Briefing Overview

  • According to a report released Tuesday by technology research and advisory firm Information Services Group (ISG),reportU.S. companies are incorporating cyber risk issues into their overall enterprise risk strategies, while AI adoption and business resilience are driving significant shifts in business priorities.
  • As companies accelerate the adoption of agentic AI and migrate large volumes of technology and data infrastructure to hybrid or multi-cloud environments, cybersecurity is increasingly viewed as a critical business issue.
  • Corporate leadership is closely integrating cybersecurity spending decisions with overall IT strategy. Additionally, C-suite executives and board members bear greater responsibility for business continuity, financial risk exposure, and regulatory compliance.

Deep Insights

The report reflects a significant shift in how large enterprises discuss overall business risk amid the expanding scope of AI cloud adoption.

AI adoption is forcing companies to reassess their corporate governance, internal controls, and overall preparedness for major cyberattacks or IT disruptions.

"Cybersecurity has become a core business consideration, rather than a standalone technical function," ISG cybersecurity director Jason Stading told Cybersecurity Dive. "Companies are embedding cyber risk into AI adoption, digital transformation, and broader technology investment decisions; most recognize that security can enable innovation while managing enterprise risk."

Stading noted that Chief Information Security Officers (CISOs) and Chief Information Officers (CIOs) are playing a more strategic role in these organizations. They work with corporate boards and executive leadership to shape business decisions and ensure cybersecurity is integrated into overall business strategy.

A June report from S&P warned thatcompanies lacking robust internal security governancemay face the risk of credit rating damage.

Meanwhile, UK authorities haveurged business leadersto incorporate cyber risk into overall business strategy and have raised alarms over the increasing number of attacks on critical infrastructure.