You & The CFO: A Risk Management Partnership
Brendan has written a lot lately on cybersecurity as risk management. Another person in your organization who manages risk is the Chief Financial Officer (CFO). Is there any ovelap?
Your CFO is supposed to keep the company's books straight and tell the board when something doesn't add up. Now imagine telling that same CFO: also, go adopt the new accounting software company-wide, use it yourself for the close, and be the one who catches it when it's wrong.
That's roughly the position CFOs are in with AI according to Deloitte's Q2 2026 CFO Signals survey. More than half of CFOs are using AI for financial planning and budgeting. Forty-one percent use it to analyze financial data. Yet only 43% say they're very confident in their organization's AI governance framework. Most land at "somewhat confident," which is a polite way of saying "we haven't stress-tested this," which is even more polite than "I have no idea."
As a CISO you know this position. You are simultaneously the person deploying the tool and the person who's supposed to catch the tool doing something wrong. User and regulator, same job description. It's an uncomfortable seat and it doesn't get more comfortable just because the technology changed.
Notice from this study that CFOs are also worried about: litigation over protected or private content (43%) and cybersecurity incidents like data loss and network breaches (41%) lead the list, ahead of regulatory complexity (36%) and fraud by external actors (35%). These aren't finance risks, they're cyber-risks. When a CFO lies awake worrying about AI, they're worrying about the same categories of exposure that keep you, the CISO, up.
Risk management doesn't respect org charts.
Here's the part that should really catch your attention as a CISO: 51% of CFOs cite lack of governance authority, or "effective challenge" in risk-speak, as one of the biggest barriers to building an AI governance framework that works. Translation: the person nominally on the hook for managing the risk doesn't have the organizational power to make anyone listen when they say no.
Sound familiar?
Thirty-three percent of CFOs say the CISO -- i.e., you -- owns AI governance at their company. And when asked who actually holds the greatest AI-governance responsibility, only 19% of CFOs name themselves -- ahead of CEOs (12%), and miles ahead of boards and audit committees (4.5%) or chief risk officers (0.5%, which is basically rounding error). Ownership and responsibility for managing this risk are being handed around a table. Everyone's pointing at someone who's pointing back, and while they sort that out, the risk itself doesn't wait for the org chart to catch up.
This is what happens whenever an organization asks its risk owners to also be its growth engine, without giving either job the authority to actually manage the risk that comes with it.
We at Pythia Cyber assess whether the leaders you've put in these seats, including yourself, have the standing, and not just the title, to make risk decisions stick.
Talent without authority is a liability waiting for a trigger event. Let's find out where yours stands.
Ask us how you can align your leaders' authority with the responsibility you've already handed them.
(image credit: Cat and mouse by Pauline E, CC BY-SA 2.0 <https://creativecommons.org/licenses/by-sa/2.0>, via Wikimedia Commons)

Comments
Post a Comment