Council Post: AI Is Changing The Economics Of Cyber Risk. CEOs Are Responding

Fran Rosch is the CEO of Imprivata, a digital identity company for life- and mission-critical industries.

getty

​For years, cybersecurity was largely viewed as an IT responsibility. Today, that perspective has fundamentally changed as cyber risk has become inseparable from business resilience.

Recent surveys consistently rank cyber threats among executives' greatest concerns—not simply because attacks have become more frequent and sophisticated, but because the consequences now extend well beyond technology. A successful cyberattack can halt operations, derail customer relationships, damage reputation and erode trust across every part of the business, in both visible and invisible ways.

Artificial intelligence (AI) is accelerating that shift.

AI Is Rewriting The Threat Landscape

Much of the discussion around AI focuses on productivity and innovation. Organizations are moving quickly to deploy AI assistants, autonomous agents and new digital workflows because the business opportunity is significant. But AI is also changing attackers' capabilities.

At my own company, I've seen how AI is changing the way leaders think about cyber risk. Modern AI systems dramatically reduce the time and expertise required to discover vulnerabilities, generate convincing phishing campaigns, automate reconnaissance and accelerate other stages of an attack. As capabilities that once required highly skilled adversaries become increasingly accessible, strengthening cybersecurity has become an even greater strategic priority.

AI changes how work gets done, but it also changes who—or what—has access to enterprise systems. That makes identity the connective tissue between AI innovation and organizational trust.

Identity Is The Foundation Of Trusted AI Innovation

The risks and opportunities AI offers create an uncomfortable tension for today's CEOs. While the pressure to move quickly intensifies, speed without governance can create risks that scale with the technology.

The challenge isn't choosing between innovation and security. It's recognizing that one depends on the other, which requires leaders to fundamentally rethink what security actually means.

Historically, organizations built defenses around networks and applications. The assumption was that if the perimeter was secure, the business was secure. Today, employees work from anywhere, critical applications span multiple cloud environments and third-party partners require access to sensitive systems. Increasingly, AI agents are also interacting directly with enterprise data and applications alongside human employees. The perimeter has dissolved, and identity has become the new control plane.

Every employee, contractor, partner, application and AI agent represents an identity that requires appropriate access to necessary resources at specific times. Managing those identities at scale has become one of the defining challenges of enterprise security.

Innovation Requires Governance

Strong identity and access governance allows organizations to answer questions that have become fundamental to resilience:

• Who has access?

• Should they still have it?

• Who or what is accessing sensitive information?

• Can we trace every action back to a trusted identity?

• If an incident occurs, can we quickly contain it without disrupting the entire business?

These questions are as important as ever as AI adoption accelerates. AI systems cannot create value without access to enterprise data. Agents need this information to retrieve knowledge, automate workflows and make decisions on behalf of human users. With each new AI deployment, however, an organization’s identity landscape expands. Without clear governance, organizations risk creating thousands of new identities operating with broad permissions and limited oversight. Such innovation without visibility inevitably creates risk.

The organizations that will realize the greatest value from AI won't necessarily be the first to adopt it. They'll be the ones that build governance into innovation from the outset. That means recognizing identity as a strategic business capability, continuously governing both human and non-human identities and applying adaptive access controls that respond to context instead of relying on static permissions. Done well, security becomes an accelerator for the business—not a barrier to innovation.

Most importantly, it means recognizing that trust has become a competitive advantage.

The CEOs Who Will Lead In The AI Era

Customers, employees, partners and regulators now expect organizations to demonstrate that sensitive information is protected, access is governed responsibly and critical operations can continue even when attacks occur. Resilience is no longer measured simply by preventing incidents but by how confidently an organization can continue to operate despite them.

That's why cybersecurity has moved into the CEO's purview. It provides the foundation organizations need to scale AI, drive digital transformation and maintain the trust that underpins long-term business success.

As CEOs, we're often asked how quickly we can adopt the next technology. The more important question is whether we're building the foundation that allows innovation to scale with confidence. In the AI era, governance, resilience and trust won't determine how fast organizations can move; they will determine how far they can go. ​


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?