Deloitte: 49% of Organizations have a CISO

A senior executive in a suit stands in a corner office, gazing at a monitor displaying identity-access logs, with city skyline visible.

“These days it’s getting down to hours,” a chief information security officer (CISO) at a major American biopharmaceutical company told Deloitte’s 2026 Global Technology Leadership Study, describing the time left once a flaw surfaces. Deloitte, the global professional-services and audit firm, polled 662 senior technology leaders about artificial intelligence (AI) for its 2026 Global Technology Leadership Study. The study found that companies are creating CISO jobs faster than they hand that office real authority over AI governance. Forty-nine percent of organizations now have a CISO, up from 31% in 2023, while only 11% of those same leaders still count legal, compliance, and risk among their top priorities.

Four C-Suite Roles Touch Every AI Agent, One Signs for It

Four different roles have a hand in every AI agent Deloitte’s survey describes: the CISO, the chief technology officer (CTO), the chief information officer (CIO), and the chief data and analytics officer (CDAO). Add the vendors that build the underlying models, and the agents themselves, and the line between who decided and who answers for it gets hard to find. Deloitte reports that 80% of automation leaders plan to speed up AI-agent investment, while only 21% say their agentic AI governance is mature enough to handle what they are about to deploy.

Vendor reliance is rising at the same time. Sixty-three percent of the technology leaders Deloitte surveyed say it grew over the past year, and 62% expect it to keep growing over the next two. Every one of those vendors can push code, models, or access decisions into a company’s environment, and each one is third-party risk the CISO inherits once it’s inside.

AI Governance’s Missing 11%

Deloitte frames this as shared responsibility: the CISO, the CTO, the CIO, and the CDAO all touch an AI agent’s rollout, and none of them owns it alone. That framing dodges the harder question. Boards find it easier to hire one person with a fitting title than to hand legal, compliance, and risk teams the budget and authority an AI agent’s mistakes actually require. Hiring a CISO looks like progress on an org chart; funding the teams that hold contract terms, data rights, and vendor audits does not, so it keeps losing the budget fight.

When an AI agent causes harm, the company will blame the person with the title, the CISO, while the teams that actually had the power to prevent it stay untouched. Nobody signs off on that trade before it happens, so nobody owns the call after it does. We’ve flagged this visibility gap before: CISOs can’t be the last line of defense for AI agents they can’t fully see.

Three Moves to Put Someone in Charge of the Call

Fix the sequence, not the org chart: visibility has to come before any rule about who answers for what an agent does. As we’ve noted, AI keeps expanding the CISO job, and naming who answers before the agent acts is the next expansion. Deloitte’s own research points to three moves that would actually change the outcome.

Treat every agent’s access like a person’s – Extend identity and access management (IAM) so it logs not just who can reach a system, but which agent touched it, when, and on whose authority. That answers the question Deloitte says most companies still can’t: who, or what, can access what.

Set the automatic-versus-human line before an agent crosses it – Decide in advance which actions an agent can take alone, which need a human, and which pause the agent entirely. The biopharmaceutical CISO’s hours-not-weeks timeline only helps if that decision already exists when the alert fires.

Fund the 11% along with the CISO – Merge cyber, compliance, and vendor risk into one process with named owners. Give legal and compliance a seat before the next contract, not after the next incident. Boards that hire a CISO but skip this step have paid for the title, not the fix.

The next time a flaw turns into a live compromise in hours instead of weeks, the biopharmaceutical CISO’s account should mean someone knows who answers for AI governance, not whose name is on the door.

Join our LinkedIn group Information Security Community!

Holger Schulze
Holger Schulze is the founder and publisher of Cybersecurity Insiders, an independent cybersecurity research and media company. He writes about how AI is reshaping cybersecurity, where attackers are moving faster than defenses, and what security leaders can do about it. His work draws on original research and real-world incidents, translating both into practical guidance for security teams. Holger moderates the Information Security Community on LinkedIn, one of the largest professional networks in cybersecurity. Connect at linkedin.com/in/holger-schulze

No posts to display