https:\/\/www.linkedin.com\/in\/networkforensics\/\">Joe McManus<\/a> couldn\u2019t wait for the next annual planning cycle to respond.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIf you ask an agent to do something, it will try everything it can to complete that goal,\u201d he says.<\/p>\n<p class=\"wp-block-paragraph\">Those agent findings spurred McManus to add control audits and system segmentation to the open-source observability company\u2019s roadmap. Neither had been part of the plan a few months earlier.<\/p>\n<p class=\"wp-block-paragraph\">Planning beyond a year is close to \u201can exercise in futility,\u201d McManus says, given how quickly the landscape changes, especially with cheap, capable AI now available to nearly anyone. Cloud security, in his view, is largely a solved problem at this point. The open questions revolve around shadow AI and shadow code, and the integrations citizen developers build on their own.<\/p>\n<p class=\"wp-block-paragraph\">Grafana still keeps a two-year \u201cgoal map.\u201d But the second year gets reprioritized as the threat landscape shifts. And the team has abandoned long threat-modeling engagements with full code reviews in favor of weekly, tactical sprints with six-week turnarounds. Security, McManus adds, has no end state.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe luxury of a fixed three-year plan you set and forget is gone,\u201d says Cochran of SANS Institute. CISOs are now expected to deliver answers quarter to quarter and \u2014 increasingly \u2014 in the moment. AI, threat actor speed, budget cycles, and board pressure are compounding each other.<\/p>\n<p class=\"wp-block-paragraph\">Security review used to run in a straight line at Fable Security, a human-risk-management startup. The product team designed a feature, security and engineering reviewed the design, engineering built it, security and QA reviewed it again, and only then did the product ship.<\/p>\n<p class=\"wp-block-paragraph\">That sequence is gone, says Fable Security CISO Jacob Berry. Security now works alongside engineering as features release more quickly to keep pace with the market. The gates haven\u2019t disappeared, but the approach has changed from controlling teams to equipping them.<\/p>\n<p class=\"wp-block-paragraph\">Raja Chris, former CISO of Annaly Capital Management and founder and CEO of AI governance company AIVONS, notes that the better security tools today behave more like living systems, continuously discovering and responding to new exposures rather than waiting for the next planned review. CISOs\u2019 approaches to their strategies and roadmaps should follow suit.<\/p>\n<h2 class=\"wp-block-heading\">Where the long view still stands<\/h2>\n<p class=\"wp-block-paragraph\">Many security leaders still build multi-year roadmaps for threats <a href=\"https:\/\/www.csoonline.com\/article\/3552701\/the-cisos-guide-to-establishing-quantum-resilience.html\">such as quantum computing<\/a>, even as they expect AI-powered attacks to become the leading cyber threat over the next two to three years, according to <a href=\"https:\/\/kpmg.com\/us\/en\/articles\/2026\/cybersecurity-technology-risk-survey-ciso-resilience.html\">KPMG\u2019s 2026 Cybersecurity and Technology Risk Survey<\/a> of 310 security leaders at companies with more than $1 billion in revenue.<\/p>\n<p class=\"wp-block-paragraph\">Insight Global\u2019s long-term category includes commitments to data governance, core platform modernization, and international growth, an enterprise plan that Dickson\u2019s security team\u2019s timeline follows. At Fable Security, Berry\u2019s team still produces a long-range document he calls \u201ca direction and resourcing plan more than a technical roadmap.\u201d<\/p>\n<p class=\"wp-block-paragraph\">There\u2019s no hard-and-fast rule for how long a roadmap should run, SANS Institute\u2019s Cochran says. Long-horizon plans tend to focus on compliance and business commitments, or on major AI and infrastructure migrations. But even those aren\u2019t safe from disruption. A shift in budget or executive buy-in, he says, can derail a two-year roadmap overnight.<\/p>\n<h2 class=\"wp-block-heading\">Determining what goes where<\/h2>\n<p class=\"wp-block-paragraph\">Deciding which bucket a given piece of work belongs in isn\u2019t guesswork, though, Berry says. To make its determinations, his team asks two questions of each initiative: How many people will need to be involved to get it done, and how directly is it tied to a strategic commitment the business has already made?<\/p>\n<p class=\"wp-block-paragraph\">Work that requires wide coordination and ties directly to a standing commitment gets the longer horizon; narrower, more self-contained work is handled within the same continuous review cycle as tools and tactics.<\/p>\n<p class=\"wp-block-paragraph\">Outcomes such as identity and resilience endure for years, AIVONS\u2019 Chris says, but the specific technology delivering those outcomes rarely does. So he asks whether a given commitment still holds true if every vendor involved were replaced next year. If so, it probably belongs in the long-term plan. If not, it\u2019s really just an implementation choice \u2014 which should be handled on a faster cycle \u2014 being mislabeled as strategy.<\/p>\n<p class=\"wp-block-paragraph\">That\u2019s one of the ways roadmaps lose credibility, Chris says.<\/p>\n<h2 class=\"wp-block-heading\">Governance as an ongoing conversation<\/h2>\n<p class=\"wp-block-paragraph\">A roadmap that\u2019s rewritten every quarter can\u2019t be governed the same way a static three-year plan was, with a single sign-off and compliance checklist. What separates organizations handling this well from those struggling is leadership, says SANS Institute\u2019s Cochran. The CISOs thriving under quarterly replanning treat governance as a discipline of communication rather than compliance. Success depends on whether they can bring the board, the business, and their own teams along when the plan changes again.<\/p>\n<p class=\"wp-block-paragraph\">Berry sees that expectation firsthand from his own board. They want a clear account of how security is keeping pace with where the business is going, and what risk that pace introduces.<\/p>\n<p class=\"wp-block-paragraph\">Boards are asking different questions, AIVONS\u2019 Chris says. They used to ask whether the organization was secure. Now they want to see the evidence: what\u2019s running, who\u2019s accountable, and what can reach sensitive data.<\/p>\n<p class=\"wp-block-paragraph\">A report that can\u2019t distinguish between \u201cwe looked, and it was fine\u201d and \u201cwe never looked,\u201d he says, is claiming a confidence it hasn\u2019t earned. KPMG\u2019s 2026 survey points to a related challenge: 42% of security leaders say they struggle to demonstrate return on cybersecurity investment to their boards.<\/p>\n<p class=\"wp-block-paragraph\">The challenge of proving value as convincingly as proving risk is part of why the roadmap is evolving. CISOs haven\u2019t abandoned long-range thinking, but what they\u2019re willing to commit to in writing, and for how long, is changing.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThat is why I don\u2019t think the security roadmap is dead,\u201d says AIVONS\u2019 Chris. \u201cThe static roadmap is.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Insight Global\u2019s Dickson agrees. \u201cA long-range roadmap still has value,\u201d he says, \u201cas long as you\u2019re willing to revisit it as often as the world around it changes.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Insight Global\u2019s John Dickson had a problem familiar to many CISOs today. Employees were embracing AI tools faster than his security team could track them, and new AI agents and service integrations spread rapidly across the environment alongside them. Dickson and his security org had plans to build visibility into those non-human identities (NHIs), tracking [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9611,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9610","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9610"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9610"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9610\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9611"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9610"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9610"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9610"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}