Sep25
Top 10 Leadership and Management links of the week, curated by Corix Partners Founder and CEO JC Gaillard, focusing on cyber security of course, but also a large cross section of subjects including digital transformation, emerging tech, AI governance and the future of work.
This Week >> AI is expanding the enterprise risk landscape faster than governance can keep up.
- Security spending is growing — but not where CISOs control it
- Enterprises are deploying AI agents they can’t even count
- Cyber insurers are struggling to price agentic risk
- Deepfakes are industrializing social engineering
- AI coding is reopening security problems we thought we had solved
- Governance can’t remain an afterthought as agents gain autonomy
The common thread? AI adoption is racing ahead of visibility, control and accountability. The leadership challenge now is to close that gap before complexity turns into systemic risk.
Headline security spending growth masks a more difficult reality for many CISOs: median budgets are flat while AI absorbs an increasing share of new investment, making governance maturity and clearer AI budget ownership increasingly important.
Agentic AI is creating new categories of autonomous and potentially systemic risk that insurers are struggling to quantify, raising the prospect of tighter coverage and pushing more responsibility back onto enterprises.
Organizations are deploying AI agents faster than they can inventory and govern them, creating a fundamental visibility problem around ownership, permissions, access and accountability.
https://www.bankinfosecurity.com/enterprises-cant-count-their-ai-agents-survey-finds-a-32849
With deepfake-enabled social engineering already reaching voice and video calls, organizations need to move beyond teaching employees to “spot the fake” and make robust identity verification the default for sensitive actions.
https://www.helpnetsecurity.com/2026/09/22/cisos-deepfake-incidents-social-engineering-survey/
AI-assisted and vibe coding can reintroduce familiar software-security weaknesses when speed and convenience bypass the mature development, testing and security disciplines organizations have spent years establishing.
AI could reshape cybersecurity around agent-run SOCs, continuous vulnerability triage and machine-speed containment, leaving humans increasingly responsible for supervising fleets of defensive agents and making higher-level judgments.
Reactive AI governance becomes untenable as autonomous agents gain the ability to plan and execute business processes, making guardrails and governance necessary from the outset rather than after deployment.
Because agents behave dynamically and non-deterministically, enterprises need an agent-specific development lifecycle covering evaluation, observability, identity, access, cost controls and governance from design through production.
Diverging approaches to AI safety among major technology providers could fragment enterprise AI strategies, reinforcing the need for organizations to develop their own assurance, evaluation and governance capabilities.
In an environment where AI is compressing technology, strategy and decision cycles, successful IT leadership increasingly depends on coherence, communication, continuous learning, confidence, conviction, courage and the ability to drive change.
https://www.cio.com/article/4222994/the-7-new-cs-of-it-leadership-for-the-ai-era.html
Contact Corix Partners to find out more about developing a successful Cyber Security Practice for your business.
Corix Partners is a Boutique Management Consultancy Firm and Thought-Leadership Platform, focused on assisting CIOs and other C-level executives in resolving Cyber Security Strategy, Organisation & Governance challenges.
Our Founder and CEO JC Gaillard is is a leading strategic advisor and a globally-recognised cybersecurity thought-leader with over 25 years of experience developed in several financial institutions in the UK and continental Europe, and a track-record at driving fundamental change in the security field across global organisations, looking beyond the technical horizon into strategy, governance, culture, and the real dynamics of business transformation.
He is the author of:
Keywords: Cybersecurity, GRC, Leadership
Changing horizons, a business perspective
The Corix Partners Friday Reading List - September 25, 2026
What role should AI have in judging awards?
Two Clocks, One Truck: The Army's Need for Speed Meets New Defense Sourcing Rules
Why Enterprise AI Deals Die Between Meetings