The CIO’s New Mandate: Rearchitecting Enterprise Work

The article argues that CIOs must lead a shift from simply managing enterprise applications to redesigning enterprise work itself, leveraging AI agents to orchestrate work outcomes rather than just automating tasks within discrete systems. This new discipline, called Enterprise Work Architecture (EWA), involves mapping business outcomes to work activities, defining authority and execution across humans and AI, and measuring economic impact, enabling more efficient, secure, and transparent operations across integrated applications. The transformation requires CIOs to collaborate across business functions to reimagine how work flows through technology and human judgment, focusing on outcomes rather than individual applications.

https://www.cio.com/article/4230816/the-cios-new-mandate-rearchitecting-enterprise-work.html

Should the CISO Role Be Split in Two?

As the CISO role expands from technical security oversight to encompass business risk management, governance, and strategic leadership, industry experts debate whether it should be split into separate business-focused and technical-focused positions. While some organizations have introduced deputy CISOs to manage operational tasks, the consensus among professionals like Todd Fitzgerald and Tim Brown is that a single CISO with clearly defined responsibilities is preferable, supported by appropriate teams to handle technical and governance functions. The evolving role increasingly requires CISOs to act as business leaders responsible for cyber risk at the enterprise level, raising the importance of executive authority, board engagement, and personal liability considerations.

https://www.csoonline.com/article/4230243/should-the-ciso-role-be-split-in-two.html

6 Guidelines for Governing AI

Sravan Vadigepalli, leading enterprise AI strategy at Lowe’s, outlines six guidelines for governing AI systems that emphasize keeping humans involved in decision-making through principles rather than rigid rules. He stresses the need to encode corporate values as machine-readable governance layers, implement confidence-based human oversight (“trust thermostat”), and ensure context integration for AI reasoning, enabling organizations to shift from directly executing tasks to overseeing AI-driven processes with human judgment focused on exceptions. This governance approach aims to bridge the gap between AI experimentation and scalable business value by redefining roles around setting intent, managing risk, and embedding culture in AI operations.

https://spectrum.ieee.org/6-guidelines-governing-ai

Why CISOs Struggle to Answer the Board’s Three Hardest Questions, and How to Fix the Report

CISOs often struggle to confidently answer boards’ key questions on security posture, financial exposure, and improvement because relevant data is siloed across multiple tools that lack shared context. A proposed solution involves adopting a unified intelligence layer that correlates identity, cloud, endpoint, and SaaS data into attack paths to critical assets, enabling reports focused on exposure and financial risk trends instead of activity metrics. This approach helps security leaders provide measurable risk reduction insights aligned with business priorities and facilitates more effective board communication and remediation prioritization.

https://thehackernews.com/2026/10/why-cisos-struggle-to-answer-boards.html

Who Should Own AI? I Started with an Incomplete Answer

AI transformation requires shared ownership across technology, security, legal, finance, and business leaders, as no single function can fully own the work. While a chief AI officer or similar executive should be accountable for strategy, governance, and organizational change, effective AI adoption depends on cross-functional collaboration to redesign workflows, manage risk, and integrate AI sustainably into operations.

https://www.cio.com/article/4229636/who-should-own-ai-i-started-with-an-incomplete-answer.html

How to Set up SPF, DKIM, and DMARC for Your Sending Domain

The article provides a detailed, step-by-step guide to setting up SPF, DKIM, and DMARC records for authenticating a sending domain to improve email deliverability and reduce spam. It explains how SPF authorizes sending servers, DKIM adds cryptographic signatures for message integrity, and DMARC enforces alignment with the visible From address and specifies policies for handling unauthenticated mail. The guide emphasizes correctly publishing DNS records, verifying them, and monitoring DMARC reports before enforcing strict policies, with practical advice on common pitfalls and validation methods.

https://mailfully.com/blog/spf-dkim-dmarc-setup

AI Won’t Replace CIOs. It Will Expose the Ones Who Can’t Lead People

AI is automating much of the technical work previously handled by CIOs, exposing deficiencies in people leadership rather than replacing these executives. Senior IT leaders face increased expectations to manage complex interpersonal challenges—such as difficult conversations and resource negotiations—that AI cannot resolve, highlighting the need for stronger emotional intelligence and communication skills in technology leadership roles. Those CIOs who develop and embrace these people-focused capabilities will be better positioned to succeed in the AI-augmented workplace.

https://www.cio.com/article/4229000/ai-wont-replace-cios-it-will-expose-the-ones-who-cant-lead-people.html

Top Soft Skills for CIOs, and How to Get Them

Modern CIOs must develop key soft skills—such as storytelling, stakeholder management, emotional intelligence, negotiation, change leadership, conflict navigation, and adaptability—to effectively lead beyond technical expertise. These skills enable CIOs to communicate complex ideas, align diverse organizational priorities, manage resistance to change, and drive adoption of technology initiatives, with practical experience and deliberate practice being essential for mastery.

https://www.techtarget.com/it-strategy/tip/Top-soft-skills-for-CIOs-and-how-to-get-them

If AI Makes the Decision, Who Owns the Consequence?

As AI increasingly shapes operational decisions rather than merely assisting tasks, organizations face a governance challenge in clearly defining who holds authority and accountability for AI-driven outcomes. Boards should focus on identifying material AI-supported decisions, mapping who can authorize, oversee, and accept consequences for these decisions, and demanding evidence that authority boundaries are respected and exceptions managed. Effective AI governance requires moving beyond inventories toward accountability frameworks that trace decision authority and ensure humans remain responsible for consequences.

https://www.cio.com/article/4226780/if-ai-makes-the-decision-who-owns-the-consequence.html

September AMA: I’m a CISO Who’s Built Many Security Teams. I Want to Help You Level up Your Career. Ask Me Anything.

CISO Series hosts a September AMA featuring experienced cybersecurity leaders who have built and led multiple security teams, offering advice on career growth, leadership, hiring, and team management within the security field. The panel includes CISOs and security directors from diverse organizations and covers topics such as AI security, cloud security, risk management, and security culture. Participants engage with the community over a week-long event on Reddit to answer questions and share insights relevant to advancing careers in cybersecurity.

https://cisoseries.com/september-ama-im-a-ciso-whos-built-many-security-teams-i-want-to-help-you-level-up-your-career-ask-me-anything/

Scroll to Top