The Renaissance Exec: 30 years ago a hack created cybersecurity's top job – now AI is redrafting it

In 1994, a group of hackers led by Vladimir Levin broke into Citicorp's electronic funds transfer system and moved more than US$10 million out of customer accounts. Nearly all of it was recovered. The bank's reputation was another matter, and the board instructed its CEO to find an executive whose sole job would be making sure it never happened again. The man they appointed in 1995, Steve Katz, became the world's first Chief Information Security Officer (CISO) – a title that had not existed the year before.

Three decades later, the role that heist invented is being redrafted again, but this time the pressure comes from inside the organisation. The latest threats are less about who is attacking, and more about who is working.

"The CISO's role has fundamentally changed in ways that were pretty unimaginable even five years ago," says Anna Collard, SVP of content strategy and CISO advisor at KnowBe4 Africa. "In almost every type of organisation we are now managing a hybrid workforce, and half of that workforce doesn't have a heartbeat. And that has really changed things dramatically."

Anna Collard, SVP of content strategy and CISO advisor at KnowBe4 Africa.

South Africans already brush up against this hybrid workforce daily, mostly without registering it: the bot resolving a banking query at 23:00, the AI assistant triaging an insurance claim, the agent scheduling a delivery. What customers experience as convenience, security leaders experience as a workforce of autonomous systems with access to inboxes, databases and payment infrastructure – workers in function, if not in form – none of whom sat through an interview, signed a contract or attended an induction.

The numbers show how quickly this has become the defining feature of the CISO’s job. Splunk's 2026 CISO Report, which surveyed 650 CISOs globally, found that 96% now oversee AI governance and risk across their entire organisations. The RH-ISAC 2026 CISO Benchmark Report, drawing on more than 200 security leaders in retail and hospitality, found that 71% identified AI as their primary point of friction – ahead of ransomware and phishing for the first time. Data from KnowBe4's From Agentic Risk to Human Wins report shows that 64% of South African organisations report their use of AI is unapproved or ungoverned, and that 38% of local cybersecurity leaders say AI agents are already taking autonomous action within their workflows. Separately, 48% report that unsanctioned software and AI apps have actively impacted their security posture over the past 12 months.

The problem the org chart cannot see

Consider a single employee who, in an afternoon, sets up an AI agent with access to the customer database, the email system and cloud storage. Is that a security event? An HR matter, since something is now performing work nobody hired it to do? A legal question about data protection under POPIA? A procurement issue, given that software with system access usually goes through vetting? It is all four at once, and the twentieth-century organisational chart has no owner for it. In practice, the responsibility defaults to the CISO.

"Ten years ago, CISOs focused on defending against external threats," Collard says. "Human risk was secondary, and CISOs were gatekeepers measured by what they blocked."

The perimeter those early CISOs defended has since largely dissolved. Attackers now target human attention and judgement directly, through social engineering sharpened by generative AI, which is why the discipline of digital workforce security – aligning people, processes and technology to manage the risks humans and their AI agents carry into organisations – has moved from the margins of the role to its centre. “Governing the behaviour of digital workers is becoming just as critical as training human ones,” Collard explains.

"The CISO of today already deals with both humans and machines. The CISO of 2030 will inherit a workforce that isn't fully human. That demands three new competencies: managing non-human, machine and agent identities with the same rigour as employees; AI orchestration literacy, understanding what your agents can do, who they act on behalf of, and where their authority ends; and applied AI governance, anchored in frameworks like ISO 42001.And because agents act continuously rather than at a single decision point, governance itself has to become a runtime discipline - watching and able to intervene while they're actually working, not just approving them once up front."

What binds those competencies together is not code, but rather behavioural science – the one discipline that applies equally to a distracted employee and an over-eager AI agent. "Treat behavioural science and psychology as core skills," Collard advises. "Build resilience, assume compromise, and govern autonomous systems. Modern CISOs succeed through influence not  control."

Executives will still need to translate all of this upward. "The CISOs who thrive in 2030 will be the ones who have learned to speak the language of the boardroom without losing their technical credibility," says Collard. "Think about how a credit score works. You don't need to understand the underlying mechanics to know whether your score is moving in the right direction. A well-constructed risk score does the same for cybersecurity."

A wider door into the profession

The career implications run in both directions. For security professionals, the path to the top now runs through psychology, organisational dynamics and governance as much as through infrastructure. ISC2's 2025 hiring research found employers now ranking traits like problem-solving and analytical thinking above technical skills for entry-level roles, and actively looking beyond computer science degrees. For everyone else, the door has widened. If the scarcest skill in security is understanding why people – and the systems trained on people – behave the way they do, then graduates in psychology and behavioural economics hold qualifications the industry now needs. In a country with a persistent shortage of security practitioners and no shortage of graduates searching for a foothold, that is a recruitment argument worth making loudly.

Katz spent his career insisting that security was a business risk discipline rather than a technology function, decades before the industry caught up with him. The 2030 version of the role he pioneered takes that idea further than he could have anticipated. "The deeper skill is still human: as AI agents think fast, our people must think better," Collard says. "The CISO becomes part architect, part behavioural scientist, protecting human judgement, attention, and oversight inside increasingly automated workflows."