CIOs and CISOs Must Evolve Risk Management to Address AI-Powered Threats and Governance Requirements
As an experienced board director and governance expert with over 25 years of experience in deep tech and information security, I understand the critical importance of strong leadership in managing cybersecurity risks in the new digital landscape. The emergence of artificial intelligence as both a cybersecurity tool and threat vector has fundamentally transformed how organisations must approach risk management. It is imperative that senior executives and the board work together to manage the organisation’s risk exposure, including the new challenges presented by AI-powered threats and AI system vulnerabilities. The board must take ownership of this responsibility and, in plain English, must be able to explain the organisation’s cybersecurity risk [1], AI governance framework, and the comprehensive measures taken to address both traditional cyber and AI-enhanced threats.
AI has Changed the Threat Landscape
Australian Signals Directorate responded to over 1,100 cybersecurity incidents in 2023-2024, highlighting continued exploitation of Australian systems [2]. Recent high-profile cyber incidents across health, government, finance and education sectors in Australia demonstrate the continuing need for strong incident response capabilities. However, organisations must now also prepare for AI-enhanced attacks that may be more sophisticated, persistent, and difficult to detect than traditional threats.
The cybersecurity landscape in 2025 has been fundamentally reshaped by AI. Ransomware, social engineering and AI-powered cybercrime remain top concerns, with artificial intelligence supercharging familiar threats such as phishing, insider threats and ransomware. Organisations now face a dual challenge: protecting against AI-enhanced attacks while securing their own AI systems and data.
AI-enhanced threats take many forms, from phishing emails generated with error-free grammar and personal details to highly adaptive malware that can learn and evade detection systems. Cybercriminals are increasingly deploying deepfakes for identity fraud, resulting in fraudulent transactions or sharing of sensitive information.
The sophistication of these attacks requires boards to understand not just traditional cyber risks, but also the unique vulnerabilities introduced by AI systems, including data poisoning, model manipulation, and adversarial attacks designed to compromise AI-driven security systems.
Mitigation Strategies: Beyond the Essential Eight
While the ACSC’s Essential Eight mitigation strategies remain the foundation of cybersecurity defence in Australia [3], organisations must now expand their approach to address AI-specific risks through additional AI-focussed controls that complement the existing framework. Organisations should implement comprehensive AI-specific security measures including AI model security to protect machine learning models from adversarial attacks and ensure model integrity, robust data governance for AI training and operational datasets, AI supply chain security through assessment and monitoring of third-party AI services and components, algorithmic transparency to maintain visibility into AI decision-making processes for security-critical applications, and AI asset inventory to catalogue all AI systems including their purposes, data sources, and risk profiles. These enhanced controls ensure that whilst the Essential Eight continues to make it much harder for adversaries to compromise systems, organisations are equally prepared for the sophisticated AI-enhanced threats that characterise the modern cybersecurity landscape.
Enhanced Reporting Framework for the AI Era
Technology and AI governance remains a top concern for corporate directors and executives in 2025 relative to safeguarding data, managing new technologies and ensuring the necessary skills in the boardroom. While the ACSC Essential Eight remains the gold standard for traditional cybersecurity reporting in Australia, board reports must now incorporate AI-specific risk assessments and governance measures. An effective cybersecurity report for 2025 should include all traditional elements while adding critical AI-focused components.
The report should begin with an executive summary that provides an overview of the current cybersecurity posture including AI system security, identified risks and threats (both traditional and AI-enhanced), and the likelihood and potential impact of these risks. This must include an assessment of how AI is being used defensively and the risks associated with AI systems deployed within the organisation.
Traditional cybersecurity KPIs should be supplemented with AI-specific metrics that provide comprehensive visibility into artificial intelligence security posture. These include AI system uptime and integrity monitoring, detection rates for AI-enhanced threats, and AI model performance and drift monitoring to ensure systems remain secure and effective. Additional metrics should cover AI governance compliance and time to detect and respond to AI-specific incidents, enabling boards to understand both defensive capabilities and incident response effectiveness.
Reports should assess the organisation’s capability to manage AI security risks, including specialised skills in AI security, data science, and algorithmic auditing. As new guidance and compliance burdens emerge, alongside new commercial opportunities associated with good governance, a mature AI governance program will look different in 2025 or 2026 than it did in 2023 or 2024. Organisations must stay abreast of evolving AI regulations while maintaining compliance with established cybersecurity standards such as ISO 27001 [4] and NIST CSF [5]. The CEO should also report regularly on the organisation’s AI data holdings.
Board Expectations and AI Literacy
Board directors must develop AI literacy to effectively oversee cybersecurity in the AI era. The board must set clear expectations around AI governance information it receives from management, including the format, frequency, and level of detail around AI security risks. Executives and boards must prepare for a new era of crisis management as AI-enhanced cyber incidents occur that may be more sophisticated and potentially more damaging than traditional cyber-attacks.
Outlook
Cybersecurity governance in 2025 is fundamentally different from previous years due to the pervasive influence of artificial intelligence. Organisational success will increasingly belong to those enterprises that perceive governance not as a barrier but as a catalyst for growth, transforming regulatory challenges into opportunities.
Cybersecurity remains everyone’s responsibility, but this responsibility now extends to understanding and managing AI-related risks. Boards, CEOs, CIOs, and CISOs must work together to ensure that the organisation is prepared to handle both traditional cyber threats and the new generation of AI-enhanced attacks while responsibly deploying AI for defensive purposes.
80% of leaders say AI is making data security more challenging, highlighting the critical need for enhanced governance frameworks [6]. With the increasing frequency and sophistication of AI-powered cyber-attacks, it’s more important than ever to have a clear understanding of the organisation’s cybersecurity posture in the context of AI adoption and to be informed of any significant risks or incidents involving AI systems.
The integration of AI considerations into cybersecurity governance is essential for organisational resilience and competitive advantage in 2025 and beyond. Through following enhanced best practices and creating comprehensive cybersecurity reports to the board that address AI considerations, organisations can mitigate emerging risks while capitalising on AI’s defensive capabilities to protect their assets and data. This demonstrates a commitment to modern cybersecurity governance and helps build trust and confidence between the board and the organisation in our AI-driven future.
About: Gary Morgan is an experienced board director, CEO, consultant, and corporate advisor with extensive knowledge in strategy, innovation, and growth across various sectors including health tech, aged care, agtech, information security, and research. His focus is on driving business growth through transformational change, with particular emphasis on leveraging emerging deep technologies while maintaining robust governance postures. He serves as a Fellow of the Governance Institute of Australia and on the Griffith University Industry Advisory Board for the ICT School. Gary has co-authored papers and reports published in top entrepreneurship and medical journals.
Acknowledgment: This article updates the original April 2023 publication “Enhancing Cybersecurity Governance: Creating Comprehensive Reports for Board Directors” and incorporates AI-assisted research and drafting.
References
- Australian Cyber Security Centre (2022). Questions Boards Ask About Cyber Security.
- Australian Cyber Security Centre (2024). Annual Cyber Threat Report 2023-2024.
- Australian Cyber Security Centre (2023). Essential Eight.
- International Organisation for Standardisation (2022). ISO/IEC 27001
- National Institute of Standards and Technology (2025). Cybersecurity Framework.
- Immuta (2025). The AI Security & Governance Report.
