if ( !emtpy($headline_subheadline ) ) : ?>
Rapidly emerging risks and the need for business agility have many CISOs forgoing fixed, multi-year plans in favor of a tiered approach that includes continual revisiting of key strategic priorities.
endif; ?>
Insight Global’s John Dickson had a problem familiar to many CISOs today.
Employees were embracing AI tools faster than his security team could track them, and new AI agents and service integrations spread rapidly across the environment alongside them. Dickson and his security org had plans to build visibility into those non-human identities (NHIs), tracking what they could reach and how they behaved. It just wasn’t supposed to happen for another year.
Dickson didn’t wait. His team immediately built AI discovery, observability, control, and reporting, including visibility into NHIs such as service accounts and AI agents. He paired the work with a cross-functional AI assurance function built around what he calls “the Department of Know, not the Department of No.”
Every quarter now, Dickson and his security team formally reassess their strategy against what’s changed in the threat landscape and the staffing firm’s business, then shift the horizon out another three months. “An annual review means you’re making decisions on assumptions that may be a year old,” he says. “A quarterly cadence keeps the strategy anchored to where things are today rather than where they were.”
Security leaders like Dickson are finding that they can no longer treat a roadmap as something they set once a year and revisit at the next planning cycle. In its 2026 Leadership Perspective Survey of more than 1,000 CISOs, Gartner defines agility for security and risk leaders as the ability to rapidly reprioritize roadmaps and investments to address shifting business risks.
As a result, leading CISOs are bifurcating traditional two- to three-year security roadmaps into two speeds. Principles, compliance commitments, and major architectural bets still get planned years out. Tools and day-to-day tactics are revisited monthly, weekly, sometimes in the moment.
Ambiguity has become the baseline. “We are operating with more genuine uncertainty than at any point I can remember,” says Chris Cochran, field CISO and vice president of AI security at SANS Institute, the cybersecurity training and research organization. “In that environment, intellectual flexibility is a decisive competitive advantage.”
When quarterly is too slow
When AI agents built by citizen developers at Grafana Labs started surfacing misconfigurations and incomplete controls nobody had caught, CISO Joe McManus couldn’t wait for the next annual planning cycle to respond.
“If you ask an agent to do something, it will try everything it can to complete that goal,” he says.
Those agent findings spurred McManus to add control audits and system segmentation to the open-source observability company’s roadmap. Neither had been part of the plan a few months earlier.
Planning beyond a year is close to “an exercise in futility,” McManus says, given how quickly the landscape changes, especially with cheap, capable AI now available to nearly anyone. Cloud security, in his view, is largely a solved problem at this point. The open questions revolve around shadow AI and shadow code, and the integrations citizen developers build on their own.
Grafana still keeps a two-year “goal map.” But the second year gets reprioritized as the threat landscape shifts. And the team has abandoned long threat-modeling engagements with full code reviews in favor of weekly, tactical sprints with six-week turnarounds. Security, McManus adds, has no end state.
“The luxury of a fixed three-year plan you set and forget is gone,” says Cochran of SANS Institute. CISOs are now expected to deliver answers quarter to quarter and — increasingly — in the moment. AI, threat actor speed, budget cycles, and board pressure are compounding each other.
Security review used to run in a straight line at Fable Security, a human-risk-management startup. The product team designed a feature, security and engineering reviewed the design, engineering built it, security and QA reviewed it again, and only then did the product ship.
That sequence is gone, says Fable Security CISO Jacob Berry. Security now works alongside engineering as features release more quickly to keep pace with the market. The gates haven’t disappeared, but the approach has changed from controlling teams to equipping them.
Raja Chris, former CISO of Annaly Capital Management and founder and CEO of AI governance company AIVONS, notes that the better security tools today behave more like living systems, continuously discovering and responding to new exposures rather than waiting for the next planned review. CISOs’ approaches to their strategies and roadmaps should follow suit.
Where the long view still stands
Many security leaders still build multi-year roadmaps for threats such as quantum computing, even as they expect AI-powered attacks to become the leading cyber threat over the next two to three years, according to KPMG’s 2026 Cybersecurity and Technology Risk Survey of 310 security leaders at companies with more than $1 billion in revenue.
Insight Global’s long-term category includes commitments to data governance, core platform modernization, and international growth, an enterprise plan that Dickson’s security team’s timeline follows. At Fable Security, Berry’s team still produces a long-range document he calls “a direction and resourcing plan more than a technical roadmap.”
There’s no hard-and-fast rule for how long a roadmap should run, SANS Institute’s Cochran says. Long-horizon plans tend to focus on compliance and business commitments, or on major AI and infrastructure migrations. But even those aren’t safe from disruption. A shift in budget or executive buy-in, he says, can derail a two-year roadmap overnight.
Determining what goes where
Deciding which bucket a given piece of work belongs in isn’t guesswork, though, Berry says. To make its determinations, his team asks two questions of each initiative: How many people will need to be involved to get it done, and how directly is it tied to a strategic commitment the business has already made?
Work that requires wide coordination and ties directly to a standing commitment gets the longer horizon; narrower, more self-contained work is handled within the same continuous review cycle as tools and tactics.
Outcomes such as identity and resilience endure for years, AIVONS’ Chris says, but the specific technology delivering those outcomes rarely does. So he asks whether a given commitment still holds true if every vendor involved were replaced next year. If so, it probably belongs in the long-term plan. If not, it’s really just an implementation choice — which should be handled on a faster cycle — being mislabeled as strategy.
That’s one of the ways roadmaps lose credibility, Chris says.
Governance as an ongoing conversation
A roadmap that’s rewritten every quarter can’t be governed the same way a static three-year plan was, with a single sign-off and compliance checklist. What separates organizations handling this well from those struggling is leadership, says SANS Institute’s Cochran. The CISOs thriving under quarterly replanning treat governance as a discipline of communication rather than compliance. Success depends on whether they can bring the board, the business, and their own teams along when the plan changes again.
Berry sees that expectation firsthand from his own board. They want a clear account of how security is keeping pace with where the business is going, and what risk that pace introduces.
Boards are asking different questions, AIVONS’ Chris says. They used to ask whether the organization was secure. Now they want to see the evidence: what’s running, who’s accountable, and what can reach sensitive data.
A report that can’t distinguish between “we looked, and it was fine” and “we never looked,” he says, is claiming a confidence it hasn’t earned. KPMG’s 2026 survey points to a related challenge: 42% of security leaders say they struggle to demonstrate return on cybersecurity investment to their boards.
The challenge of proving value as convincingly as proving risk is part of why the roadmap is evolving. CISOs haven’t abandoned long-range thinking, but what they’re willing to commit to in writing, and for how long, is changing.
“That is why I don’t think the security roadmap is dead,” says AIVONS’ Chris. “The static roadmap is.”
Insight Global’s Dickson agrees. “A long-range roadmap still has value,” he says, “as long as you’re willing to revisit it as often as the world around it changes.”










