U.S. companies incorporate cyber risk into broader strategic vision
According to a report released Tuesday by Information Services Group, U.S. companies are incorporating cyber risk issues into overall enterprise risk strategies, with AI adoption and business resilience driving significant shifts in business priorities. Cybersecurity is increasingly seen as a critical business issue, with companies accelerating the adoption of agentic AI and transitioning to hybrid or multi-cloud environments. Corporate leadership is closely integrating cyber spending decisions with overall IT strategy, with C-suite executives and board members taking on greater responsibility for business continuity, financial risk, and compliance.

Briefing Overview
- According to a report released Tuesday by technology research and advisory firm Information Services Group (ISG),reportU.S. companies are incorporating cyber risk issues into their overall enterprise risk strategies, while AI adoption and business resilience are driving significant shifts in business priorities.
- As companies accelerate the adoption of agentic AI and migrate large volumes of technology and data infrastructure to hybrid or multi-cloud environments, cybersecurity is increasingly viewed as a critical business issue.
- Corporate leadership is closely integrating cybersecurity spending decisions with overall IT strategy. Additionally, C-suite executives and board members bear greater responsibility for business continuity, financial risk exposure, and regulatory compliance.
Deep Insights
The report reflects a significant shift in how large enterprises discuss overall business risk amid the expanding scope of AI cloud adoption.
AI adoption is forcing companies to reassess their corporate governance, internal controls, and overall preparedness for major cyberattacks or IT disruptions.
"Cybersecurity has become a core business consideration, rather than a standalone technical function," ISG cybersecurity director Jason Stading told Cybersecurity Dive. "Companies are embedding cyber risk into AI adoption, digital transformation, and broader technology investment decisions; most recognize that security can enable innovation while managing enterprise risk."
Stading noted that Chief Information Security Officers (CISOs) and Chief Information Officers (CIOs) are playing a more strategic role in these organizations. They work with corporate boards and executive leadership to shape business decisions and ensure cybersecurity is integrated into overall business strategy.
A June report from S&P warned thatcompanies lacking robust internal security governancemay face the risk of credit rating damage.
Meanwhile, UK authorities haveurged business leadersto incorporate cyber risk into overall business strategy and have raised alarms over the increasing number of attacks on critical infrastructure.