Mustafau | iStock | Getty Images
For senior cybersecurity leaders at leading companies, the stakes have never been higher.
“It feels like my job has doubled or quadrupled,” said Wally Dalrymple, chief security officer at ETS, a global education and human resources solutions company.
“It’s coming at us very fast and in very large quantities,” he said.
The rise of artificial intelligence has suddenly brought chief information security officers out of the server room and into the boardroom, forcing leaders to navigate a rapidly changing threat landscape while dealing with changing budgets and business needs.
Hacked by fraudsters in July OpenAI Autonomous agents on the open source developer platform Hugging Face have accelerated that change, proving that the era of advanced AI hacking has arrived. We also showed how far agents would go to reach their goals.
In the weeks since then, the list of agent-led attacks has grown, with Reuters reporting on Friday that another swarm of OpenAI agents broke containment and took over German websites in May.
The startup paused some of its AI research and training after the Hugging Face attack, but the security incident hasn’t stopped OpenAI from releasing new products. The company this week announced the rollout of its latest GPT-6 Astra model, despite previously warning of “significant” cyber capabilities.
And the pace of releases of models with special cyber capabilities continues unabated. google Gemini 3.8 Flash Cyber human This week we’re also releasing Fable 5.1 and Mythos 5.1.
“The ground beneath our feet is changing,” he said. Dell John Simone, head of security. “It’s completely changing the variables, the safe assumptions, that we’ve been able to rely on for decades.”
“Worth its weight in gold”
For all the added stress, there is one big silver lining. That means the job market is booming for CISOs with the talent and technical skills to tackle the world of AI.
Michael Piacente, co-founder and managing partner at cybersecurity research firm Executive Partners, said qualified candidates who check the box are easily earning salary packages in excess of seven figures, but recruiters need to act quickly.
Piacente said his team often works 18 to 20 hours a day, but still loses candidates to other offers in one search per week. He hasn’t seen comparable dynamics since the introduction of the cloud.
“It was more of a slow drift,” Piacente said. “Like AI, it didn’t all come together at once.”
For years, companies have considered deep cybersecurity expertise and government and compliance experience to be coveted skills for CISOs. In the age of AI, these qualifications are just the bare minimum.
As AI becomes more prevalent, CISOs are not only responsible for keeping bad actors out, but also managing the company’s AI agents and data management.
JC Christian, president of Christian & Timbers, a major executive recruitment firm, says the technical background, including experience and risks in building AI security, has become non-negotiable for companies.
“Many CISOs who were able to operate a few years ago are probably not ready for today’s world,” Christian said.
AI-proven CISOs also need strong communication skills and confidence to present to boards of directors and weigh in on major business decisions such as mergers and acquisitions.
This has changed organizational structures, allowing many security officers to report directly to the CEO rather than the chief information officer, said Meredith Griffanti, global head of cybersecurity and data privacy communications at FTI Consulting.
For example, Barclays analyst Saket Kalia told CNBC this week that he has heard from CISOs whose meetings with CEOs have gone from once a month to three times a week.
CISOs with crisis management experience, strong business acumen and the ability to present on stage at industry conferences like Black Hat are “very valuable,” Griffanti said.

“Spider Sense”
CISOs are under pressure to quickly deploy AI defenses, but urgent demand doesn’t necessarily mean budgets or tools can keep up.
According to Gartner data, cybersecurity budgets are expected to increase by 6% in 2026, largely due to new tools to protect and implement AI. IDC analyst Craig Robinson said spending was higher in some parts of the world, with the Middle East and Africa seeing a 16% year-over-year increase.
Mission-critical sectors such as finance, pharmaceuticals, energy, and healthcare are scrambling to shore up their cyber defenses before attackers deploy the latest AI tools.
Joe Sullivan, a former chief information officer at Uber and Facebook who runs a cyber consulting business, said that because the technology is so new, “some security teams are so overwhelmed that they don’t know where to start, and they’re not ready for prime time when it comes to security products.”
Top cybersecurity vendors have emerged as major winners, with CrowdStrike and Okta’s recent earnings showing a surge in demand for AI defense. After a sluggish start to the year amid widespread concerns about the disruption of AI, stocks have rebounded sharply. CrowdStrike and Palo Alto Networks are up about 80% this year, and Octa stock has nearly doubled.
While long-standing all-in-one incumbents appeal to customers through bundling, there is an explosion of startups committed to tackling AI problems.
As a result, many CISOs are having to use their “spider sense” to weed out the winners or advocate for a few solutions until a clearly better solution emerges, says Jeremiah Kuhn, global head of information security at AppLovin.
Mr Dalrymple said the scope of decision-making and the pressure to implement it had never been more challenging.
“I feel the weight of the world figuring out how to do it myself,” he says.

