Wolfgang Goerlich has spent his career in security and has been a CISO for the past seven years.Like many long-term security execs, Goerlich has seen plenty of changes within the profession. He’s bracing for more.“For the future I see growing the role of CISO to be the pacesetter for innovation, to be in the board room and executive conversations advising them on how to take smart, calculated risks with technology, including AI,” says Goerlich, who is now a public sector CISO and a faculty member with IANS Research.Goerlich sees this as the next step for a role that has continuously evolved since its inception in 1995.“It’s gone from the ‘department of no’ to ‘let’s slow down’ to ‘let’s take smarter risks based on our understanding of them,’” he adds. “How exciting is this? To be the one to say, ‘You want to take more risk? Let us help you. We can help you make smarter decisions.’”Goerlich isn’t the only one with such observations. Others similarly believe that the responsibilities assigned to the typical CISO will change in the upcoming years.Despite a broad consensus on change, predictions vary on how that change will play out in terms of the CISO’s roles and responsibilities. Mirroring the traditional three-year look for strategic planning at many organizations, security leaders see a range of possibilities for the CISO position evolving by 2029. Regardless, all agree that the CISOs of tomorrow will have to work at a faster pace, contend with more threats, and bear more strategic responsibility than they do today.Research confirms this outlook.“The CISO role is being redefined in real-time,” states a 2026 KPMG report on the evolving CISO role. “As digital platforms, artificial intelligence (AI), and third-party ecosystems accelerate the pace of change, security leaders are increasingly expected to enable response speed while assuming accountability for enterprise-level risk.”The report goes on to say, “The modern CISO operates at the crossroads of immense technological opportunity and unprecedented risk. This requires a fundamental evolution of the CISO role itself.”CISO as ‘strategic facilitator’KPMG offers ideas on what’s ahead, writing that the future CISO must evolve “from that of a pure technologist to one of a business leader and, critically, a storyteller who can translate complex threats into a business context.” They must become “a strategic facilitator of secure innovation, whose mission is to help the business move at speed in a trusted, safe manner.”Some CISOs already serve as that strategic facilitator for secure innovation, with researchers and current security chiefs saying they expect a greater percentage of CISO positions to take on that work in the coming years.Goerlich is experiencing that shift already, having been tasked with standing up an innovation team that includes architecture and engineering professionals as well as security practitioners.Moreover, his research at IANS has brought him into contact with other CISOs who are leading or co-leading innovation. CEOs and boards increasingly recognize that having security in those leadership roles accelerates — rather than slows — innovation because “security knows how to help them take risks,” he says.In fact, Goerlich believes more CISOs will have responsibility for enterprise risk in general, in addition to cyber risk, by 2029.That said, Goerlich doesn’t expect that to be a universal truth. The CISO role will vary from one organization to another in 2029, as it does today, he says, with some more focused on risk and others more tactical.Security leaders will “self-select into the right organization in ways that fit their temperament, their skills, and their resume,” he says.‘Enabler of business strategy’Diana Kelley, CISO at Noma Security, has a similar take on what’s ahead. “The biggest change that is happening is that CISOs are moving more from defender role and compliance to enabler of the business strategy.”She adds, “It’s becoming more about how to enable the business, how to understand strategically what the business is doing so I can make the business more resilient. It’s already happening. We’ve already seen some CISOs move to being a strategic trust officer and strategic risk partner.”On the other hand, Kelley also thinks that, thanks in large part to AI, CISOs will need to sharpen their technical chops for the job ahead of them. “I don’t mean CISOs need hands on the keyboard, but they do need to be able to interrogate technically and architecturally what the organization is doing with technology so they can say, ‘This is how we can govern and control this in runtime,’” she explains.In fact, Kelley suggests that in the future there may be two different types of security leaders in an organization — one focused on shoring up defenses and the other focused on risk and resilience.Expansion to risk and trustLongtime security exec Edna Conway also believes the CISO role will continue to morph.Conway, a former CSO who had CISOs reporting to her, thinks CISOs should expand their responsibilities beyond information security risk to include enterprise risk.As such, she thinks the title should be chief security and trust officer or chief security and risk officer. She knows something about that: She herself was chief security and risk officer for Azure Infrastructure at Microsoft from 2020 to 2023.However, Conway, now CEO of EMC Advisors and chief operating and risk officer for TPO Group, isn’t sure all that will happen by 2029.‘Dynamic environment’ driving CISO evolutionAli Waezzadah, CISO at iCOUNTER, sees today’s “dynamic environment” — from evolving IT infrastructure to geopolitics to the economy — as driving the next evolution of the position.More specifically, he sees changing (and increasing) work around managing teams, securing technology, supporting the business direction and strategy, and ensuring compliance with regulatory, security, and governance standards.The background and experience of security workers is changing, he contends. New technologies are being deployed increasingly faster. Adversaries constantly develop new techniques. The regulatory environment is in flux. And the business itself continues to experiment and revise strategies at shorter intervals. “Those are the things that will force the CISO to adapt,” he adds.All that is regularly reshaping both the day-to-day actions of the CISO and the remit that falls under the title. That, in turn, is forcing security leaders to be more agile than ever before, Waezzadah says.“By 2029 they’ll have more things they’ll have to pay attention to,” he predicts. “How and what CISOs have to protect is rapidly changing, and they have to be much more prepared for a dynamic landscape. They need to be more nimble and flexible.”‘Strategic architect of business outcomes’Of course, change is not new to CISOs as they’ve seen their mandate expand over the past decades, says John White, field CISO for security tech company Torq.The upcoming years will require CISOs to build and manage an operation that can move at lightning speed, a consequence of AI’s use by the organization and its adversaries, White says. To do that, CISOs must build and manage a new type of security department, one where agents execute and human workers define and oversee outcomes.“The traditional security model we’re used to is no longer going to be sufficient for what’s upon us, and the CISO role will evolve to be a more agile, product-oriented role and to be someone who can pull holistic teams together quickly to engineer responses,” he says, adding that CISOs will need strong risk skills and business acumen to do all that.In an online post, he writes “The CISO of the near future is less a chief technologist and more a strategic architect of business outcomes, designing human-machine teams that reimagine the target operating model in response to both risk and opportunity.”CISO as orchestratorAndrew Obadiaru, CISO at Cobalt, a security services company, also believes “by 2029 the CISO will be even more of a business leader than a technical leader.”“Security will increasingly be measured by how quickly organizations can identify, validate, and reduce risk,” he says. “The CISO will be responsible for enabling the business to adopt AI safely, managing software supply chain risk, and ensuring the organization can continuously validate its security posture in an environment where attackers are operating at machine speed.”As a result, Obadiaru sees the CISO role becoming “less about owning security technology and more about orchestrating security across engineering, IT, product, legal, procurement, and the executive team.”He expects three main priorities to dominate the role in the future: continuously validating organizational exposure rather than relying on assessments; ensuring AI is adopted securely across the enterprise; and accelerating remediation.CISOs will have to act faster, too. “As a result, CISOs will spend less time reviewing individual technical findings and more time building automated decision-making processes, resilient engineering practices, and governance models that allow organizations to respond safely at machine speed,” Obadiaru says.And they’ll have to change their operating model. “Security has always been about managing uncertainty. What’s changing is the speed at which uncertainty develops,” he says. “AI is accelerating vulnerability discovery, software development, and attacker innovation simultaneously. That means the CISO must evolve from managing security programs to managing adaptive security systems.”However, he believes the fundamental mission will stay the same.“The CISO’s responsibility is still to protect the organization’s ability to operate by understanding risk, communicating it effectively, and helping the business make informed decisions,” he adds. “Technology evolves, but leadership, trust, sound judgment, and clear communication remain constant requirements.”