The cybersecurity leadership model that worked yesterday will not be enough for the enterprise of tomorrow.
I have spent enough time around technology transformation to know that leadership rarely becomes obsolete overnight.
It happens more quietly.
The environment changes.
The assumptions change.
The speed of decision-making changes.
And eventually, the old leadership model starts creating more risk than value.
I believe cybersecurity is at that point now.
The next generation of cyber leaders will inherit an environment where AI can accelerate both defence and attacks, software vulnerabilities can be exploited at unprecedented speed, third-party dependencies can become enterprise-wide exposures, and employees are increasingly interacting with AI systems that organisations may not fully understand.
That is not the cybersecurity environment I started with.
And it requires a very different leader.
The Threat Has Changed. Has Leadership Changed with It?
The numbers are difficult to ignore.
The World Economic Forum’s Global Cybersecurity Outlook 2026 found that 94% of respondents expect AI to be the most significant driver of change in cybersecurity in 2026. At the same time, 87% identified AI-related vulnerabilities as the fastest-growing cyber risk.
But there is another number I find even more interesting.
Only 64% of organisations reported having processes to assess the security of AI tools before deployment, although that figure has nearly doubled from 37% the previous year.
https://www.weforum.org/publications/global-cybersecurity-outlook-2026/digest
That gap tells us something important.
Technology adoption is moving faster than organisational readiness.
And whenever that happens, leadership becomes the differentiator.
The Old Cybersecurity Playbook Was Built Around Control
Traditional cybersecurity leadership was largely built around a familiar model:
Identify → Protect → Detect → Respond → Recover
That model still matters.
But today’s leader has to operate one level above it.
The question is no longer simply:
“How do we protect the environment?”
It is increasingly:
“How do we allow the business to move faster without creating unacceptable exposure?”
That is a fundamentally different leadership problem.
A modern CISO may be expected to advise on:
- AI adoption
- Software supply chains
- Digital products
- Cloud transformation
- Fraud
- Regulatory exposure
- Business continuity
- Third-party risk
- Data strategy
- Executive reputation
Cybersecurity has moved closer to the centre of enterprise decision-making.
The leader has to move with it.
AI Is Changing the Job Before It Changes the Job Title
One of the most significant changes I see is the transformation of the cybersecurity workforce itself.
ISC2 reported in July 2026 that 56% of cybersecurity professionals surveyed believe AI has reduced the need for entry-level positions over the previous year.
But the same study found something more encouraging:
53% believe AI is creating new types of entry-level cybersecurity roles.
https://www.isc2.org/Insights/2026/07/ISC2-AI-pulse-survey-2026
This is not simply automation replacing people.
It is a redesign of the career ladder.
Tasks such as alert triage, log analysis, vulnerability prioritisation, and report generation are increasingly being accelerated by AI.
That means tomorrow’s leaders cannot rely on the same progression that worked for previous generations.
The profession is going to need people who can move earlier into:
- AI security
- AI governance
- Risk interpretation
- Security architecture
- Business analysis
- Decision-making
- Human-AI collaboration
The entry point is changing. Therefore, the leadership pipeline must change too.
The Boardroom Has Become Part of the Attack Surface
From a board perspective, cybersecurity is no longer something that can be delegated entirely to the security function.
The board has to understand what risk the organisation is accepting.
The CEO has to understand how cyber risk can affect growth.
The CISO has to explain what investment is required and why.
And the leadership team has to agree on what happens when prevention fails.
This is why I increasingly see cybersecurity leadership as a governance discipline, not simply a technical discipline.
A 2026 World Economic Forum analysis argues that cyber resilience should be measured upstream, through preparedness and early mitigation, not only by how quickly an organisation recovers after an incident.
That is a significant shift in executive thinking.
The board shouldn’t only ask, “How quickly can we recover?”
It should also ask:“How early can we recognise that we’re becoming vulnerable?”
The Speed of Exploitation Has Changed the Meaning of Preparedness
Consider the latest Verizon DBIR findings.
For the first time in the report’s 19-year history, vulnerability exploitation surpassed stolen credentials as the leading initial access vector, accounting for 31% of breaches reviewed.
More importantly, Verizon reports that AI is helping attackers compress the time needed to exploit known vulnerabilities, from months to hours.
That changes the leadership equation.
A quarterly vulnerability review may have made sense in a slower environment.
A heavily manual process may have been acceptable when response windows were measured in weeks.
But when the attack cycle accelerates dramatically, leadership has to ask:
Which decisions can we automate?
Which controls need continuous monitoring?
Where are humans still essential?
Where is our response process simply too slow?
The future leader must manage time as a security variable.
Third-Party Risk Is Becoming Leadership Risk
One of the most uncomfortable realities of modern enterprise security is that your organisation doesn’t control its entire attack surface.
Your suppliers do.
Your cloud providers do.
Your technology partners do.
Your software ecosystem does.
And increasingly, your AI providers do.
Verizon’s 2026 DBIR reported that third-party involvement in breaches increased 60%, reaching 30% of breaches reviewed.
That makes third-party risk more than a procurement issue.
It becomes an executive accountability issue.
A future cyber leader needs to understand the organization’s dependency map:
Who do we depend on?
What can they access?
What happens if they fail?
How quickly can we isolate the impact?
What assumptions are we making about their security?
This is where cybersecurity leadership intersects with enterprise strategy.
The Skill I Would Prioritise Above Everything Else
If I had to choose one capability for tomorrow’s cyber leaders, it wouldn’t be a particular certification.
It would be judgment.
Technology can tell you what is possible.
Security tools can tell you what is happening.
AI can increasingly tell you what deserves attention.
But someone still has to decide:
What matters most?
That decision requires context.
It requires understanding the business.
It requires knowing when to accept risk, when to challenge it, and when to stop the organisation from moving too quickly.
That is leadership.
What I Would Expect from a Future Cyber Leader
If I were evaluating someone for a senior cybersecurity role today, I would look beyond technical competence.
I’d want to know whether they can:
Think commercially
Can they understand how security decisions affect revenue, customers and growth?
Think systemically
Can they see relationships between AI, suppliers, technology, people and regulation?
Think at speed
Can they make sound decisions when the environment is changing faster than the traditional planning cycle?
Challenge intelligently
Can they disagree with senior stakeholders without becoming disconnected from the business?
Communicate uncertainty
Can they tell the board what is known, what isn’t known and what should happen next?
Build organizational capability
Can they create a security function that doesn’t depend on one exceptional individual?
Lead through ambiguity
Can they remain decisive when there is no perfect answer?
These are not traditional “soft skills.”
These are executive security capabilities.
The Leadership Pipeline Needs to Change Too
There is another issue we should discuss openly.
If AI is automating portions of traditional entry-level cybersecurity work, we need to rethink how future leaders acquire experience.
We cannot simply remove repetitive work and assume leadership skills will appear automatically.
Organisations need deliberate development paths.
That means giving emerging professionals exposure to:
- Business risk discussions
- Incident simulations
- Executive briefings
- AI governance
- Vendor-risk decisions
- Cross-functional projects
- Board-level cyber exercises
- Crisis communication
- Strategic planning
Technical exposure builds competence.
Decision exposure builds leaders.
My Advice to the Next Generation
Don’t build your career around the tools that exist today.
Build it around your ability to understand what changes next.
Learn cybersecurity deeply.
But also learn:
How businesses make decisions.
How boards think about risk.
How AI changes accountability.
How organizations respond under pressure.
How trust is built between security and the business.
And perhaps most importantly:
Learn how to make a decision when there isn’t enough information.
Because that is where leadership begins.
The New Cybersecurity Leadership Equation
I see the next generation of cyber leadership as a combination of five capabilities:
Technical depth
Business judgment
AI literacy
Executive influence
Resilience thinking
None of these can replace the others.
Technical knowledge without business judgment creates technically elegant decisions that may not serve the organisation.
Business knowledge without security depth creates dangerous optimism.
AI literacy without governance creates uncontrolled experimentation.
Executive influence without technical credibility creates distrust.
And security without resilience creates a false expectation of perfection.
The future requires all five.
Tomorrow’s Leaders Must Think Beyond the Breach
The strongest cybersecurity leader of the next decade may not be the person who prevents the most incidents.
It may be the person who helps the organization make better decisions before an incident happens.
That means understanding where to invest.
Where to automate.
Where to slow down.
Where to accept risk.
Where to challenge assumptions.
And where to prepare for failure. That is a very different definition of cybersecurity leadership.
My Closing Thought
I don’t believe the future of cybersecurity belongs to people who can predict every threat.
Nobody can.
I believe it belongs to leaders who can build organisations capable of responding intelligently to whatever comes next.
AI will change.
Attack techniques will change.
Regulations will change.
Technology stacks will change.
But the need for sound judgment will not.
So, my advice to tomorrow’s cyber leaders is simple:
Don’t inherit the old playbook. Understand why it existed; and then have the courage to rewrite it.
Because the next decade won’t just require better cybersecurity.
It will require a different standard of cybersecurity leadership.





