The future CISO will enable risk-taking, not just prevent it: Security leaders
https://etimg.etb2bimg.com/thumb/msid-134105190,imgsize-94076,width-1200,height=627,overlay-etciso,resizemode-75/corporate/the-future-ciso-will-enable-risk-taking-not-just-prevent-it-security-leaders.jpg

The next phase of the CISO role will be defined less by how effectively security leaders stop business activity and more by how confidently they help organisations take risk.
That was a central theme of the trilogue “The CISO Mandate 2026: From Defender to Architect of Enterprise Trust” at the 9th ETCISO Annual Conclave 2026 at Grand Hyatt, Goa. The discussion brought together Kalpesh Doshi, CISO & DPO, HDFC Life; Shivam Gupta, CISO, Dabur; and Lai Seow Yong, Head of Presales Engineering, APAC, Utimaco. The session was moderated by Muqbil Ahmar, Editor, ETCISO.
As enterprises accelerate artificial intelligence adoption, operate across increasingly complex technology environments and face growing expectations around privacy and resilience, the panel argued that CISOs must move beyond the traditional role of technology defender and participate directly in decisions about business risk, architecture and growth.
Shivam Gupta said the evolution is already moving cybersecurity leadership “from cyber defence to taking risks”, where the CISO is expected not merely to prevent attacks but to enable the organisation to take risk confidently and responsibly.
He pointed to AI adoption as one of the forces accelerating the transition. Businesses want to deploy AI safely and at scale, while customers, employees and vendors increasingly expect organisations to demonstrate how responsibly they handle data.
At the same time, resilience has become part of the mandate. Security leaders must think about how critical business processes continue or recover when an incident occurs, rather than working under the assumption that every incident can be prevented.
Tomorrow’s CISO needs business acumen
Gupta argued that this expanded mandate requires capabilities that go beyond cybersecurity expertise.
CISOs increasingly need to understand revenue, operations and business priorities to explain what could go wrong, quantify exposure and show leadership how the organisation intends to sustain operations.
Communication is equally important. Board engagement requires security leaders to explain risk through a business narrative rather than relying on technical terminology.
Technology foresight will also become critical as enterprise architecture changes. CISOs will have to understand the operating models, architectures and emerging technologies on which their organisations increasingly depend.
Summing up the progression, Gupta said the CISO of the past was primarily expected to protect technology risk, today’s CISO manages enterprise risk more broadly, while tomorrow’s security leader will increasingly help the organisation navigate it.
A board seat does not automatically create trust
Kalpesh Doshi said the growing prominence of the CISO should not be confused with the completion of the role’s transformation.
Cybersecurity has moved from being embedded within IT to becoming an increasingly independent function, and many CISOs have secured access to boards and senior leadership. But Doshi argued that having a seat at the table is only the beginning.
“We have a seat, but it’s time for us to now put up our talk,” he said, stressing that security leaders still have to demonstrate tangible value to the business.
Doshi challenged the traditional image of the CISO as a gatekeeper whose authority is demonstrated by stopping projects.
Security leaders may once have taken pride in being able to halt initiatives on security grounds, he said, but the more mature role requires an understanding of why the business wants to proceed and how risk can be brought within acceptable boundaries.
The CISO therefore has to shift from being a gatekeeper towards becoming what Doshi described more as a mediator or navigator — understanding both the risks facing the organisation and the business objectives it is trying to achieve.
Enterprise trust depends on knowing when to take risk
Doshi said security leadership ultimately requires a deeper understanding of business risk appetite.
The objective cannot be to eliminate risk altogether. CISOs need to help determine what risks the enterprise can accept, where safeguards are required and what controls will allow the business to proceed with greater confidence.
He used the analogy of navigating a ship: the security leader needs to understand the approaching storm, the resilience of the vessel and the route the organisation intends to take.
That role becomes particularly important with AI, where businesses are moving rapidly towards adoption while many of the underlying risks are still evolving.
For Doshi, the answer is not to obstruct AI adoption but to strengthen the foundations supporting it. If core controls, data governance and security architecture are weak, scaling AI will amplify existing weaknesses rather than solve them.
Trust does not mean nothing will go wrong
The expansion of the CISO mandate also requires organisations to rethink what they mean by trust.
Rather than promising that systems will never fail, the security function needs to create confidence that the organisation can respond appropriately when something does go wrong.
That places established cybersecurity disciplines alongside emerging responsibilities around data, AI and increasingly interconnected technology environments.
Doshi also argued that organisations cannot protect every piece of information with equal intensity indefinitely. As technology environments expand, enterprises will need to become more deliberate about understanding where their data resides, how it is used and which information remains sufficiently important to warrant the highest level of protection.
That prioritisation will become particularly important as organisations prepare for emerging risks such as post-quantum security.
AI and post-quantum security widen the architecture mandate
Lai Seow Yong, Head of Presales Engineering, APAC, Utimaco, brought the discussion towards the infrastructure and cryptographic challenges accompanying the CISO’s broader responsibilities.
He pointed to post-quantum readiness as an emerging challenge for organisations that depend on cryptographic protocols and algorithms to protect sensitive information.
At the same time, decentralised adoption of generative AI and AI agents creates new visibility and data protection challenges. Enterprises need to understand how information is being used by models and applications, protect sensitive data and establish controls around AI operations.
Lai highlighted advanced encryption approaches as one way enterprises can reduce exposure when sensitive information is processed, including protecting cryptographic operations through hardware security mechanisms.
The wider implication is that the CISO’s architecture mandate increasingly extends beyond perimeter security. Security leaders need to consider how data remains protected across cloud infrastructure, AI systems and emerging cryptographic environments.
The CISO should be consulted before the business moves
For Doshi, one of the clearest indicators that CISOs have earned enterprise trust will be when business leaders approach security before launching a new initiative rather than after decisions have already been made.
The ideal relationship, he said, is one where leadership brings a prospective product or business idea to the CISO and asks how it can move forward securely.
That represents a significant change from security functioning primarily as an approval layer at the end of the process.
Instead, the CISO becomes an adviser during the formation of business strategy — helping leaders identify acceptable risk, design safeguards and make better-informed decisions from the outset.
The discussion ultimately positioned enterprise trust not as an abstract security objective but as an outcome of business understanding, resilient architecture, responsible risk-taking and credible leadership.
The CISO’s growing visibility may have created the opportunity to influence strategy, but influence will increasingly depend on what security leaders do with that access.
The mandate for 2026 and beyond is therefore not simply to defend the enterprise. It is to help architect the conditions under which the enterprise can move faster, adopt new technologies and take calculated risks without losing control of the trust on which the business depends.
(With inputs from Sachi Srivastava.)
Firewall Support Company in India All type of Firewalls Support Provider Company in India












