HomeSecurityThe 10 biggest problems facing CISOs today

The 10 biggest problems facing CISOs today

From escalating AI-driven threats to budgets that don’t scale with the expansion of threats, security leaders are reshaping their agenda to address several key long-standing and emerging concerns.

See also: CISA law expires at the end of September

CISO

The CISO job is tough and getting tougher: 66% of security leaders surveyed by the ISACAsaid their roles are more stressful today than they were five years ago – in the midst of a pandemic.

CISOs face increasing risks, competing priorities, tight budgets and more. Below are the 10 issues that concern them most today.

  1. Artificial Intelligence Infrastructure Security

Any CISO (Chief Information and Data Officer) who has been in the industry for any length of time knows that emerging technologies evolve faster than the tools and strategies for effectively securing them. The same is not true for artificial intelligence.

Many organizations are neglecting to strengthen security in their rush to adopt AI. However, CISOs are catching up. According to ISACA survey findings, 47% of security leaders said they have helped develop AI governance (up from 35% in 2024) and 40% said they have been involved in AI implementation (up from 29% the previous year).

  1. Scaling — and accelerating — attacks with the support of Artificial Intelligence

A 2025 survey by Boston Consulting Group found that 80% of CISOs worldwide cited AI-enabled cyberattacks as their top concern, a 19-point from the previous year. A 2025 survey by Darktrace, a security technology company, found that 78% of CISOs reported significant impact from AI-driven threats, a 5% from 2024.

  1. Data Security in a World of Artificial Intelligence

Nearly 67% of security leaders surveyed for Proofpoint ’s 2025 Voice of the CISO Report said they consider information protection and governance a top priority. The report also found that only two-thirds said data within their organization is adequately protected, despite nearly all CISOs reporting having data loss prevention technologies in place.

  1. An ever-expanding threat landscape

The volume and velocity of attacks have been increasing for decades, a trend that CISOs and their teams are constantly trying to keep up with. Artificial intelligence has only accelerated that trend, says Katell Thielemann, senior vice president of research at research firm Gartner.

See also: HoundBytes launches an automated security analyzer

The 10 biggest problems facing CISOs today
  1. Increasingly ferocious attacks

Security experts have long warned that anyone could be a victim of a cyberattack, but hope remained that some entities were off-limits. The September 2025 breach of Kido International Preschool , in which hackers used photos and names of about 8,000 children the company served to demand ransom, was seen by many as a new low.

  1. Budget constraints

Research shows that the majority of organizations are spending more on security year after year, but the increases haven't kept pace with the increasing volume and ferocity of attacks. This increases the pressure that CISOs feel, Thielemann.

  1. Preparing employees so they don't fall victim to increasingly sophisticated scams

CISOs are looking for training and awareness campaigns that can address the new generation of electronic “phishing” and fraud attempts.

  1. Quantum computing

As they continue to struggle to ensure the speed of AI adoption and the escalation of AI-based threats, CISOs must also prepare their organizations for the arrival of quantum computing, says Tony Velleca, UST CISO and CEO of CyberProof, a UST subsidiary.

  1. Setting the right priorities

Resolving these issues is itself a top concern for CISOs, says Matt Gorham, head of PwC's Cyber ​​and Risk Innovation Institute.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Neon Cyber ​​shifts cybersecurity focus to human resources

EDR
  1. Correct risk prioritization

To prioritize their work, CISOs need to understand what matters most to the business and which risks are most significant to the organization. But many still struggle with these tasks, says Chris Simpson, director of the National University Cybersecurity Center.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS