At a Glance

  • U.S. companies are incorporating cyber risk into their overall enterprise risk strategies as AI adoption and business resilience drive major shifts in business priorities, according to a report released Tuesday by technology research and advisory firm Information Services Group (ISG).
  • As enterprises accelerate the adoption of agentic AI and migrate significant technology and data infrastructure to hybrid or multi-cloud environments, cybersecurity is increasingly viewed as a business-critical matter.
  • Business leaders are closely aligning cyber spending decisions with overall IT strategy. Additionally, C-level executives and board members are taking on greater responsibility for business continuity, financial risk, and regulatory compliance.

Deep Dive

The report reflects a significant shift in how large enterprises are changing the overall business risk discussion as AI cloud adoption expands.

AI adoption is forcing enterprises to rethink their corporate governance, internal controls, and overall preparedness for major cyberattacks or IT disruptions.

"Cybersecurity has become a core business consideration, rather than a standalone technical function," Jason Stading, ISG's cybersecurity director, told Cybersecurity Dive. "Enterprises are embedding cyber risk into AI adoption, digital transformation, and broader technology investment decisions; most recognize that security can enable innovation while managing enterprise risk."

According to Stading, chief information security officers and chief information officers are playing a more strategic role in these organizations. They work with corporate boards and executive leadership to help shape business decisions and ensure cybersecurity is integrated into overall business strategy.

A June report from S&P warned that enterprises lacking strong internal security governance could put their credit ratings at risk.

Meanwhile, U.K. authorities have urged business leaders to incorporate cyber risk into their overall business strategy and warned about the increasing number of attacks on critical infrastructure.

Editor's note: Additional commentary from ISG has been added.