Senior cybersecurity leaders are gaining influence and higher pay as AI‑driven attacks force security out of the server room and into the heart of corporate decision‑making. The July breach involving rogue OpenAI autonomous agents on the Hugging Face platform crystallised the threat, accelerating a wave of agent‑led intrusions and underlining how quickly attack methods are evolving.

Executives describe a role that has ballooned in scope. "It feels like my job has doubled or quadrupled," said Wally Dalrymple, chief security officer at ETS. John Scimone, Dell's security chief, put it bluntly: "The ground under our feet is shifting." Organisations now expect CISOs to not only block external attackers, but also govern internal AI agents, control sensitive data and advise on major business moves.

The market is reacting. Recruiters report intense competition for candidates who combine deep technical chops with AI security experience, and pay reflects that demand, with packages exceeding seven figures for the right hires. Michael Piacente of Hitch Partners said his team is working around the clock and still losing candidates to faster offers, likening the intensity to the early cloud era but compressed into weeks.

That pressure is reshaping corporate structure and priorities. Many security chiefs are now reporting directly to CEOs instead of chief information officers, and CISOs with crisis management experience, business acumen and public profiles are especially prized. One Barclays analyst heard from a CISO who went from meeting the CEO once a month to three times a week.

Money is following the risk, but not fast enough for some teams. Gartner projects cybersecurity budgets will rise 6% in 2026, while IDC says the Middle East and Africa are on pace to boost spending 16% year over year. Vendors with AI defence offerings have seen surging demand, and stocks for firms such as CrowdStrike and Palo Alto Networks are up roughly 80% this year, while Okta has about doubled. At the same time, the vendor landscape is crowded with startups promising fixes, leaving CISOs to evaluate new tools that are still maturing.

OpenAI paused some research after the Hugging Face incident but has continued product releases, including the rollout of GPT‑6 Astra this week despite earlier warnings of "Critical" cyber capabilities. Google and Anthropic have also released models with specific cyber features, underscoring how rapidly the threat and response ecosystems are evolving.

Companies face a simple choice next: accelerate hiring and budget shifts to place experienced, AI‑proven CISOs at the centre of strategy, or risk exposure as attackers adopt increasingly autonomous techniques. For incumbent CISOs, the mandate is clear, and the stakes have rarely been higher.