CultureAI
All blog posts
NewsResearch

Inside the CISO Mindset: 5 Themes From a Candid Discussion

Ria ManzaneroHead of Marketing
PublishedRead time5 min readShare

In brief

  • CISOs are reframing resilience around data rather than infrastructure: knowing what is exposed, where it flows and whether control can be proven.
  • Detection and alerts are no longer enough. Security teams want controls that intervene at the moment of risk without adding workload.
  • Blocking AI has been quietly abandoned in favour of monitoring and enablement, yet real visibility into how AI is used is still missing.
  • Security is increasingly a human problem, with stress, fatigue and culture now directly tied to risk.

The Eskenzi IT Security Analyst & CISO Forum wasn’t a typical security event. This forum was a gathering of CISOs, analysts, and security leaders speaking candidly under Chatham House Rule about what’s actually breaking, what’s working, and where things are heading.

Here are 5 key themes that came through loud and clear. None of them were surprising. But together, they paint a pretty stark picture of where security and AI are right now.

Boardroom

1. It’s Not an Infrastructure Problem. It’s a Data Problem.

One theme anchored the entire discussion: we’re still framing the problem incorrectly.

Several CISOs pushed back on the idea that infrastructure is the core issue. The reality is more uncomfortable. Infrastructure might be where attacks land, but data is where the real risk sits.

As one CISO put it:

“Infrastructure is broken, but the core issue is data.”

That shift matters. Because it reframes resilience entirely.

It’s no longer just about uptime or recovery. It’s about understanding what data is exposed, where it’s flowing, and whether you can prove control when something goes wrong, especially when that question comes from the board or the CFO.

2. We Need Automated Controls, Not Just Alerts.

There’s no shortage of security tooling in the enterprise. If anything, that’s part of the issue.

CISOs are questioning why, despite everything they’ve already invested in, problems still exist.

“The problem isn’t the tooling. It's the controls the tooling offer.”

The real issue is that most tools were built for a different era. They detect. They log. They alert.

But they don’t intervene in the moment the risk actually happens.

That’s where the friction shows up.

“If scanning finds something, then what? We’ve just added work to a team that’s already overloaded.”

This is the gap: not visibility, not detection, but execution.

Security teams need systems that prevent things from going wrong in the first place, without creating more work.

That’s why the model is shifting.

The tools that win won’t be the ones that generate better alerts. They’ll be the ones that:

  • Understand behaviour, not just events
  • Act at the point of interaction (not after)
  • Reduce workload instead of adding to it

In other words, any tools introduced need to have a control layer: one that sits inside the workflow, guides behaviour in real time, and closes the gap between policy and action.

3. AI Has Already Outpaced Control.

There was no debate about whether AI is being used inside organisations. That question is settled.

The real issue is control, or more accurately, the lack of it.

“We can’t stop people using AI. They’ll just use their phones.”

That’s the reality most organisations are now dealing with. AI usage is happening across sanctioned and unsanctioned tools, and increasingly inside everyday SaaS products, where it’s even harder to detect.

What’s changing is the approach. Blocking is being quietly abandoned. Not because it’s a bad idea in theory, but because it doesn’t work in practice.

“We moved from ‘block everything’ to ‘monitor and educate’.”

That shift is significant. It signals a move away from enforcement as the primary control, toward behaviour and enablement.

Because ultimately, AI adoption is being driven by the business, not security.

4. Visibility Is Still the Missing Piece

Almost every conversation about AI circled back to one starting point: visibility.

Not high-level reporting. Not dashboards for the sake of it. Real visibility into how AI is actually being used.

“The first step is getting the visibility.”

Right now, most teams don’t have that. Or at least not at the level they need.

They don’t know:

  • How widely AI is being used
  • Which tools are involved (especially shadow and embedded AI)
  • What data is being shared in prompts or uploads
  • Where the real risk sits versus normal behaviour

So decisions get made with incomplete information.

As one CISO admitted:

“We’re winging it with the best data we’ve got.”

That’s the gap. And it’s only getting wider as AI becomes embedded across more systems and workflows.

5. Security Is Becoming a Human Problem

One of the more interesting shifts in the conversation was how often people, not technology, came up as the limiting factor.

Stress. Fatigue. Burnout. Culture.

These aren’t side issues anymore. They’re directly tied to risk.

“People are more likely to make mistakes when under stress.”

At the same time, expectations are increasing. More tools, more alerts, more pressure to respond faster, all while the threat landscape is accelerating.

There’s a growing recognition that security isn’t just a technical discipline. It’s behavioural.

“Each individual person is a firewall.”

That idea may be challenged in some circles, but it’s a practical reality in a world where a single prompt can expose sensitive data.

So What Do CISOs Actually Want?

The closing question of the session was simple: What do you need?

They weren’t asking for more features or more innovation for the sake of it.

They want:

  • Simplicity
  • Less friction
  • Tools that genuinely reduce workload
  • Solutions that fit into how teams already operate

And above all:

“Don’t sell on fear. Solve real problems.”

What This Means Going Forward

One comment stuck more than most:

“We can’t keep up with the pace of change.”

That’s not a failure. It’s the environment.

AI is accelerating everything: how people work, how data moves, how risk is created. And that pace isn’t slowing down. Which means the model has to change.

Security can’t rely on controls that sit outside the workflow, react after the fact, or depend on already stretched teams to interpret and act.

Keeping up with this pace requires controls that operate at the same speed as the behaviour itself, embedded into how people use AI, able to guide decisions in real time, and capable of reducing risk without slowing work down.

In practice, that means introducing technologies that don’t just detect or report on AI usage, but actively shape it as it happens.

👉 Learn more about CultureAI's AI Security and Governance Platform.

Uncover hidden AI risk

Start a free 2-week AI Risk Assessment. Easy setup. Fast visibility.