In a nutshell: According to a KPMG report and experienced CISOs, the role will evolve by 2029 from a reactive risk guardian into a strategic enabler of secure, AI-driven business innovation.
Security leaders and analysts expect the CISO to evolve in the coming years from a pure risk guardian into a strategic enabler of secure innovation. A recent KPMG report and assessments from experienced CISOs paint a picture of growing business responsibility alongside mounting pressure from both threats and innovation.
Wolfgang Goerlich, a CISO for seven years and now working in a public-sector position as well as a faculty member at IANS Research, describes the historical evolution of the role since its emergence in 1995 in three phases: from the “department of no,” through “let’s slow down,” to “let’s take smarter risks based on understanding.” For the coming years, he expects CISOs to increasingly act as drivers of innovation, advising boards and executive leadership on how companies can take calculated risks with new technologies, including AI.
A KPMG report published in 2026 on the evolution of the CISO role supports this assessment: digital platforms, artificial intelligence, and third-party ecosystems are accelerating change, meaning security leaders are increasingly expected to enable speed of response while also taking on responsibility for enterprise-wide risk. According to KPMG, the modern CISO operates at the intersection of technological opportunity and unprecedented risk, which requires a fundamental evolution of the role — from a pure technologist to a business leader and “storyteller” who can translate complex threats into a business context. KPMG describes this as a transition to becoming a “strategic facilitator of secure innovation,” whose task is to enable the organization to innovate at a safe and trustworthy pace.
Goerlich says he is already experiencing this shift firsthand: he was tasked with building an innovation team that brings together architecture, engineering, and security professionals. In his research work at IANS as well, he increasingly encounters CISOs who lead or co-lead innovation processes. According to Goerlich, boards and executive leadership are increasingly recognizing that security leaders in leadership roles accelerate rather than slow down innovation, since they know how to take calculated risks. He expects that by 2029, more CISOs will be responsible for general enterprise risk in addition to cyber risk — though he stresses that the concrete shape of the role will continue to vary by organization, ranging from more risk-oriented to more tactically focused positions.
Diana Kelley, CISO at Noma Security, describes a similar shift: CISOs are increasingly moving away from a purely defensive and compliance-focused role toward a function as an enabler of business strategy. For CISOs in the DACH region, this development means that board communication, business acumen, and the ability to clearly convey risk trade-offs for innovation initiatives — particularly in the context of AI — are likely to gain importance, while purely technical and reactive tasks may correspondingly decline in relative significance.
Source: www.csoonline.com · Published August 17, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.