The CISO’s job has always been challenging, and it doesn’t seem to be getting any easier.From managing a rapidly evolving and expanding threat landscape to a widely distributed IT environment with a chronic shortage of skilled security talent, CISOs are now being asked to take on the responsibility of securing AI workloads including ensuring data privacy and security.The added duties are putting a tremendous amount of pressure on CISOs, according to Kara Sprague, CEO of crowdsourced security platform company HackerOne."It’s not just a few more tasks; it’s a fundamental change in their role,” Sprague told MSSP Alert. "This means they're tasked with securing technologies like AI, which are evolving at an incredible speed, often driven by different parts of the business eager for a competitive advantage. This rapid adoption creates entirely new attack surfaces and unique vulnerabilities that internal teams, no matter how skilled, may not have the specialized knowledge to address.”
programs, VDPs, and pentesting,That is true when addressing the newest responsibilities of AI security and data privacy. According to the report, 84% of CISOs say they are now in charge of securing AI, and 82% now oversee data privacy. Of those, 88% find crowdsourced security effective for data privacy vulnerabilities, and 81% for AI flaws.
Responsibilities, Challenges Grow
While their responsibilities are growing, their struggles with budgets and talent continue. CISOs are now turning to crowdsourced security, which includes proactive elements such as bug bounties, vulnerability disclosure programs, and third-party penetration testing that organizations can tap into, to identify vulnerabilities in applications, systems, and infrastructures.In addition, MSSPs and MSPs – which are increasingly being leaned on by enterprises and SMBs to supply some or all security functions and to take on a more strategic role – are seeing the advantage, she said."What we’re seeing is that MSSPs and MSPs are increasingly recognizing that crowdsourced security helps them scale,” the CEO said. "It provides specialized, on-demand expertise without the need to increase internal staff. And yes, adoption is accelerating. As more CISOs embrace crowdsourced models, their service providers are following suit, either by integrating these capabilities directly or by partnering with companies like HackerOne to deliver them as part of a broader security portfolio.”15% of CISOs are All In
The San Francisco-based company discussed the issue in its recent report, The 15% Advantage: How High-Performing CISOs Leverage Crowdsourced Security, which explored how CISOs are adopting crowdsource programs. Among the 400 leaders surveyed, 15% reported using the full range of these program and saw a significant advantage - doubling their ability to identify and remediate vulnerabilities compared to those who only implemented some elements.The report also found that while 73% of CISOs using crowdsourced security say it’s effective for finding and fixing vulnerabilities, with even stronger results in areas like data privacy and AI-related threats. That effectiveness rises to 89% among CISOs who adopt all three elements, which are, ug bountyprograms, VDPs, and pentesting,That is true when addressing the newest responsibilities of AI security and data privacy. According to the report, 84% of CISOs say they are now in charge of securing AI, and 82% now oversee data privacy. Of those, 88% find crowdsourced security effective for data privacy vulnerabilities, and 81% for AI flaws.




