Businesses worldwide are increasing the responsibility and influence of their chief information security officers (CISOs), according to the latest research from Deloitte.
In the fourth edition of its Global Future of Cyber Survey, the multinational professional services firm found that organisations are increasing their Boards awareness of critical cybersecurity issues as threats become ever more urgent.
According to Deloitte’s survey of 1,200 cyber decision-makers across 43 countries, 25% of respondents from cyber-mature businesses reported 11 or more cybersecurity incidents in the past year, a 7% increase of incidents since the 2023 survey.
With that rise in cyber-attacks, the report highlights that CISOs are taking on more responsibilities, becoming key partners to CEOs and Boards, with the role growing as the C-suite becomes more tech-savvy.
Though moving in the right direction, the data shows there is still some way to go. Only about half (52%) of all respondents said they were very confident in the C-suite and Board’s ability to adequately navigate cybersecurity, however among high-cyber-maturity organisations, that confidence in the C-suite and Board grows to 82%.
Deloitte said that around one-third of respondents reported a significant increase in CISO involvement in strategic conversations about tech-related capabilities in the past year, while 20% of decision-makers say their CISOs now report directly to their CEO.
That’s leading to a surge in spending, with 57% of respondents anticipating an increase to their cybersecurity budgets over the next 12 to 24 months, and 58% expecting to integrate cybersecurity spending with budgets for other programs, like digital transformation initiatives, IT programs, and cloud investments.
The top three expected outcomes from ramping up such cybersecurity initiatives are protecting intellectual property (46%), improving threat detection and response (44%), and increasing efficiency and agility (44%).
As cyber-tools, particularly within AI, continue to evolve, business areas such as cloud (48%), GenAI (41%), and data analytics (41%) are becoming priorities for increased spending.
AI in particular is becoming ever more concerning for cybersecurity teams, with organisations adopting the technology into their security measures.
Of the 39% who reported using AI capabilities in their cybersecurity programs, most use it to continuously monitor digital infrastructures (42%), create advanced simulations (40%), automate security processes, speed up response time, and analyse data in real-time (all 39%).
Recommended reading
- UK Businesses Face New Cyber-attacks Every 44 Seconds in Q2 2024
- Half of Cybersecurity Professionals Expect to Burnout Within the Next Year
- Cyber Leaders Reveal Compliance and Boardroom Struggles
Even with the flood of AI threats, organisations have an eye to the future threat landscape, most notably in regards to quantum readiness. The majority (83%) of respondents said they were assessing quantum-related risks or taking some kind of action, whether developing strategies, implementing pilot solutions, or creating solutions at scale.
While over half (52%) are still assessing their exposure and developing quantum related risk strategies, the rest (30%) are taking decisive action to implement solutions as early adopters.
“As threats become more sophisticated and impactful to core business, CISOs are increasingly required to adopt a more strategic role driving cross business risk prioritisation and mitigation,” said Emily Mossburg, Deloitte’s global cyber leader.
“The close relationship between CISOs and CEOs is a testament to the role security plays in a business’s long-term success. Today, CISOs are not only protectors against outside threats, but key players helping their organisation find success by integrating cyber considerations in the strategic decision-making process.”





