What’s Keeping Security Leaders Up at Night?
- Read time: 3 mins.
In this recap...
- Why AI might be the most overhyped threat in the room
- The risk hiding in plain sight: data oversharing and third-party access
- The one metric that actually gets executives to say yes
- What's really costing security leaders sleep, and it's not always a hacker
A Threat Everyone’s Talking About (Maybe Too Much)
Ask a room full of security leaders what they get asked about the most, and AI comes up almost by reflex. The panel didn’t dispute the risk, but there was some push back on the noise around it. Corey joked about seeing an ad promising AI would change everything for the better, set to a song about the world ending in five years.
Being impressed by AI and trusting it are two different things. The industry spends far more energy on the first.
A second contender for most overblown threat: the idea that a major SaaS provider could vanish overnight and take a chunk of the internet with it. The panel treated it as a fun thought experiment, not a planning priority.
A Risk Getting Overlooked
Flip the question around, and the answers were more specific. Data oversharing topped the list. Years of loose permissions on shared drives and systems don’t cause problems on their own. Feed that same data into an AI tool, and every excessive permission becomes a much bigger exposure. Most organizations haven’t cleaned house before turning AI loose inside.
Third-party risk was the other answer. Everyone already knows it’s a problem. What’s missing is a shared way to address it. Vendor risk gets discussed constantly and managed inconsistently, which is arguably worse than ignoring it altogether.
What Gets a Budget Approved
Every security leader has pitched a tool or a project that went nowhere. The panel’s advice for breaking through: stop leading with the technology and start leading with the income statement.
One panelist recalled an early-career lesson: boil every ask down to one question. Does this help the business sell more of whatever it sells? That question works in almost any industry.
The follow-up metric security leaders should always have ready: downtime has a dollar figure. Once a leader has lived through one drawn-out recovery, that number becomes the fastest way to get resilience investments approved. Executives respond to money.
What’s Keeping Them Awake at Night
One panelist wants AI development to swing toward defenders instead of fueling more sophisticated attacks. Vendors should build defensive capability into the products organizations already own, not charge extra for it.
Another panelist’s answer had nothing to do with hackers. A string of weather-related outages caused real downtime with no cyber component at all. There’s no tidy fix for a problem that starts with weather instead of a threat actor.
The last answer was probably the most universal one in the room: volume. Attacks are arriving more often and in more novel forms, and security teams aren’t growing at the same pace. The path forward isn’t hiring at scale. It’s automating enough of the response process to keep up.
What to take from this…
- AI fatigue is real. Don’t confuse noise with actual risk.
- Clean up permissions before you scale AI on top of them.
- Translate every security ask into a business outcome.
- Downtime has a dollar figure. Know yours before you need it.
- Automation is monumental when attack volume outpaces headcount.
Want help turning these takeaways into a plan? Connect with HBS to talk through where your organization stands today.
Related Content
Data Classification: What It Is and Why It Matters
Data classification helps protect your organization’s sensitive information, ensure compliance, and streamline data management.
How to Test Your Cybersecurity Incident Response Plan
Here’s how to choose the right test in order to confirm that your cybersecurity incident response plan actually works like you think it will.
Day in the Life of Shadow AI: The Performance Review That Left the Building
A fictionalized case study on shadow AI: one free AI account, 14 months of exposed data, and the breach that followed. See what governance could have prevented.