SHARE
Security / September 29, 2026

Hybrid AI Is Changing the CISO Mandate

One month into my new role, and it’s clear that I joined Gigamon at a pivotal time for cybersecurity.

Artificial intelligence (AI) is rapidly changing how organizations operate, how applications are built, and how attackers operate. At the same time, a significant shift toward Hybrid AI is already taking shape.

Much like cloud, organizations are unlikely to standardize on a single AI model or provider. They will use frontier, open-weight, specialized, and privately hosted models, selecting the right AI for each workload based on performance, security, sovereignty, and cost.

That flexibility is powerful. It also creates a new challenge for chief information security officers (CISOs).

Every model, agent, application, application programming interface (API), and data source creates connections that must be understood and governed. AI is creating a dynamic ecosystem in which data moves among systems spanning public and private clouds, data centers, software as a service (SaaS) platforms, and the edge.

Left unaddressed, this creates new opportunities for threat actors to exploit gaps across hybrid cloud infrastructure. Effective security depends on understanding what is actually happening inside your environment. As AI increases the speed and complexity of technology, CISOs increasingly need independent evidence of how systems communicate and how data moves to manage risk with confidence.

Hybrid AI Is Raising the Stakes for Governance

Our latest research, based on responses from more than 300 global CISOs, shows how quickly governance is rising on the security agenda. Inadequate governance surrounding unsanctioned AI use is a top data security challenge for 80 percent of CISOs, while 43 percent rank corporate governance as their top security priority.

Infographic titled “Hybrid AI Creates Governance Challenges for CISOs.” Three horizontal bars show survey findings: 80% cite inadequate governance around unsanctioned AI use as the top challenge to securing data; 76% report limited visibility into AI-driven traffic as a major barrier to securing AI adoption; and 43% rank AI corporate governance as a top security priority. Source: Gigamon 2026 Hybrid Cloud Security Survey.

AI governance can easily become focused on policy, including which models are approved, what data they can access, and where sensitive information can be processed. Those policies are important, but policy alone isn’t governance.

Organizations also need evidence that policies are being followed. That means understanding which AI systems are operating across the infrastructure, how they interact with applications and data, where that data is moving, and whether those interactions are authorized.

That is becoming harder as employees adopt their own AI tools, developers embed models into applications, and AI agents initiate actions with less human involvement. The result is a growing gap between the AI activity organizations believe they are governing and what is actually taking place across their environments.

The consequences are already apparent. Our research found that 83 percent of organizations experienced an AI-related security incident over the past year.

You Cannot Govern What You Cannot See

Effective governance depends on knowing what is actually happening across the environment. As Hybrid AI expands the number of models, agents, applications, and data flows organizations must govern, visibility provides the evidence security teams need to validate policies, identify activity outside approved boundaries, and respond when risk emerges.

That visibility remains a significant challenge. Limited visibility into AI-driven traffic is a major barrier to securing AI adoption for 76 percent of CISOs, even as organizations continue investing heavily in security technology. In fact, 93 percent have deployed new tools to improve detection and visibility.

Yet breaches continue.

Organizations are realizing that having more security data does not necessarily provide better security visibility.

Security teams already have enormous quantities of metrics, events, logs, and traces (MELT) data. What they often lack is the independent evidence that helps explain what actually occurred.

Hybrid AI magnifies this problem. An AI agent might access enterprise data, interact with an application, call a model hosted in a public cloud, and initiate an action in an internal system. Security teams may have logs from several components without a complete view of the interaction or the data moving between them.

As machine-to-machine interactions multiply, reconstructing that activity will become fundamental to securing Hybrid AI.

Closing the Gap Between Perception and Reality

Visibility also matters beyond the security operations center.

Our research found a significant gap between executive perceptions of cyber readiness and the experience of CISOs. Nearly half of non-CISO C-level executives believe their organizations can identify the root cause of an incident and restore normal operations within 72 hours, compared with just 27 percent of CISOs.

The disconnect extends to AI governance, with seven in 10 CISOs saying limited board understanding of security best practices could cause AI adoption to move faster than security readiness.

CISOs must also translate highly technical activity into evidence business leaders can use to make decisions. As organizations embrace Hybrid AI, leaders need a clear understanding of where AI is being used, what data it accesses, where that data moves, whether controls are working, and where risk exists.

That can move conversations with the board from theoretical risk to observable reality.

From More Data to Better Evidence

Hybrid AI also magnifies familiar blind spots. AI models, agents, applications, and data stores increasingly communicate laterally across distributed environments, often through encrypted traffic. Understanding that data in motion will become more important as AI architectures become increasingly complex and autonomous.

For CISOs, this creates an opportunity to establish the right security foundation before Hybrid AI architectures become significantly more complex. The time to establish visibility is now, while those architectures are still taking shape. Building that foundation early can give security teams the evidence they need to understand new AI interactions, identify emerging risks, and apply governance as the environment evolves.

Network-derived telemetry, including application-aware metadata, packets, and flows, provides independent evidence of what systems are actually doing and how they are communicating. Combined with MELT data, it provides a more complete understanding of activity across hybrid infrastructure. Our research found that 87 percent of CISOs consider this deep observability foundational to securing their AI deployments.

Getting that foundation right now can put CISOs in a stronger position to support AI innovation without sacrificing visibility, governance, or control as Hybrid AI scales.

Today’s Opportunity for CISOs

Hybrid AI creates risk, but it also gives CISOs an opportunity to play a more strategic role in AI adoption.

Security cannot simply tell the business where AI cannot go. Our job is to establish the visibility, governance, and controls that allow organizations to use AI confidently.

Models, providers, economics, and applications will continue to change. Building a security foundation that evolves with them will help organizations maintain visibility and control as Hybrid AI scales.

For CISOs, visibility is becoming a foundation for confident AI innovation and an opportunity to help shape how the business moves forward.

Read CISO Empowerment in the Age of AI Risk for more insights from more than 300 global CISOs on how AI is reshaping security, governance, visibility, and the CISO mandate.

CONTINUE THE DISCUSSION

People are talking about this in the Gigamon Community’s AI Exchange group.

Share your thoughts today


Back to top