ai · security · skills

For the CISO

The board just asked: are we OK on AI?

Track 2 · Your skills path is one click away. The story below is depth; the path names what to learn.

Score your mastery

Every function you own is adopting AI — most didn’t ask first.

The copilots landed in identity, in the SOC, in the pipeline, each on its own terms.

Now the board wants one answer, and your tools give you forty.

4 in 10

AI decision-makers name security and risk as their top AI concern — ahead of readiness, ahead of cost, ahead of the technology itself.

Forrester · State of AI Survey, 2025 · base 1,528 AI decision-makers

You are not behind, and you are not being replaced. Nobody has the textbook yet; these are emerging problems, and the frameworks are still being written.

What exists today is a way to see the whole estate on one grid, and an honest line between what’s governed and what merely got adopted, so you own the board answer.

Can I show, function by function, that AI hasn’t outrun our controls?

Yes. Two axes per function, one gate, one page.

Three things make that sentence true. Each one is next, in the order you’d present them.

The scorecard

Every function, one glance.

Each of your functions plots at two coordinates: how far AI has been adopted, and how well that adoption is governed. Above the diagonal, adoption sits inside what your controls can catch. Below it, something runs ahead of the controls that should catch it.

That diagonal is the whole argument, and the board reads it in a minute.

The board scorecard, function by function →

Every function, one glanceGoverned
SELF-ASSESSED · ILLUSTRATIVEAUTONOMY AHEADGOVERNEDAI AUTONOMY · AI Cyber Maturity Model (AI-CMM) 1–4GOVERNANCE · AI Security Maturity Model (AISMM) 1–5

Identity Security: Autonomy 2.0 of 4 (AI-CMM, our model · calibrated to SAE J3016), governance 3.0 of 5 — adoption is inside what the controls can catch.

Your portfolio, live — the same instrument the board page opens with.

The gate

Autonomy must never outrun governance.

Two ladders, one rule. Maturity grades how well each function’s AI is secured — the CSA AI Security Maturity Model, five levels. Autonomy grades how far the AI has been allowed to act — our own four-rung ladder, calibrated to SAE J3016.

The gate joins them: a function may only climb the autonomy ladder as far as its governance floor supports. No exceptions, no vibes — a rule your auditors can read.

The gate, applied to a function →

The top risks

Three lines you can read aloud.

The scorecard ends in sentences, not heat maps — the kind you can say to a board without a backup slide.

Security Operations adopted fastest — and is the one function where autonomy has outrun governance.

derived from the portfolio, function by function

Identity and Data are within the gate; their next autonomy step is already governed.

the gate reading, per function

Nothing here is a vendor score. Every number traces to a question your teams answered.

self-assessed · every reading labeled

The three lines, from your own portfolio →

Your reskilling list

11 controls have your name on them.

Not a course catalogue. These are the controls your program answers for, grouped the way you would delegate them.

10 to build · 1 to verify, not build. Nobody reskills for what the provider already owns.

Govern the AI program

4 controls

Set the appetite and the gates

3 controls

Own oversight and the ethics of use

3 controls

Build the AI-ready workforce

1 control

This is the same spine the assessment reads. Score your mastery on four concrete rungs per prompt, or run the function diagnostic — every gap lands on this list: the named skill, the group it belongs to, and who learns it.

Browse skills personalities →Run the diagnostic. Your gaps land on this list →

Fresh for you · the practice keeps learning

What just shiftedSTA-16 · 2026-07-20

Panorays 2026 CISO Survey: 60% View AI Vendors as Uniquely Risky but Only 22% Have Dedicated AI Vendor Policies

A survey of 200 CISOs across finance, healthcare, and technology found that while 60% view AI vendor risk as uniquely risky compared to traditional software, 52% still use general-purpose onboarding for AI vendors and only 22% have developed dedicated AI vendor evaluation policies. Additionally, 85% lack full supply chain visibility, 50% of incidents originate beyond direct third parties, and 79% have limited or no formal incident response plan for third-party breaches. Regulatory pressure has increased for 62% of CISOs in the past year, but only 22% feel fully prepared to meet new requirements.

Sharpens: CISOs must develop a dedicated AI vendor risk evaluation policy that accounts for model training data provenance, privacy controls, and algorithmic transparency. Extend supply chain visibility beyond direct third parties to fourth-party and nth-party relationships. Replace or augment static questionnaires with continuous risk monitoring. Build an operational playbook specifically for AI third-party breach response. Require AI vendors to disclose model architecture, data sources, and security testing results as part of procurement. · source

New way to build itGRC-02 · 2026-07-20

UC Berkeley CLTC Publishes Agentic AI Risk Management Standards Profile Extending NIST AI RMF

In February 2026, UC Berkeley's Center for Long-Term Cybersecurity published the Agentic AI Risk Management Standards Profile, extending the NIST AI RMF with targeted guidance for autonomous, goal-directed AI systems. The Profile addresses risks unique to agentic AI including unintended goal pursuit, unauthorized privilege escalation, self-replication, and expanded attack surfaces from tool access. It recommends proportional governance scaled to autonomy level, agent cards for structured documentation, escalation pathways with human-approval checkpoints, and continuous post-deployment monitoring. The Profile treats risk as an emergent property of autonomous systems rather than solely a property of individual models.

Sharpens: CISOs should adopt the Agentic AI Profile's proportional governance model: classify AI agents by autonomy level, authority scope, and operational environment. Implement escalation pathways and human-approval checkpoints for high-risk agent actions. Deploy continuous monitoring for agent behavior evolution post-deployment. Integrate agent cards into AI system documentation alongside model cards. Use the Profile's guidance to map harm pathways for each deployed agent and calibrate oversight to agent classification. · source

On the frontiernot yet on the CSA spine · 2026-07-20

Okta Research Reveals Only 34% of Organizations Apply Equal Security Controls to AI Agents as Human Workers

Okta's 2026 global survey found 92% of executives report widespread AI agent use, yet only 34% apply the same rigorous security controls to agentic identities as they do to human workers. Meanwhile, 58% of executives reported an AI-related security incident or close call in the past 12 months, and 52% of employees admit to using unapproved AI tools. The gap between executive confidence (90% believe they have visibility) and shadow AI reality creates a massive governance blind spot. 54% of employees using unapproved tools shared internal messages and emails, 45% uploaded sensitive HR data, and 39% exposed confidential documents.

Sharpens: CISOs must establish parity between human and non-human identity management for AI agents. Implement identity verification, role-based access control, and continuous behavioral monitoring for every AI agent with the same rigor applied to employees. Conduct a shadow AI discovery audit to identify unsanctioned AI tools. Publish clear, actionable AI usage policies embedded directly into daily workflows, and deploy technical enforcement controls rather than relying on policy alone. · source

What just shiftedGRC-06 · 2026-07-20

SEC Makes AI Disclosure a Standing 2026 Examination Priority with Board Oversight Expectations

The SEC's FY2026 Examination Priorities designate AI-related disclosures as a focus area, examining registrant claims about AI capabilities for accuracy. Commissioner Uyeda stated the SEC expects issuers to define AI, describe board oversight, and separate internal versus customer-facing AI impacts. The SEC also created an AI Task Force led by a Chief AI Officer, signalling that AI governance expectations will be enforced through exams, comment letters, and enforcement actions. The SEC repeatedly frames AI issues as variations on familiar securities law concepts: accuracy and completeness of statements, reasonable basis and substantiation for claims, and material risk disclosure.

Sharpens: CISOs must inventory and map all AI use cases across the business, pressure-test external AI claims in earnings scripts and investor materials against actual deployment status, and align risk factor disclosures to the company's real AI profile. Implement AI-specific disclosure controls: document board oversight structure, management steering committees, and escalation paths. Treat AI-related disclosure as a disclosure-controls topic, not innovation messaging. · source

What just shiftedGRC-14 · 2026-07-20

EU AI Act Article 50 Transparency Obligations Take Effect August 2, 2026

From 2 August 2026, organizations must comply with Article 50 of the EU AI Act, requiring transparency disclosures for AI systems that interact with individuals, generate synthetic content, perform emotion recognition, or create deepfakes. The obligations apply beyond high-risk systems to certain limited-risk AI. The EU Digital Omnibus Proposal delays synthetic content marking requirements until Dec 2, 2026 for pre-existing systems, but all other transparency rules take effect on the August deadline. The European Commission published draft Guidelines and voluntary transparency icons to support compliance.

Sharpens: CISOs must inventory all AI systems interacting with individuals or generating content, assess which Article 50 obligations apply, and implement content-labelling mechanisms including metadata tagging, watermarking, or cryptographic provenance. Update procurement contracts to allocate transparency responsibilities between providers and deployers. Document exemption analyses where disclosure is deemed unnecessary and integrate AI transparency measures into existing GDPR and regulatory notice frameworks. · source

New way to build itSTA-11 · 2026-07-19

Health Sector Coalition Publishes Six-Phase AI Third-Party Risk and Supply Chain Transparency Guide

The Health Sector Coordinating Council Cybersecurity Working Group published a comprehensive Third-Party AI Risk and Supply Chain Transparency Guide in April 2026, providing a full-lifecycle process from AI use case justification through end-of-life management. The six phases cover: Phase 0 (use case justification and strategic assessment), Phase 1 (vendor evaluation and due diligence with AI-specific assessment questions covering data lineage, bias mitigation, security controls, and model transparency), Phase 2 (contract negotiation with AI-specific legal protections), Phase 3 (implementation and integration), Phase 4 (ongoing monitoring including model drift detection and adversarial robustness), Phase 5 (incident response including model compromise scenarios), and Phase 6 (end-of-life and transition management). The guide is grounded in the NIST AI RMF and addresses vendor opacity risks including subcontractors, offshore development, open-source AI assets, and vendors who refuse to sign BAAs. While healthcare-sector specific, the methodology transfers to any regulated industry procuring AI from third parties.

Sharpens: Adapt the six-phase AI vendor lifecycle process for your organization: incorporate AI-specific due diligence questions about data lineage, bias testing, and model drift detection into existing third-party risk assessments; ensure contracts include AI-specific provisions for model change notification, adversarial robustness testing rights, and end-of-life data and model transition · source

Control ids above refer to the CSA AI Controls Matrix (AICM).

8 functions. Two readings each. One page.

Self-assessed where a run exists, illustrative where it doesn’t — always labeled which.

Open the board scorecardRun the 20-minute assessment
Every number above has a method page behind it: each piece opened up as inputs → mechanism → outputs, with provenance — and the deeper tables named, content owner-gated.The method, piece by piece →

Not your role?

Each role has its own way in. Here is where the others start.