Analyst Report

Forrester Report: The AI CISO

AI agents are already acting inside your organization — accessing systems, making decisions, and triggering consequences faster than any human team can monitor. The question is no longer whether your organization is going to embrace AI, it’s how will you adapt your plan to secure it.

Forrester found that 73% of AI decision-makers say that their organization has documented AI policies, but policies alone will not govern autonomous agents. Without architected guardrails and automated controls, every agent your organization deploys is operating without a safety net.

The AI CISO outlines the transformation underway across the security function and gives leaders a concrete framework for building trust and assurance at enterprise scale.

Access the full report

Inside The AI CISO
The Shifting CISO Mandate
  • How the CISO role moves from policy enforcement to engineering automated agent guardrails at scale
  • Why agentic sprawl is already a challenge for 56% of organizations — and what traditional controls miss
  • The shift from IT observability to intent-aware oversight: knowing not just what happened, but why
Regulatory Accountability
  • How the EU AI Act assigns liability up the supply chain — and what that means for the CISO personally
  • Japan's AI Guidelines and the global push for executive-level accountability for AI actions
  • Why future CISOs will be named, accountable officers under multiple simultaneous regulatory regimes
The Future Security Organization
  • New roles emerging now: trust engineers, AI governance advisors, agentic workflow assurance engineers, and AI red team orchestrators
  • How automation takes over day-to-day detection and response — and what that frees security teams to do
  • Why the CISO needs real authority alongside the CAIO, and how boards must respond
ABOUT FORRESTER'S RESEARCH

Now in its latest cycle, Forrester's security research is among the most rigorous independent assessments available to enterprise security leaders. Forrester evaluates trends, technologies, and organizational dynamics across thousands of respondents — including its State of AI Survey 2025, Q4 2025 AI Pulse Survey, and Security Survey 2025. The AI CISO draws on this data to give practitioners a benchmark they can trust, not more vendor opinion.

WHY THIS REPORT MATTERS FOR YOUR ORGANIZATION

Whether you are mapping the future of your security organization for the first time or building the case for AI governance investment with your board, this report gives you an independent, analyst-backed framework for the decisions ahead. Cynet customers and partners receive access to Forrester research and security intelligence as part of our commitment to keeping your organization protected and informed.

73 %
of AI decision-makers have documented AI policies — but policies alone will not govern autonomous agents 
56 %

of generative AI decision-makers say agentic sprawl is a current challenge for their organization

5.5 years

average tenure of a Fortune 500 CISO — this transformation will define every security leader's career

Information in Forrester publications is based on Forrester’s efforts to compile and analyze the best resources reasonably available to Forrester at any given time. Opinions reflect judgment at the time and are subject to change.  This report is part of a broader collection of Forrester resources, including interactive models, frameworks, tools, data, and access to analyst guidance.  

Backed by the industry, loved by customers.

MITRE_ATTACK-Evals_new_logo

Outstanding results in 2025 MITRE

  • 100% Detection Visibility
  • 100% Technique-Level Coverage
  • 100% Protection
Learn more
G2-tags-spring2026

Top-tier performance according to our users

  • 98% score for Real-Time Detection
  • 97% score for 24x7 support​
  • 97% score for Automated Remediation
Learn more
gartner-peer

Recommended by 95%

  • Overall 4.8/5 Rating​
  • Product capabilities 4.8/5 Rating​
  • Ease of deployment 4.8/5 Rating​
Learn more