Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Google DeepMind Releases EmbeddingGemma 2, a 740M Open Multimodal Embedding Model Built on Gemma 4

    October 6, 2026

    Pacing the AI frontier won’t solve agentic cybersecurity’s most urgent problems

    October 6, 2026

    UK Digital Bond Pilot Moves Closer to 2027 Issuance

    October 6, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Google DeepMind Releases EmbeddingGemma 2, a 740M Open Multimodal Embedding Model Built on Gemma 4
    • Pacing the AI frontier won’t solve agentic cybersecurity’s most urgent problems
    • UK Digital Bond Pilot Moves Closer to 2027 Issuance
    • NASA to Cover Northrop Grumman CRS-24 Spacecraft Departure
    • Water Bills Surged More Than Other Costs in US Homes Over 10 Years, a ‘Striking’ New Report Shows
    • Investigate Midwest names Mc Nelly Torres editor-in-chief
    • The Guardian view on the Green party and Palestine: rejecting two states is no shortcut to peace | Editorial
    • Catalan separatist Puigdemont to return to Spain after warrant lifted | Elections News
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, October 6
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    IANS’ Kakolowski: How AI Is Reshaping CISO Budgets

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 6, 2026 Cybersecurity No Comments16 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    AI is changing cybersecurity teams — but not necessarily by replacing the people who work on them. New research from IANS finds that CISOs are largely looking to AI to help their existing teams do more, while rethinking how work gets divided between junior and senior security professionals. The research suggests most CISOs aren’t planning to shrink their teams because of AI; instead, they’re looking to automate routine tasks, reskill employees, and give experienced security professionals more time to focus on complex problems.

    As organizations race to adopt AI, security leaders are also facing new questions about budgets, staffing, and the skills their teams will need in the years ahead. AI is becoming an increasingly important factor in how CISOs make the case for security spending. As businesses prioritize AI initiatives, security leaders are finding opportunities to use that momentum to secure funding for new tools, staffing, and other areas of their programs. At the same time, rising costs from vendors adding AI capabilities to their products are putting added pressure on already tight security budgets. Dark Reading associate editor Kristina Beek spoke with Nick Kakolowski, senior director for CISO research at IANS, about how AI is reshaping security organizations and what CISOs are doing to keep pace.

    Related:RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail

    For all of our Dark Reading news videos, please check out our YouTube channel, and our curated video articles.

    Kristina Beek & Nick Kakolowski: Full Transcript

    This transcript has been edited for clarity and length by Informa TechTarget’s internal AI assistant. For the full experience, please watch the video.

    Dark Reading’s Kristina Beek: Hi everyone, my name is Kristina Beek, and I’m an editor at Dark Reading. Today we are here to talk about some research that you were a part of, Nick. I would love it if you could introduce yourself, and then we’ll get started on some of this research.

    Nick Kakolowski: Thanks so much for having me, Kristina. It’s great to be here. I’m Nick Kakolowski, senior director for CISO research at IANS. Artico Search and IANS work together on a CISO compensation and budget survey every year. And we’ve recently done a lot of research around how AI is shaping teams, and also in general, work around AI maturity and capabilities across the infosec sector.

    DR’s Kristina Beek: Awesome. What can you tell us about some of the findings this year that were really notable or stood out to you?

    Nick Kakolowski: We have found that the industry is still very all over the place in terms of use of AI, maturity around AI. But what is fairly unified is that business executives are moving way more aggressively than they have, compared to any other technology that we have seen over the years. And the result has been the CISO community moving fast to get past this idea that this is dangerous, we need to pump the brakes, and get into this mindset of the business is going here, we have to figure out how to secure it as we go. And as a result, we are seeing early signs of fairly significant changes in terms of how orgs are thinking about staffing, how they’re thinking about organizing teams, how they’re thinking about what maturity really looks like.

    Related:Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response

    DR’s Kristina Beek: What would you say has changed in the past couple of years to make AI such a dominant budget priority? I’m sure people have slightly different opinions on pinpointing what it is.

    Nick Kakolowski: The macro story has been told a lot around how much the technology has the potential to be transformative, how much it has the potential to drive efficiencies in the workplace. When I think about practically what is happening when we talk to our CISO community, they are often able to explore solving problems that they otherwise simply wouldn’t have bandwidth for.

    Related:SWIFT Banking & Government Middleware Enables RCE

    Whether it’s processing all of those alerts that they never would have gotten to and figuring out how to prioritize them, whether it’s gathering all of the third-party questionnaires and analyzing them for trends and action items that they can take, whether it’s trying to get past questionnaires and into actually interviewing their peer CISOs and figuring out what the risk looks like, there’s this huge swath of data that security teams have been gathering and documenting and logging across a whole variety of disciplines.

    They haven’t been able to tap into that simply because of a lack of resourcing and a lack of human time to gather and analyze that data. And as AI enables them to make sense of that information and make it more digestible, there’s this byproduct where teams are now even more aware of some of the problems they have, even more aware of some of the risks that the organization is taking.

    And they now need to figure out, well, how do we find time to plug all of these holes? How do we find time to fill the gaps in our program and reorganize and resource so that we can figure out how to prioritize, because we can get to data and information that we weren’t able to really get to in the past.

    DR’s Kristina Beek: Right. So when I was reading parts of the report, my understanding is that CISOs want to spend more money on AI. What is it that they are actually spending money on? Are we talking about AI-powered security tools? Securing systems with AI? Did you receive feedback from that in regard to speaking to your CISOs?

    Nick Kakolowski: It’s hard to speak to all of that in detail based on our benchmarking data because we don’t go super, super granular, but we do talk a lot with our community about that. And so we can speak anecdotally around how folks are thinking about that problem set. The single biggest thing is simply that every vendor out there is adding AI capabilities into their tools and raising prices. And we are seeing significant price increases across the marketplace.

    And in many cases, increases in budget are going almost entirely to keeping up with the price changes in the vendor stack. But we are also seeing an emergence of small, fast-growing vendors who are doing interesting things to solve problems with AI. And in many cases, CISOs are communicating dissatisfaction with the mainstream vendors and their AI capabilities.

    They’re starting to watch the smaller startup space because they’re seeing more viable solutions there, to see which of those get bought by the larger players, which of those are stable, which of those are actually potentially reliable enough to bring into their stack. But as a result of all this uncertainty in the vendor marketplace, we are seeing a growing appetite to build solutions in-house, especially with capabilities for vibe coding and increased scrutiny on the SDLC [software development life cycle] on the security side.

    There is an appetite for saying we have problem X in our infosec program. We need to deal with that problem. There isn’t a vendor solution that neatly solves it. Let’s just go and build it. And that is taking up operational cycles and potential budget in terms of tokens. And then there is the whole “we need to secure AI.” And in many cases, the business doesn’t have a huge appetite for spending on identity, or spending on the SOC [security operations center], or spending on vulnerability management, but the business does have an appetite for spending on AI.

    And we are seeing savvy CISOs use the AI narrative as a way to funnel resources into areas where they might have operational or tech debt in the security program, to be able to catch up in terms of maturity and sophistication, and solve problems that the team has been dealing with for a long time.

    DR’s Kristina Beek: OK. Are you seeing organizations rethink hiring because they think that AI will change how existing security teams handle their work and more work moving forward?

    Nick Kakolowski: This is complicated because it’s moving very fast. What the market is telling us right now is the majority of CISOs do not yet materially think that they are going to shrink their teams as a result of AI. The general theme in the marketplace is that we are going to be able to do more while keeping our teams the same. But to get there, most of them do believe that they are going to need to reskill their teams and reorganize their teams.

    In most cases, what that looks like is automating tier-one SOC tasks, automating some tier-two SOC fast tasks, moving fast to upskill kind of entry-level and more inexperienced employees so they can start making more thoughtful decisions and be a little bit more strategic. And then freeing time for the more senior employees to take on a wider range of tasks and essentially create this AI-enabled pipeline where a lot of the data gathering, data analysis kinds of tests that people might be doing in their first few years of their career on the team are getting automated. The folks who are more experienced and able to make more nuanced decisions are focusing their time on those choices at a larger scale.

    DR’s Kristina Beek: So what I’m understanding is that we’re training existing security staff in this new era. But I do imagine that there’s almost a trickle-down effect of, OK, if this is affecting CISOs, then it’s affecting security leaders, then it’s affecting entry-level professionals who are in security. Then it ultimately, I assume, is impacting students in cybersecurity programs or what have you. How is it changing education to prepare these people for coming into the industry now, when AI is so dominant?

    Nick Kakolowski: It’s a challenging time to make those kinds of projections simply because everything is changing so fast. Right now, the rhetoric that we are hearing most in the marketplace is the market needs people who are skilled at using AI to problem-solve. And being able to do that is going to be a key step forward. Whether that is getting good at testing code that is generated by AI, making sure it’s clean, making sure it’s free of vulns, whether that is being a creative problem-solver, the market will tell over time.

    When we asked our CISO community at the end of 2025 the question of, if you start automating all of your entry-level tasks, where are you going to get your senior leaders in five years? They told us, we’ll talk in five years about that problem, and we’ll deal with it then. Now we have CISOs at our events who are openly questioning how to figure out what our future talent pool looks like when we’re outsourcing so much. So it’s happening that fast that the market is really transforming. And it’s a time where it’s very important to build flexible skills, to come into situations with curiosity and look for ways to solve business problems.

    DR’s Kristina Beek: Because we’re moving so fast, is there even a way to predict what security will look like a year from now, two years from now? Do you have any predictions that you could share? Or is it just all up in the air?

    Nick Kakolowski: The funny part is that while everything’s moving fast, what’s old is new again is a persistent theme in security. It’s not as if people aren’t still finding that phishing and social engineering are the easiest way to get into a network. They’re still the easiest way to get into a network. It’s just AI-enabled phishing and AI-enabled social engineering. It’s still a problem of organizations having really messy permissions and user roles and secrets management, and they haven’t really put the time and effort into data classification so that they can adequately control who has access to what data.

    AI is taking the same problems we have largely always had and amplifying them. And so in many cases, what we expect security to look like in two years is what it’s always looked like, just bigger and more and faster. We have to do the same identity stuff that we’ve been doing. We just have to do it at a greater scale, at a greater speed, with more flexibility. We have to do the same on user education and the same for network monitoring and the same on vuln prioritization work.

    The big thing that we see starting to change, and this is really interesting in terms of executive mindsets, is if you went to a typical board or business executive team as a security leader a year ago and said, we are going to have to purposely break something, or we’re going to have to take an action that we know might break something on the business side in order to do a patch, they would say, no, wait, choose the optimal time to do that, minimize disruption, test the patch to death until you know it’s going to work.

    Now, businesses are becoming sufficiently aware of the scale of the risk created by AI-enabled threat actors by AI finding vulnerabilities at scale, that they are willing to say, we understand that the risk of breaking something by choice, by taking a known action, is smaller than the risk of letting that patch sit unsettled, untaken for a month. And they are more willing to say, yes, CISO, go automatically put all those patches in, and if something breaks, we’ll roll it back.

    And so now CISOs are having to make this really interesting strategic decision as to what level of automation risk are we willing to accept and what level of automation risk is something that we need to elevate and talk to the business about before we pull the trigger on it.

    DR’s Kristina Beek: Is there — and I feel like you’ve sort of almost already answered this — but do you feel as though from CISO responses that they are seeing measurable returns from their investments in AI, or is it too early to tell?

    Nick Kakolowski: We are seeing the industry hit a transition point on this. Three months ago, most of the rhetoric we were hearing was, we’re very afraid that if we don’t invest heavily in AI, we’re going to fall behind and we’re not gonna be able to claw back that market share and those capabilities. We just need to keep going in and trying AI everywhere.

    We are now — we started within the past few weeks, months, a couple months, maybe even about a month ago — hearing more and more boards are starting to ask, are we getting efficiency gains? Are we seeing real returns on our AI investments? How are we measuring it? If we’re gonna spend X amount on AI, we need to save Y amount in the budget.

    We even had a couple of CISOs at a recent event talk about the board stepping back and asking, are we taking too much risk here? If AI is starting to escape its guardrails and starting to, unprompted, hack competitors or hack other organizations, do we need to pump the brakes on how fast we’re moving? So we are starting to enter this period where the industry is transitioning from put all the chips in the AI bucket and see what we can do into is this actually working? But we’re at the very early stages of that transition.

    DR’s Kristina Beek: Would AI spending help CISOs make the case for larger overall security budgets, or do you think in the future organizations will just reallocate existing security dollars towards AI?

    Nick Kakolowski: I would say historically, we’ve thought about security budgets as something that often gets defined by the threat environment. The boards become more aware that they might get hit by a breach. They’re afraid. So now we can get some budget. Or the industry has lots of headlines right now around data breaches. We can get more budget. And it’s been the risk environment has changed. Folks are more aware of the risk. We can get spending.

    As security has matured, what we are seeing in our data is security budgets becoming a strong reflection of the business budget. So now it’s you’re just a part of how the business is operating. If the business has more revenue and the business is growing and now your threat exposure is growing as a result, you get more budget. If the business is shrinking, it doesn’t really matter if your threat exposure is growing. The business is shrinking, you’re not going to get more money.

    So instead of these swings in security budget growth, we’re actually really seeing it be much more tied to the macro environment and to the specific business revenue environment. And CISOs are getting much more sophisticated about building the cross-functional relationships they need to build to get ahead of understanding where the organization is going in order to adequately ask for what they need and get it.

    But because of that, as the orgs are getting so aggressive about AI, we are seeing AI as one of the primary arguments that folks can make to justify budget. It might be very hard to get new staff to keep turning the wheels in part of your SOC. It might be easier to get staff to manage and maintain AI enablement within your team. And so what we are seeing is more and more CISOs managing the optics and positioning within the organization to get resourcing via AI initiatives.

    DR’s Kristina Beek: Are there any lasting takeaways that you want readers, viewers, to glean from this conversation?

    Nick Kakolowski: This is another tick in a positive direction for cybersecurity and infosec as a whole that is pushing the business to be more aware of how embedded cyber risk is to broader business risk. AI is creating greater awareness that what we are doing as businesses from a technological perspective is changing the data-related risk, changing the privacy risk, changing the regulatory risk, and getting the CISO more involved with the choices that the business is making and how the business goes about executing those choices can help create an opportunity for innovation.

    As a result, we are seeing more and more CISOs thinking about themselves from the perspective of, “how do I become an innovation enabler with the business? How do I build security into our capabilities so that the company can move fast on new capabilities rather than being looked at as the person who is either not necessarily saying no, but slowing things down?”

    DR’s Kristina Beek: Yeah. Well, thank you so much for taking the time to speak with me. This was so interesting.

    Nick Kakolowski: Thanks for having me, Kristina.

    budgets CISO IANS Kakolowski Reshaping
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Pacing the AI frontier won’t solve agentic cybersecurity’s most urgent problems

    FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware

    FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

    Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers

    FBI Blames Contractor’s Missed Patch for ShinyHunters Breach

    How to secure RMM software: 8 controls MSPs should test

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Google DeepMind Releases EmbeddingGemma 2, a 740M Open Multimodal Embedding Model Built on Gemma 4

    October 6, 2026

    Pacing the AI frontier won’t solve agentic cybersecurity’s most urgent problems

    October 6, 2026

    UK Digital Bond Pilot Moves Closer to 2027 Issuance

    October 6, 2026

    NASA to Cover Northrop Grumman CRS-24 Spacecraft Departure

    October 6, 2026
    Latest Posts

    4 Best Compression Boots: Therabody, Hyperice, and More (2026)

    August 9, 2026

    Former Iraqi provincial governor arrested as graft crackdown continues | Corruption News

    August 9, 2026

    The culture surrounding ‘ideal’ childbirth has to evolve | Childbirth

    August 9, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Google DeepMind Releases EmbeddingGemma 2, a 740M Open Multimodal Embedding Model Built on Gemma 4

    October 6, 2026

    Pacing the AI frontier won’t solve agentic cybersecurity’s most urgent problems

    October 6, 2026

    UK Digital Bond Pilot Moves Closer to 2027 Issuance

    October 6, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.