September 16, 2026

CISO Talks: Top 5 Focus Areas of 2026

We traveled coast to coast, asking 159 CISOs in 5 cities what's most important right now in data security. Here's what they had to say.

Mary Hayes WeierContent Marketing Lead

Key Takeaways:

  • This first installment of CISO Talks introduces 5 data security issues that surfaced repeatedly during roundtables with security leaders in 5 U.S. cities.
  • CISOs said visibility and detection were the biggest security gaps. They want a clearer picture of where sensitive data lives and how it moves across their companies.
  • Data classification needs a new approach. CISOs broadly agreed that manual, user-driven classification isn’t working and see automation as the path forward.
  • AI is reshaping data protection priorities and budgets. Its rapid proliferation is creating new data risks while giving organizations a new reason to invest in stronger protections.
  • The conversations went beyond technology. CISOs also spoke candidly about career resiliency and the tension between building a security program that can run without them and remaining indispensable.
  • Thank you! Your submission has been received!
    Oops! Something went wrong while submitting the form.

    Data is always on the move. This summer, so were we. ORION Security traveled across America to meet with CISOs and hear firsthand the challenges reshaping data security in 2026. 

    We joined roundtables in Boston, Columbus, Minneapolis, Las Vegas, and San Diego hosted by CISO Executive Network, a peer-to-peer networking group. Collectively, the roundtables brought in 159 security leaders who talked candidly about security gaps, what's getting funded, and what needs fixing. 

    To get the conversation going, we asked security leaders the same quick question at each stop: What's the one thing that would most improve your organization's data security posture?

    When the answers were tallied, two priorities took the top spots: visibility and detection, followed closely by ownership and accountability

    But the rankings told only part of the story. Automated classification and discovery, while not in the top three, sparked some of the most animated discussion in every city. In a different poll about data security investments, AI-driven budget wins was a theme across all regions, while on a more personal level, CISO job security surfaced as a recurring concern in career workshops.

    These conversations became the foundation for CISO Talks, our blog series on what we learned in our cross country tour. This first article gives a top-level view of five topics that dominated much of the talks. In future articles, we’ll dig more into the details of each one.

    Editorial note: While the content for this series comes from event transcripts, attendee names and companies won't be shared.

    1. Desire for Data Visibility Tops All

    For the quick poll on the one thing that would improve data security most, visibility and detection took the top spot out of 12 answers, with 14% of 159 respondents choosing it nationwide. CISOs said their teams often can’t get a full picture of sensitive company data or where it’s going as it moves across the organization.

    At one large insurer, roughly two million emails are on the move every month, and its six-person insider-threat team is tasked with trying to determine what among them actually poses a data leak risk.

    That helps explain why data loss prevention (DLP) remains such an important part of the security stack in 2026. Protecting sensitive data means being able to map how sensitive data moves, understand where it’s headed, and recognize when that movement puts it at risk.

    CISOs' own experiences shed light on this priority. One security leader at a large health insurer discovered the same sensitive file had been replicated across 50 repositories. Another said his company, founded in the 1960s, still has files dating back to that decade, digitized enough to be searchable but never meaningfully assessed for risk.

    At another large insurer, virtually every document is classified as "internal," regardless of what it actually contains. Roughly two million emails are on the move every month at the insurer, many of them with documents attached, and its six-person insider-threat team is tasked with trying to determine what among them actually poses a data leak risk.

    These stories highlight an overarching struggle: Companies have accumulated decades of data, copied it across repositories, moved it into SaaS applications and cloud environments, and layered classification systems on top of that—with no meaningful distinction between an ordinary internal document and something genuinely sensitive. 

    What's the one thing that would most improve your organization's data security posture? Poll of 159 security leaders at CISO Executive Network and ORION Security roundtables in Boston, Columbus, Minneapolis, Las Vegas and San Diego, 2026. One answer per respondent; percentages rounded.
    RankAnswerRespondentsShare of 159
    1Visibility and detection2214%
    2Ownership and accountability2013%
    3Business buy-in and resources1912%
    4Automated classification and discovery1811%
    5Culture and education159%
    6Data minimization and retention149%
    7Data in motion and lineage128%
    8Identity and access106%
    9Shadow AI and AI governance96%
    10Consolidation and standardization85%
    11Enforcement and policy authority64%
    12Third and fourth party risk64%
    Total159100%

    2. Everyone Wants to Own Data. Who Owns the Risk?

    If visibility is the most common frustration for CISOs, ownership and accountability are close behind. In fact, it was the most emotionally charged topic across the country.

    When describing business owners outside of IT and security, CISO Executive Network General Manager Andy Land put it this way: "They want to own the upside, the value of the data. They just don't want to own the downside and the risks that come with it."

    Attendees largely agreed, describing governance committees full of stakeholders with an interest in data but no one ultimately accountable for it. One CISO noted there were “too many cooks in the kitchen.” 

    A security leader at a utility company described what happens when an organization takes the opposite approach. His company formally assigns data loss risk from a software application to the corporate officer whose business unit uses the app, rather than defaulting that responsibility to IT or security. That led to an uncomfortable conversation with a CFO who discovered she was accountable for a legacy application. Her first response was that the application belonged to IT. The security leader's answer: If your business unit needs it, or if it doesn't and you don't turn it off, then you own the risk that comes with it.

    The bigger picture is that ownership ambiguity has real consequences for data control. Visibility into where data lives and how it moves means little if no one is accountable for deciding what to do about it. 

    3. Data Classification Needs a New Approach

    Automated classification and discovery came in fourth in CISO ExecNet’s opening poll for what's needed to improve data security, but the popularity of this topic in the talks that followed underscores how much security teams are still struggling to get it right.

    A security leader at a semiconductor company raised another wrinkle: when AI tools use company data to create new data, who classifies the output, and who owns it?

    And from coast to coast, there was strong consensus that manual, user-driven classification has failed for decades, and that AI-native, automatic classification on the fly is the first credible path forward.

    At a Boston roundtable, a security leader at an asset management firm said his company's classification still depends on employees tagging their own files. But employees under-tag because they don't want to trigger controls that could get in the way of their work. 

    A poll on security program maturity told much the same story. Asked to rate their ability to discover and classify sensitive data across cloud, SaaS, and AI environments, almost no group anywhere in the country called itself highly automated. At the Columbus event, which drew in CISOs from across the Great Lakes region, only one respondent out of 37 claimed high automation. In Las Vegas, seven attendees said their classification was still entirely manual.

    And classification gets considerably harder when the sensitivity of data can change depending on where it moves and how it's used. A GRC leader at a large industrial manufacturer described a part number that might sit in an ordinary engineering file until it's sold to a defense customer. Suddenly, that same information becomes federally controlled, but there's no system tracking the change. 

    A security leader at a semiconductor company raised another wrinkle: when AI tools use company data to create new data, who classifies the output, and who owns it?

    A transportation company security leader had identified more than 250 AI tools already operating somewhere inside the organization, most of which didn't have security approval. 

    4. AI Dominates Security Investments

    The most interesting pattern in the numbers appeared only when we compared two different questions.

    When CISOs were asked what would most improve their data security posture, shadow AI and AI governance didn’t rank as high as the other areas covered in this article. But when they were asked at these events what was driving new investment in data protection, the picture changed dramatically.

    In Columbus, AI beat regulatory compliance 22 votes to 13 as the biggest investment driver. In Boston, it led 9 to 5 over compliance among attendees in the room and 12 to 5 among those participating online. San Diego was the exception, where regulatory pressure edged ahead, although AI remained a strong second.

    That disconnect may say more about the current state of data security than either poll does on its own. The proliferation of AI is giving boards and business leaders a new reason to fund data protection, because they see AI as a data security problem.

    A security leader at a transportation company had identified more than 250 AI tools already operating somewhere inside the organization, most of which didn't have security approval. 

    Another participant connected the proliferation of AI directly to the much older problem of data sprawl: every new workflow that needs its own access to company information can create yet another place for sensitive data to travel or reside.

    5. Tension About CISO Job Security

    One of the most revealing talks of the tour came from a completely different part of the day.

    During members-only workshops on career resiliency, CISO ExecNet leaders talked about the challenge of moving from “dispensable to indispensable.” One CISO challenged the premise: “Well, don’t we want to become dispensable?”

    The question gets at an odd tension in security leadership. A successful CISO builds processes, develops people, and creates a mature program that doesn’t depend on one individual to keep it running. In most leadership jobs, that’s what success is supposed to look like.

    But several attendees described the uncomfortable consequences. Build a program that runs well enough without you, and the organization may eventually ask how much it still needs the person who built it.

    One CISO joked that the best thing his company could do for its security posture might be mandatory sabbaticals for the team, a way to force-test whether the security function could carry on without constantly depending on the same people.

    A Bird's-Eve View of Our U.S. Tour

    We started our coast-to-coast travels with a straightforward question about data security. What we discovered was that security teams everywhere are under pressure from several directions at once.

    In the next installments of CISO Talks, we'll take each of these issues in turn, going deeper into what security leaders told us, where they agreed, where they didn't, and what they're actually doing about these challenges. 

    We’ll also bring in ORION Security’s perspective on each issue, sharing what we’ve learned about what works, what doesn’t, and how security teams can start addressing these problems. You’ll come away from this series with a better understanding of how to protect sensitive data as it moves across users, applications, and environments.

    Thank you to all the security leaders who joined ORION Security and CISO Executive Network during what we've been fondly calling the "Route 66" summer road trip (although there were admittedly far more planes than cars involved). From Boston to San Diego and several stops in between, we covered a lot of ground. More importantly, we came back with a much clearer picture of what's on the minds of CISOs in 2026.

    Are data visibility and detection at the top of your security gap list? Learn what real visibility looks like in a quick demo.

    The DLP renaissance, as it unfolds

    DLP Strategy & Trends

    CISO Talks: Top 5 Focus Areas of 2026

    We traveled coast to coast, asking 159 CISOs in 5 cities what's most important right now in data security. Here's what they had to say.

    September 16, 2026
    Guides & Explainers

    Endpoint DLP: Coverage, Limits, and the AI Blind Spot

    Endpoint DLP protects data on laptops and desktops, but it can't see SaaS or AI tools. Here's what it covers, where it stops, and how to close the gap.

    September 15, 2026
    Guides & Explainers

    Data at Rest vs. Data in Motion: Where Leaks Actually Happen

    Data at rest, in motion, and in use each leak in different ways. Here's how the three states differ, and why data in use is the AI-era blind spot.

    September 10, 2026