TL;DR: 2026 CISO strategy is shifting from perimeter prevention to resilience, with board accountability, AI risk, and real-time data visibility driving budgets, according to Sentra. The security implication is that governance now depends on knowing where sensitive data lives, how AI touches it, and how quickly teams can contain exposure when controls fail.
NHIMG editorial — based on content published by Sentra: CISO priorities for 2026 and the shift from prevention to resilience
By the numbers:
- 82% of CISOs reported direct interactions with CEOs, showing how far cybersecurity has moved into board-level decision-making.
- 76% of CISOs expected a significant cyberattack, while 58% felt unprepared for it.
Questions worth separating out
Q: How should security teams govern sensitive data used by AI systems?
A: Security teams should treat AI as a data consumer that needs policy boundaries, not just authentication.
Q: Why does SaaS adoption create IAM and data governance risk?
A: SaaS adoption creates risk because access, data placement, and accountability are distributed across multiple parties.
Q: What breaks when organisations rely on static data classification?
A: Static classification breaks when data moves, changes form, or is reused inside AI and SaaS workflows.
Practitioner guidance
- Implement continuous sensitive-data discovery Track structured, unstructured, and AI-generated data across cloud, SaaS, data lakes, and on-prem environments so exposure is not limited to periodic scans.
- Tie access reviews to data sensitivity Review who can reach the highest-value datasets, then validate whether the access is still justified by the identity's role, lifecycle, and business purpose.
- Separate AI workflow governance from application governance Map prompt, retrieval, output, and storage paths for AI systems so policy can follow the data rather than stopping at the application boundary.
What's in the full article
Sentra's full blog covers the operational detail this post intentionally leaves for the source:
- The article's full board-level framing for CISO priorities and how those priorities are being translated into 2026 budgets.
- Sentra's specific DSPM and DDR positioning for AI, cloud, and SaaS data visibility.
- The vendor's explanation of how secure AI, modern data governance, and zero trust identity governance fit together operationally.
- The article's perspective on tool consolidation and continuous offensive testing as part of the same resilience agenda.
👉 Read Sentra's CISO priorities analysis for 2026 data resilience and AI governance →
CISO priorities for 2026: what changes for security teams now?
Explore further
Data visibility is now an identity problem as much as a storage problem. Once sensitive information sits behind cloud, SaaS, and AI workflows, the question is no longer only where it is stored but who and what can reach it. That shifts governance from periodic audits to continuous access and exposure control. Practitioners should treat data security posture as part of identity governance, not a separate inventory exercise.
A question worth separating out:
Q: Who should own AI data exposure risk in a hybrid environment?
A: Ownership should sit across identity, data, and security operations rather than in one tool team. IAM governs the entitlements, DSPM identifies the data, and response teams handle abuse patterns. If only one group owns the problem, the organisation usually ends up with partial visibility and weak accountability.
👉 Read our full editorial: CISO priorities for 2026 point to data visibility and resilience