All posts
·Candela Security

CISO Priorities for 2026: What Security Leaders Are Focused On

CISO priorities in 2026: AI governance, identity security, and board communication are now at the top of every security leader's agenda. Here's what changed.

security-leadershipciso priorities 2026cybersecurityciso challenges 2026cybersecurity leadership trendssecurity leader priorities

CISO priorities in 2026: a different kind of job

The CISO role has been quietly redefined over the past two years.

It used to be a technical role that reported to the CIO, managed the security stack, and escalated incidents. That version of the job still exists — but it's not what's expected anymore. Today's CISOs are expected to quantify risk in financial terms, present directly to the board, navigate AI governance questions no framework was built to answer, and do all of this while managing a more complex threat environment than ever before.

Global cybersecurity spending reaches $212 billion in 2026, up 15.1% from the year before. Eighty-five percent of organizations increased their security budgets. And more than half of security leaders still believe they're not investing enough.

This guide covers what the CISO agenda looks like in 2026 — the real priorities, not the vendor-driven ones.

AI security governance: from "we'll figure it out" to policy

AI wasn't even in the top five CISO priorities two years ago. In 2026, it's number one.

The shift happened because AI moved from experiment to production. GenAI tools are embedded in development workflows, customer service pipelines, HR processes, and financial operations at most mid-to-large companies. And in most of those companies, security teams had no seat at the table when adoption decisions were made.

The CISO challenge isn't just "is our AI provider secure?" It's more fundamental: Where is sensitive data flowing? Which AI agents have access to what systems? What happens when an AI model is retrained on data it shouldn't have seen? Are employees using personal ChatGPT accounts to process customer data?

83% of security leaders say they're concerned about AI access. And nearly half — 47% — have already observed AI agents exhibit unintended or unauthorized behavior in their environment.

The organizations getting ahead of this are doing three things. First, establishing an AI security policy that defines what tools are approved, what data categories can be used with them, and how exceptions get handled. Second, building visibility — you can't govern what you can't see, and 92% of organizations currently lack full visibility into their AI identities and agents. Third, extending their identity governance to cover AI agents as distinct actors with managed permissions, not just background processes.

Shadow AI — employees deploying personal or unapproved AI tools for work tasks — is the most common near-miss CISOs are dealing with. By 2026, the problem has evolved into what Forrester calls "shadow agents": autonomous AI systems deployed without security review, creating invisible data pipelines outside of policy controls.

Identity security: the perimeter nobody is watching

For the last decade, identity has been called "the new perimeter." In 2026, the identity threat surface has grown in a way that older IAM (Identity and Access Management) frameworks weren't designed to handle.

The issue is non-human identities. AI agents, service accounts, CI/CD pipeline tokens, cloud workload credentials, and API integrations now outnumber human users inside most enterprise environments — often by a significant margin. And the governance practices built for human accounts don't scale to this.

A departing developer gets their access revoked. But the service account attached to the integration they built? It stays. With prod access. Indefinitely.

The KPMG 2026 cybersecurity report flags non-human identities as one of the most underweighted risks on the current CISO agenda. When an AI agent needs access to a database, a file system, and three external APIs to do its job, it needs its own managed identity with scoped permissions — not shared credentials borrowed from a human account.

The practical implication: your IAM review process probably doesn't include AI agents, service accounts, or API tokens as first-class entities. If you're scoping a security review or commissioning a penetration test, identity sprawl — including machine identities — should be in scope.

Cyber resilience: what's actually changed

Cyber resilience isn't a new concept, but the framing has shifted. For most of the past decade, resilience meant backup and disaster recovery: can we restore our systems if something goes wrong?

The 2026 version is more demanding. The question is whether your organization can continue operating — not just restore data — during an active incident. That means your incident response plan needs to account for AI-assisted attack speeds, partial system compromise scenarios, and supply chain failures outside your direct control.

Boards increasingly view operational resilience as a non-negotiable. The expectation is no longer just "can you recover?" but "how long would it actually take, and what would be running in the meantime?"

Most organizations have never tested their resilience at that level. A tabletop exercise that walks through a ransomware scenario is useful. Actually simulating the communication breakdowns, decision bottlenecks, and partial system failures that happen in real incidents is different. That gap — between theoretical IR plans and tested operational resilience — is what CISOs are spending serious time on this year.

This is also where penetration testing and red team assessments become inputs to resilience planning, not just compliance checkboxes. If you haven't mapped which findings from your last pentest would have enabled ransomware deployment or lateral movement, that's the analysis worth doing.

Third-party risk: supply chain exposure is the top attack surface

Here's a number worth sitting with: 43% of CISOs cite third-party risk as their top priority in 2026. That's nearly double the share who flagged AI-enhanced attacks.

The reason is simple. Enterprise software stacks are deeply interconnected. The average mid-size company has 130+ SaaS applications. Each one is a potential entry point — not because of sophisticated zero-days, but because of credential theft, misconfigured integrations, or a breach at a vendor that cascades into your environment.

High-profile supply chain compromises have made this concrete. It's no longer an abstract risk. CISOs have watched companies get breached not because their own security failed, but because a vendor's security failed and the blast radius extended outward.

The practical response most security teams are working toward in 2026:

Tiered vendor assessment. Not all vendors need the same scrutiny. Vendors with access to production systems, customer data, or privileged credentials warrant deeper due diligence than a project management tool only accessible to internal staff. Building a tiered framework — typically three or four levels of scrutiny based on access and data sensitivity — makes the process manageable.

Contractual controls. Requiring evidence of SOC 2 Type II, ISO 27001, or penetration testing as a contract condition has become standard for enterprise vendors. Some organizations are going further, requiring specific security controls for high-risk integrations. Our guide to penetration testing for compliance covers what these frameworks actually require.

Integration-level review. OAuth integrations, API tokens, and webhooks that vendors use to access your data need periodic review. Permissions creep happens slowly and visibly. An annual audit of third-party access is a reasonable baseline.

Board communication: speaking the language of business risk

The SEC's cybersecurity disclosure rules changed the dynamic between CISOs and boards permanently. Companies must now disclose material cybersecurity incidents within four business days of determining materiality, and annual filings must cover cyber risk management, strategy, and governance.

That means the board has a direct line of responsibility for cybersecurity posture. And it means CISOs who can only speak in technical terms — vulnerabilities, CVEs, patch status — are going to struggle.

The 2026 CISO agenda is heavily weighted toward one skill: translating security exposure into financial terms. How much would a breach in this system cost? What's the probability of a credential-based attack given our current controls? What's the residual risk after this investment, and what would we need to spend to move the needle?

This is called cyber risk quantification, and the frameworks for doing it — FAIR (Factor Analysis of Information Risk) is the most widely used — are becoming standard tools in the CISO toolkit rather than academic exercises.

The shift is organizational too. More CISOs are reporting directly to CEOs rather than CIOs, a change that reflects the recognition that cybersecurity is a business risk function, not just a technology function.

For security leaders preparing board presentations in 2026: lead with business impact, not technical detail. The board doesn't need to understand CVSS scores — they need to understand what's at stake and what you're doing about it. The ROI case for security investment, framed in terms of potential losses avoided and regulatory exposure reduced, lands better than a list of controls implemented.

Tool optimization: doing more with what you have

Security tool sprawl is expensive and counterproductive. The average enterprise runs 76 security tools. Most of those tools generate alerts that no one has the capacity to triage.

"Optimizing security tools and services" is the third-ranked initiative for CISOs in 2026 — and it's not because security teams suddenly have budget to spare. It's because the ROI conversation with boards requires demonstrating that existing investment is working before asking for more.

The practical agenda here includes vendor consolidation (fewer platforms with deeper integration vs. more point tools), tuning alert thresholds to reduce noise, and moving toward platforms that automate more of the detection-to-response workflow.

Crucially, tool optimization doesn't mean cutting testing. Organizations that reduce their external security testing to save budget are trading short-term savings for long-term exposure. A well-scoped penetration test run annually — or more frequently for high-risk environments — is one of the highest-ROI security activities available. Our penetration testing cost guide lays out what realistic pricing looks like and what drives variance.

Regulatory compliance: NIS2, DORA, and the new wave

If you operate in or sell to European markets, 2026 is not a year to wait on compliance.

NIS2 (the EU's updated Network and Information Systems directive) dramatically expanded the scope of organizations covered by cybersecurity requirements — including many mid-size companies that weren't subject to the original NIS. Penalties are significant: up to €10 million or 2% of global annual turnover for essential entities.

DORA (the Digital Operational Resilience Act) applies specifically to financial services and their technology providers, with strict requirements around incident response, third-party risk management, and — explicitly — penetration testing. DORA mandates TLPT (Threat-Led Penetration Testing) for the most critical financial entities.

For US-based CISOs, the SEC disclosure rules remain the primary regulatory driver, with the FTC Safeguards Rule adding requirements for financial services companies handling consumer data.

The common thread: regulators are increasingly prescriptive about what security programs need to include, and "we have a firewall" is no longer a sufficient answer. If you're not sure whether your current security program meets the requirements of the frameworks relevant to your business, a compliance gap assessment — which often starts with a penetration test — is the fastest way to find out.

What this means for how you run security

A few themes pull these priorities together.

Security is a business function now, not just a technical one. That means metrics need to connect to business outcomes, budgets need to demonstrate ROI, and the CISO needs to be able to hold a credible conversation with any member of the executive team about risk, not just with the CTO.

The attack surface is increasingly outside your direct control — vendors, AI tools, non-human identities, third-party integrations. Your security program needs to extend visibility and governance to cover all of it, not just the infrastructure you own.

And testing — external, independent, technically rigorous — is more important than ever, precisely because the environments CISOs are responsible for are more complex and more interconnected than they were three years ago.


Wondering what a thorough security review actually looks like for your environment? Book a free consultation with our team and we'll walk you through what a pentest engagement looks like for your stack.

Frequently Asked Questions

What are the top CISO priorities in 2026?

The leading CISO priorities in 2026 are AI security governance, cyber resilience, third-party risk management, board-level risk communication, and identity security — particularly for non-human identities like AI agents and service accounts.

How has the CISO role changed in recent years?

The role has shifted from primarily technical — managing security tools and responding to incidents — to a business risk function. CISOs are now expected to quantify risk in financial terms, present to boards, navigate regulatory requirements, and demonstrate measurable ROI on security investment.

What is the biggest cybersecurity challenge for CISOs in 2026?

AI governance is widely cited as the top challenge. The rapid adoption of GenAI tools, AI agents, and automation has created risks — shadow AI, uncontrolled data flows, unmanaged AI identities — that traditional security frameworks weren't designed to address.

How much are organizations spending on cybersecurity in 2026?

Global cybersecurity spending is projected at $212 billion in 2026, up 15.1% from 2025. Eighty-five percent of organizations increased their security budgets, though more than half of CISOs believe their organizations still aren't investing enough.

What regulatory changes are most important for CISOs in 2026?

NIS2 and DORA are the major drivers for organizations with European operations or financial services exposure. In the US, SEC cybersecurity disclosure rules — requiring rapid reporting of material incidents and annual governance disclosures — have become a central focus for public companies.


Want to secure your company?

Book a free 20-minute consultation with our security team.

Book your free call