Carl Windsor, CISO, Fortinet, on CISOs rethinking resilience, risk and leadership in an AI-driven world.
AI: Driving innovation, but at what cost?
AI is fundamentally transforming almost every business – not just by automating tasks but by changing how decisions are made, how value is created and how companies compete.
Previously, broad technology changes were within the remit of IT teams. The new wave of generative AI (GenAI) technology however is democratising technological changes, putting control into the hands of all teams. Every department is leveraging AI to enhance efficiency, facilitate better decision-making and deliver more personalised experiences for customers.
However, this brings with it some new risks including:
- Lack of transparency: Many AI models are opaque, making it difficult to interpret how the system arrived at its decision which can create accountability and compliance challenges.
- Privacy and data misuse: AI requires large often sensitive datasets to be uploaded to cloud-based systems. If teams are not adequately trained on the risks this could result in the leaking of sensitive personal information or intellectual property leading to privacy violations or regulatory breaches.
- Security vulnerabilities:
- Adversarial attacks: The subtle manipulation of input data to trick models into making incorrect predictions.
- Model inversion and extraction: Model queries enable attackers to reconstruct sensitive training data or to clone the model itself such as extracting personal faces from a facial recognition AI.
- Data poisoning: The manipulation of data to force it to generate incorrect predictions.
- Large language model (LLM) prompt injection: The circumvention of guardrails by embedding hidden instructions in text or websites that cause AI systems to ignore safety rules or leak data.
- Unexpected results: As AI agents interact more there’s a risk of coordination or collusion swarm attacks and emergent vulnerabilities. These threats are sometimes not covered by traditional cybersecurity frameworks.
- Weak identity and authentication: Agentic AI can enable multiple agents to query one another making autonomous reasoned decisions and taking actions to achieve specific goals often without human intervention. As the use of this technology increases the security of the agents’ non-human identity (NHI) becomes crucial as a weakness in the identity of one agent could lead to a cascading vulnerability.
Prediction: There have already been multiple breaches of AI LLMs. 2026 will see this increase in both volume and severity as AI accesses more and more sensitive data and agent-to-agent communication is allowed without considering identity and security implications.
Adversarial use of AI
There have been many cases of disinformation being used to unduly influence people. The power of AI takes this to a new level with services such as OpenAI DALL-E and Sora 2 which make the creation of almost indistinguishable audio images and videos trivial.
Prediction: Deep-fake services are going to take business email compromise (BEC) and social engineering to a whole new level.
The use of AI-generated audio has already been observed in extortion attempts but in 2026 organisations are expected to face an onslaught of audio- and video-generated content used for BEC phishing and other targeted attacks.
The CISO’s growing role in the boardroom
At the top of CISOs’ concerns over the past three years has been the cybersecurity skills gap. Fortinet has been working to close this gap by helping train one million people in cybersecurity by the end of 2026 and is well on the way to achieving that goal.
However, the 2025 Cybersecurity Skills Gap Report shows that multiple issues remain:
- IT leaders stated that the leading causes of breaches were the lack of security awareness (56%) and the lack of IT security skills and training (54%).
- Forty-nine percent of leaders do not think their board members are aware of the risks posed by using AI.
Prediction: More than ever the CISO’s place in the boardroom is critical. CISOs must communicate the benefits of new technologies like AI along with their associated business risks as clearly as possible so the board can determine its appetite for risk.
Cybersecurity is becoming so critical to boards that CISOs are increasingly becoming board members themselves broadening the experience of leadership teams.
The next generation of security experts
Gen Z (born between 1997 and 2012) is already well established in the workforce and Gen Alpha (born between 2013 and 2029) will begin entering the workforce in the coming years.
Because many new workers were raised in the digital age where information is abundant but attention is limited due to social media organisations must adapt their approach to recruitment training and work.
AI is also growing so rapidly that it is replacing many of the entry-level roles that new graduates would traditionally rely on to build experience. This removes stepping stones to more senior roles that are still required.
Prediction: AI fluency will become a baseline skill. It must be woven into every student’s curriculum to prepare tomorrow’s workforce for an AI-driven world. As entry-level roles evolve or disappear those who understand how to apply and secure AI will advance fastest.
The quantum of solace
Quantum computing is a complex technology unlike anything CISOs are used to. While quantum threats are not an immediate concern there is a real risk that malicious actors could adopt a ‘harvest now decrypt later’ strategy highlighting the urgency of preparing for a future where current cryptographic standards may become obsolete.
Prediction: More of a recommendation. Don’t wait. Start adding quantum readiness to procurement processes now so today’s purchases are quantum-ready for the future.
The CISO is dead! Long live the Chief Resilience Officer!
The CISO title belies the fact that the role is not purely security focused. CISOs enable business transformation and innovation while ensuring this happens safely and securely. Above all they must keep the business running at all times.
There have been multiple cases of businesses grinding to a halt in 2025 due to security incidents. CISOs must therefore understand the Minimum Viable Business (MVB) required to keep organisations running and ensure this capability is protected at all costs.
Prediction: Attacks on multi-billion-dollar multinational organisations will continue in 2026 driven by AI-enabled reconnaissance the growth of Cybercrime-as-a-Service and increased nation state–sanctioned activity.
CISOs need to plan for failure and focus on building robust business continuity plans including defining MVB requirements testing plans in practice and conducting regular tabletop exercises.
The Year of Resilience: What 2026 will demand from every CISO
2026 will test every assumption about how organisations defend recover and adapt to an evolving threat landscape. AI is now both weapon and shield and the line between IT and business risk has disappeared.
For CISOs the path forward is clear:
- Build resilience first. Assume disruption is inevitable and invest in business continuity segmentation and recovery readiness.
- Treat AI as a governed capability not a shortcut. Use it to enhance detection and response but protect models data and access with the same rigour as any other critical system.
- Harden identity everywhere. As human and machine agents multiply non-human identities must be secured and continuously verified.
- Strengthen collaboration. Break down silos between security operations and leadership. Resilience depends on shared understanding and unified response.
- Stay informed and adaptive. Threat actors innovate as quickly as technology evolves making continuous learning and testing core security disciplines.
The role of the CISO has never been more vital. Success in 2026 will belong to those who combine technical depth with strategic vision turning security from a reactive function into a force for resilience trust and growth.


