The top three priorities for modern CISOs

The top three priorities for modern CISOs

Cybersecurity is at a critical inflection point. The ways we protect and defend our applications are evolving at machine speed as AI and frontier models advance. CISOs and wider security teams are under tremendous pressure to keep up and it’s leading to high stress levels and an increasing number tempted to leave their roles.

To thrive in the current climate, CISOs need to accelerate their use of AI to detect and remediate risks faster than AI-powered attacks can occur. Everything from vulnerability management and security operations to resiliency circuit breaking must now employ AI to defend organisations. Because put simply, humans cannot keep pace with machine speed attacks, without adopting machine speed defences.

Emerging API and AI trends are reshaping CISO responsibilities. The priority now is to defend against AI-powered threats before they overwhelm existing security operations and the people at the helm of them.

1. Understand AI’s impact on your infrastructure

The majority of application portfolios today are AI-enabled. Experimental projects are now finding their way into real-world use and organisations are using the technology to accelerate automation. In fact, the volume of machine-generated internet traffic is likely to exceed human traffic very soon. 

The move to AI and AI-supported automation is happening quickly. Yet most information technology (IT) environments aren’t designed for agility amidst these rapid changes, presenting a huge challenge for security leaders. 

For instance, AI systems introduce new types of runtime behaviour inside the environment. Applications call models. Agents invoke tools. Automation systems generate continuous API activity. Models interact with other services to retrieve data, trigger workflows, or execute operational actions. These interactions create entirely new communication paths inside enterprise infrastructure, which CISOs must address. 

Knowing where AI and automation live within infrastructure is key. And once AI app and automation traffic, routings and endpoints are known, they need to be analysed for vulnerabilities so the right preventive and policy controls can be applied. 

2. Securing AI models and inference are integral

Inference is now the dominant AI activity for most organisations, with the average enterprise now using seventrained AI models to power inference engines and draw conclusions, make predictions or generate content. 

As enterprises reap the incredible predictive capabilities that AI inference offers, the underlying infrastructure has gotten a lot more complicated. 

Over half (52%) of organisations are chaining or orchestrating multiple AI models. This, in turn, brings new security risks such as routing manipulation, data exfiltration through model chains and inconsistent policy enforcement across models. 

In addition, 90% of businesses will soon route inference through shared infrastructure. While shared infrastructure has its economic advantages, it increases security and performance risks. 

All of this is adding to the complexity CISOs are already grappling with. To obtain the visibility and discovery they need, security teams must treat model routing and the inference layer as integral parts of their infrastructure, applying the same observability and controls as they currently do with application routing and security. 

Similarly, they must realise that the security boundary has moved from the models themselves to the inference path. As a result, inference traffic must be delivered, inspected, authenticated and governed like any other critical app interaction. 

3. Unifying infrastructure management

Amid these rapid changes, 35% of organisations say their infrastructure is not ready to support AI workloads. Discussions about AI readiness often focus on performance: access to GPUs, adequate compute capacity, storage throughput and networking bandwidth. While those concerns are real, it’s not all about capacity. For CISOs, it’s also a security architecture issue and the ability to efficiently implement and enforce controls as AI adds another layer of complexity. 

AI workloads increase the potential blind spots. To improve their AI readiness, security leaders must simplify their sprawling environments and that requires a unified approach. 

Without a unified platform that can observe and manage these connections, CISOs will lack the controls to respond in an efficient and strategic manner. The result will be a reactive cycle in which they struggle to implement the right policies, detect fraud and attacks and remediate vulnerabilities as they’re discovered. 

Tackling AI security challenges

Hybrid and multi-cloud infrastructures are becoming increasingly complex thanks to the rapid rise of AI and automation. To meet the new challenges this reality presents, CISOs must adapt by prioritising visibility, control and simplicity. 

Integrating AI-powered security into existing application and API operational security workflows is fundamental. CISOs must be equipped with flexibility and agility to protect their organisations in this evolving landscape. Using AI-powered defences not only offers this adaptability but also a strategic business advantage to meet today’s threats head-on.

Michael Montoya, Chief Technology Operations Officer, F5

Michael Montoya

Michael Montoya is Chief Technology Operations Officer at F5 where he is responsible for the enterprise‑wide strategy and execution to operate the company with security and resiliency at its core. He leads F5’s Security, Risk, and Digital Operations organizations, driving end‑to‑end operational trust for customers, partners, and employees.

Author

Scroll to Top

SUBSCRIBE

SUBSCRIBE