{"id":6685,"date":"2026-07-26T05:06:51","date_gmt":"2026-07-26T09:06:51","guid":{"rendered":"https:\/\/workai.tv\/news\/2026\/07\/ai-security\/ivanti-ciso-takes-on-ai-security-governance-and-talent-gap\/"},"modified":"2026-07-26T05:06:51","modified_gmt":"2026-07-26T09:06:51","slug":"ivanti-ciso-takes-on-ai-security-governance-and-talent-gap","status":"publish","type":"post","link":"https:\/\/workai.tv\/news\/2026\/07\/ai-security\/ivanti-ciso-takes-on-ai-security-governance-and-talent-gap\/","title":{"rendered":"Ivanti CISO Takes on AI Security, Governance and Talent Gap"},"content":{"rendered":"<h2>Share with your CISO<\/h2>\n<p>Ivanti&#8217;s CISO is pushing back against the instinct to ban AI tools outright, arguing instead for structured governance that keeps security teams in control without killing adoption velocity. The company&#8217;s own data is the uncomfortable starting point: 32% of employees who use generative AI at work hide that use from management entirely. Ivanti&#8217;s response is an <a href=\"https:\/\/cybermagazine.com\/news\/ivanti-ciso-takes-on-ai-security-governance-and-talent-gap\" target=\"_blank\" rel=\"noopener nofollow\">AI Governance Council<\/a>, a cross-functional body that categorizes use cases, runs tiered review processes, and gives employees a sanctioned path to request tool approvals.<\/p>\n<h2>What this means for your business<\/h2>\n<p>The 32% shadow AI figure is doing real work here. If a third of your AI-active workforce is actively concealing tool use, you don&#8217;t have a policy problem, you have a trust problem that policy alone won&#8217;t fix. The organizations most exposed are those that responded to AI&#8217;s arrival with a blanket prohibition, which reliably drives usage underground rather than eliminating it. CISOs who&#8217;ve already moved toward curated allowlists are on the right side of this; those still running hard blocks are accumulating invisible data exposure they can&#8217;t audit or quantify.<\/p>\n<p>Ivanti&#8217;s tiered governance model, written by a vendor whose products sit inside security operations, is worth taking seriously on its structural logic even if the source has an interest in making governance sound manageable rather than genuinely difficult. The core idea, that friction reduction and security aren&#8217;t opposites, is defensible. Sanctioned AI options with a clear submission path lower the incentive for shadow adoption the same way consumer app stores lowered the incentive for sideloading. The model only breaks down if the review process becomes a bottleneck that takes weeks, at which point employees route around it anyway and you&#8217;re back to square one.<\/p>\n<p>The talent argument buried at the end of the piece is actually the sharper long-term call. AI fluency becoming a baseline requirement for security roles means your next hiring cycle looks different from your last one, and your current team&#8217;s skill mix has a shorter shelf life than your compensation structure assumes. The leading indicator to watch isn&#8217;t whether your governance council exists; it&#8217;s whether your security team can read an AI system&#8217;s outputs critically enough to catch when it&#8217;s wrong. That&#8217;s the capability gap that compounds quietly until it doesn&#8217;t.<\/p>\n<p><em>Based on reporting from <a href=\"https:\/\/cybermagazine.com\/news\/ivanti-ciso-takes-on-ai-security-governance-and-talent-gap\" target=\"_blank\" rel=\"noopener nofollow\">Ivanti CISO Takes on AI Security, Governance and Talent Gap<\/a>, originally published 2026-07-26 04:08:00.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Share with your CISO Ivanti&#8217;s CISO is pushing back against the instinct to ban AI tools outright, arguing instead for structured governance that keeps security teams in control without killing adoption velocity. The company&#8217;s own data is the uncomfortable starting point: 32% of employees who use generative AI at work hide that use from management [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":6686,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[143],"tags":[238],"tmauthors":[],"class_list":["post-6685","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai-security","tag-ciso"],"_links":{"self":[{"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/posts\/6685","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/comments?post=6685"}],"version-history":[{"count":0,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/posts\/6685\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/media\/6686"}],"wp:attachment":[{"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/media?parent=6685"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/categories?post=6685"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/tags?post=6685"},{"taxonomy":"tmauthors","embeddable":true,"href":"https:\/\/workai.tv\/news\/wp-json\/wp\/v2\/tmauthors?post=6685"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}