Do you have a question? Want to learn more about our products and solutions, the latest career opportunities, or our events? We're here to help. Get in touch with us.
Security leadership is shifting from protecting individual systems to managing trust, resilience and risk across increasingly connected AI-enabled environments.
Security teams must continuously adapt, strengthen AI literacy and govern both human and non-human identities without becoming a barrier to innovation.
Cybersecurity is becoming a shared organisational responsibility, requiring collaboration, education and risk-based governance to help businesses innovate confidently and safely.
As AI becomes embedded across business operations, security leaders are being asked to do more than protect systems – they must help organisations manage risk, build resilience, govern emerging technologies and enable innovation at the same time. Datacom CISO Collin Penman and Director Cybersecurity Consulting Adam Kirkpatrick examine how the role of security leadership is evolving in an AI-enabled world.
For years, cybersecurity leadership has largely been about protecting systems, reducing risk and responding to incidents. Those responsibilities haven't disappeared, but AI is forcing security leaders to rethink how they approach them.
The pace of technological change is accelerating. AI models are becoming embedded in business applications. Machine identities are multiplying. Threats are becoming more sophisticated and more automated. At the same time, organisations are under pressure to innovate faster than ever before.
During Datacom's recent executive briefing on the mythos of open AI models, Datacom Chief Information Security Officer, Collin Penman, and Director Cybersecurity Consulting, Adam Kirkpatrick, explored a question many organisations are now grappling with: what does effective security leadership look like in an AI-enabled world?
The conclusion was clear: the fundamentals of security remain important, but the role of security leaders is evolving rapidly.
One of the biggest shifts is how security teams think about their role. Historically, cybersecurity has focused on protecting infrastructure, applications and networks. AI introduces a more complex challenge. Organisations are now dealing with intelligent systems, autonomous agents, large volumes of data and rapidly changing dependencies.
As Penman explained, security leadership is becoming less about protecting individual systems and more about managing trust across increasingly connected environments.
"We've moved from protecting the systems to really managing the trust across to those AI systems," says Penman.
That requires leaders to think beyond technology controls alone. They must understand how systems interact, how decisions are made, what information is being accessed and whether governance frameworks are keeping pace with change.
Most organisations are accustomed to annual planning cycles. Cybersecurity programmes, budgets and investment priorities have traditionally been mapped out well in advance.
The challenge is that AI is disrupting that model. New capabilities emerge rapidly. Threats evolve quickly. Regulatory expectations continue to develop. Security leaders can no longer assume that priorities established at the beginning of the year will remain unchanged by the end of it.
"The biggest shift is around the fact planning has had to evolve from happening ahead of time and covering the next year to a continuous adaptation," says Penman.
Rather than treating cybersecurity as a fixed programme of work, organisations need the flexibility to reassess risk, reprioritise investments and respond to changing circumstances. Security leadership increasingly involves helping organisations become comfortable with continuous adjustment rather than rigid planning.
For decades, security strategies were built around the idea of a perimeter. Defend the network, secure the boundary and control access.
Penman says that world is disappearing as employees work from anywhere, data moves across platforms and AI systems connect to multiple services. Increasingly, decisions and actions are being taken by software agents rather than humans.
"The perimeter, like the castle wall, now has gone."
Instead, identity is becoming the critical focus. Security leaders must now understand not only who has access to systems, but also what has access.
In fact, Penman notes that Datacom now manages more non-human identities than human ones. Service accounts, APIs, automation tools and AI agents are already becoming a significant part of the technology landscape.
For security leaders, this creates a new challenge: governing a workforce that increasingly includes machines.
There is understandable focus on AI governance frameworks, risk assessments and controls. However, effective leadership also requires investment in capability.
Security teams cannot govern technologies they do not understand.
Penman describes how Datacom has been upskilling its own security function, from AI foundation training through to specialist knowledge in areas such as AI architecture and AI-related security risks.
"All of my internal team are undertaking AI courses."
This reflects a broader shift taking place across the industry. Security leaders are increasingly responsible for building organisational understanding of AI risks, opportunities and practical implementation challenges
The organisations that adapt most successfully are unlikely to be those that simply create more policies. They will be those that build the skills needed to evaluate and manage AI confidently.
One of the tensions facing many organisations is balancing innovation with risk management.
Business leaders want to move quickly. Teams want to experiment. New AI capabilities are appearing almost daily. Security functions must ensure appropriate controls are in place without unnecessarily slowing progress.
That balance is not always easy.
"I get called the AI handbrake internally because I ask the questions," says Penman.
But he points out that effective security leadership is not about saying “no”, instead it is about asking the right questions early enough to help organisations innovate safely.
This requires risk-based governance, clear approval pathways and practical guardrails that reflect the real level of risk involved. Security teams must challenge assumptions, but they must also enable progress.
Perhaps the most important leadership shift is recognising that cybersecurity can no longer sit solely within security teams.
AI is affecting every part of the organisation. Decisions about technology adoption, data sharing, procurement, governance and risk management increasingly involve business leaders, operational teams and boards.
Penman describes ongoing efforts to educate leadership teams and lines of business about the impact AI will have on their operations.
He also argues that collaboration across organisations and industries will become increasingly important.
"We need to be in a community where we can share information and help each other navigate the changes," says Penman.
The AI era is creating new challenges, but it is also broadening ownership of cybersecurity. Security leadership is no longer confined to technical controls and incident response. It now includes education, governance, resilience, collaboration and organisational change.
The technologies may be evolving quickly, but the most effective security leaders remain focused on a simple goal: helping organisations innovate with confidence while remaining resilient in an environment where both opportunity and risk are accelerating.
As AI increases the speed, scale and complexity of cyber threats, organisations need to look beyond the hype and focus on strong security fundamentals, adaptive risk management and resilience. Explore how Datacom’s cybersecurity solutions can help strengthen your security posture, protect critical systems and data and prepare your organisation to respond and recover as the threat landscape evolves.