Latest thinking on VCIO, VCISO and AI Governance

You’re probably not going to get taken down by a lone insider with a dodgy USB stick. If something bites you, it’s more likely to be an AI agent quietly pushing changes across systems.
Related services: VCIO Advisory · VCISO Advisory · AI Governance Advisory

Artificial intelligence has arrived in the boardroom wearing two faces. One is the polished promise of productivity, growth and strategic edge. The other is a less comfortable reality: variable outputs, hidden costs, weak governance and risks that do not fit neatly inside yesterday’s control frameworks.
Related services: VCIO Advisory · VCISO Advisory · AI Governance Advisory

The old fear was that AI would become too intelligent. The more immediate risk is that it’s already useful enough to be connected to customer data, internal documents and business decisions before anyone has decided who is accountable for it.
Related services: VCIO Advisory · VCISO Advisory · AI Governance Advisory

Walk into a lot of organisations, and you’ll find security buried somewhere under infrastructure, sitting alongside helpdesk tickets and patch cycles. It’s seen as necessary. Expensive. Occasionally annoying. But rarely strategic.
And yet, when something goes wrong, it doesn’t stay in IT for long.
It lands in the boardroom.
Related services: VCIO Advisory · VCISO Advisory · AI Governance Advisory
of organizations report having established policies to govern generative AI.
Source: McKinsey, State of AI 2023
say their data is ready/fit for AI (quality, governance, and access); data complexity and governance remain top barriers.
Source: IBM, Global AI Adoption Index 2023
Risk, compliance and security ranked among the top barriers to scaling AI across the enterprise.
Sources: Deloitte, State of AI in the Enterprise; McKinsey, State of AI 2023
approximate average CISO tenure, underscoring leadership continuity risk.
Source: Heidrick & Struggles, Global CISO Survey (latest)
of organizations report a cybersecurity skills shortage or skills gap.
Sources: ISACA, State of Cybersecurity; ISC2, Cybersecurity Workforce Study 2023
cost savings vs. a full-time executive when needs are part-time (e.g., 1–3 days/week), with faster time-to-impact.
Source: Market salary benchmarks (AON, Hays, Robert Half)