Insights: VCIO, VCISO & AI Governance

Latest thinking on VCIO, VCISO and AI Governance

Cover image for article: Your IAM Assumes Humans

Your IAM Assumes Humans. Your AI Agents didn't get the memo

You’re probably not going to get taken down by a lone insider with a dodgy USB stick. If something bites you, it’s more likely to be an AI agent quietly pushing changes across systems.

Cover image for article: AI, to use or not use

AI, to use or not to use

Artificial intelligence has arrived in the boardroom wearing two faces. One is the polished promise of productivity, growth and strategic edge. The other is a less comfortable reality: variable outputs, hidden costs, weak governance and risks that do not fit neatly inside yesterday’s control frameworks.

Cover image placeholder for article

ISO 42001: the governance layer AI has been missing

The old fear was that AI would become too intelligent. The more immediate risk is that it’s already useful enough to be connected to customer data, internal documents and business decisions before anyone has decided who is accountable for it.

Cover image placeholder for article

Cybersecurity is still treated like an IT problem and that's a problem

Walk into a lot of organisations, and you’ll find security buried somewhere under infrastructure, sitting alongside helpdesk tickets and patch cycles. It’s seen as necessary. Expensive. Occasionally annoying. But rarely strategic.

And yet, when something goes wrong, it doesn’t stay in IT for long.

It lands in the boardroom.

AI governance and fractional leadership: key statistics

AI governance

21%

of organizations report having established policies to govern generative AI.

Source: McKinsey, State of AI 2023

≈33%

say their data is ready/fit for AI (quality, governance, and access); data complexity and governance remain top barriers.

Source: IBM, Global AI Adoption Index 2023

Top 3

Risk, compliance and security ranked among the top barriers to scaling AI across the enterprise.

Sources: Deloitte, State of AI in the Enterprise; McKinsey, State of AI 2023

Fractional VCIO/VCISO

≈24 months

approximate average CISO tenure, underscoring leadership continuity risk.

Source: Heidrick & Struggles, Global CISO Survey (latest)

≈60%+

of organizations report a cybersecurity skills shortage or skills gap.

Sources: ISACA, State of Cybersecurity; ISC2, Cybersecurity Workforce Study 2023

Significant

cost savings vs. a full-time executive when needs are part-time (e.g., 1–3 days/week), with faster time-to-impact.

Source: Market salary benchmarks (AON, Hays, Robert Half)