As Corelight’s CISO, Bernard Brantley leads governance, risk and compliance, secure infrastructure, security operations and IT.
Over the past few years, security stopped being a technical checkbox and became a business requirement. The questions coming at my team now aren’t the old ones—not “Are you SOC 2 compliant?” or “Do you have an incident response plan?” Those have been table stakes for years. The one I got this year, first on a questionnaire and then on a call, was sharper: How are you using AI to speed up your own detection and response to keep pace with attackers using the same technology?
That tells you where the CISO sits now: inside decisions that used to belong to sales, legal and the CFO.
Take FedRAMP, for example. A federal agency can’t switch to cloud-based, SaaS providers if they don’t have a FedRAMP-authorized offering. That’s not a checkbox. FedRAMP requires 24/7 support, U.S.-based employees and a third-party assessor path.
The real questions I get now are business questions: What’s the resourcing plan? Who do we need to pull off one goal to stand up this one? And the pressure is tightening. In June 2026, CISA’s Binding Operational Directive 26-04 gave federal agencies as little as 72 hours to remediate the most dangerous vulnerabilities: those actively exploited, internet-facing and automatable.
This mandate is an agency requirement, but vendors will feel it immediately when something happens: A customer on a 72-hour clock needs its suppliers on that same timeline. The customer doesn’t only need to know your product is secure; they also need to ensure that your product enables them to meet their own requirements. Answering that changes what we sell and what we sign up for, making this much more of a business discussion than focusing on securing the enterprise’s systems.
It’s worth being honest about what isn’t driving this: aggressive SEC enforcement. Enforcement under the SEC’s cyber disclosure rule has been uneven, and from what I’ve observed, markets have largely shrugged off disclosed incidents. But CISOs continue to behave as if disclosure matters, and that’s correct and important. But what’s pulling security into the boardroom is more the issue of customer trust combined with the reality that federal and regulated businesses now run through security teams, not federal regulators.
AI turned the volume up on all of this. You’d have to be living under a rock not to hear about how frontier models are accelerating how fast attackers can find and exploit vulnerabilities. If attackers get access to a new model before defenders do, that could be game over. Addressing that SOC-acceleration question now means showing you can run AI end to end through security operations, from threat hunting and detection engineering to alert triage, all with humans still owning incident response. Done right, teams could report gains in how fast they triage alerts and ship detections. But this is not just a security metric anymore. Now it’s an operational metric, which a CFO can relate to.
The C-suite and the board are asking questions, but CISOs need to show restraint to focus on the business case. AI is promising to make everything better, cheaper and faster at once. Then a bill comes in that’s four times higher than what headcount would have cost. It’s no surprise 42% of security leaders in KPMG’s 2026 survey said that they struggle to show cybersecurity ROI to executives and boards.
The best approach I’ve found is to work backward from the top line or the bottom line. Find one workflow with a measurable line to improving revenue or margin, apply AI there and see if it’s a two-times or a 20-times improvement first. Moving everything to AI too quickly can cause expenses that will lose the support of the CFO if they don’t see how revenues or profits improve.
The same thinking changes headcount. The old model I and many leaders were used to said a 20% revenue growth target meant hiring eight more account executives tomorrow. The new question is whether a lighter team, say a sales lead, product owner and an engineer, all fluent in AI, can hit it without hiring new people. That’s an organizational design question, and the CISO has a voice in the issue now because the tooling runs through the security stack.
Getting that voice is one thing, but holding it with the board can be another. The 2026 Benchmark Report from IANS, Artico Search and The CAP Group, surveying more than 650 CISOs, found 95% now update their board regularly and 60% reach the full board. But only 25% get more than 30 minutes, and just 30% call the relationship strong and collaborative. In the report, IANS’s Nick Kakolowski put it plainly: “CISOs who discuss risk at a peer level get treated as belonging. Those who try to pull the board into operational risk get phased out of the discussion.”
I have a few ideas to help close that gap. Talk in outcomes, not controls. A board doesn’t want a vulnerability count; it wants to know what a dollar of security does to revenue, margin or trust. Don’t let everything route through the CTO or CIO, because security filtered through someone else’s priorities reads as a technical function. Bring a risk-tolerance conversation, not a compliance report. And own more than the security stack where you can, so you see AI use cases and departmental metrics firsthand.
The structures haven’t caught up. Companies that keep the CISO buried in a technical line are building a blind spot into the org chart at the exact moment security is shaping revenue, contracts and headcount. The fix isn’t a new title. It’s a direct line to the CEO or COO, real board time and a mandate that runs past the security estate into how the business gets built.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?





