Among 113 CISOs surveyed, 41% expressed confidence in their organization's capacity to handle AI security threats over the next two years, compared to 38% who felt pessimistic, according to an IANS survey conducted in April and May. The research identifies six organizational factors that distinguish optimistic security leaders from those who are apprehensive about what lies ahead. The elements that separate confident CISOs from anxious ones have less to do with existing security controls and more to do with the CISO's influence and position within their company.
The six factors IANS identified as correlating with CISO optimism include leadership's grasp of AI risks, well-defined AI governance ownership, the security team's skill with AI tools, CISO control over the AI security budget, manageable workloads for security staff, and adequate security staffing levels. The report notes that perceptions of current risk link most strongly to AI security maturity—an organization's operational ability and security controls for managing its AI environment—while optimism about the future ties more strongly to organizational readiness factors. Current AI security maturity or budget increases matter less to CISO confidence than whether organizational leadership listens to them, empowers them, and provides sufficient resources.
The report states that "the findings reveal a distinction between present-day risk perceptions and optimism about the manageability of AI risk in the future." Security analysts quoted in the report caution that optimism may not reflect actual security. One analyst observes that a CISO with an informed board, clear governance ownership, budget control, and full staffing will feel optimistic regardless of whether production agents have proper authorization boundaries, calling it "a useful map of how CISOs currently think" but "not a security roadmap." Another warns that many security leaders can't explain how AI agents work, noting that when you can't describe the mechanism, you can't accurately assess the exposure.
Industry experts highlighted in the report emphasize that organizational readiness differs from actual security posture. They point out that having leadership understanding, budget control, and capacity to act doesn't guarantee the AI estate is under control. Several consultants stress that governance proves useless if organizations don't know which models vendors are introducing into their environment and the risks those models carry. Others note that CISOs need detailed intelligence about AI system data and application interactions, including what identity an agent operates under, which systems it can access, what information it can retrieve, and whether the organization can immediately terminate its authority—a challenge that resembles managing a digital workforce rather than securing traditional software.
The report suggests that practical preparedness comes from how security teams use AI internally, which builds durable capability rather than just favorable conditions. Teams that run AI in their own triage and detection tuning learn through experience where vulnerabilities emerge and how agents fail under adversarial input, knowledge that transfers directly to securing AI across the organization. Multiple analysts questioned whether the 41% optimism rate accurately reflects enterprise CISO sentiment, with one noting that most security executives are struggling through the fastest-moving security challenge of their careers. The timing question remains open: surveyed in spring 2024, would those same CISOs respond with equal confidence given subsequent developments in AI capabilities and high-profile incidents involving rogue agents? The organizational factors may prove critical, but AI amplifies foundational security weaknesses, particularly those rooted in organizational dysfunction.

