Before each Innovate Cybersecurity Summit, we ask every attending CISO and security executive to name their three most‑active initiatives. No categories, no vendor influence, no leading questions—just where their attention and budgets are flowing today.
We polled more than 160 CISOs and senior security executives attending our upcoming Innovate Cybersecurity Summit. The following five initiatives are the result – a preview of conversations to come this next week in Scottsdale.
1. AI Governance & Security
48 mentions – 19 % of all initiatives
The single most‑frequent priority is how to govern and protect AI. Attendees are moving past “we need an AI policy” to actually building governance frameworks, risk‑assessment processes and technical controls for generative‑AI models. The discussion now includes model‑risk assessments, AI‑specific threat hunting and the emerging need for “AI guardrails” that can stop adversaries from weaponizing the same technology.
2. Zero‑Trust Architecture
31 mentions – 12 % of all initiatives
Zero‑trust—micro‑segmentation, ZTNA and continuous verification—is the next biggest focus. Respondents are consolidating network, identity and workload controls into a single verification‑always model. The goal is to replace legacy perimeter defenses with a fabric that can keep pace with cloud‑first, hybrid environments.
3. Identity & Access Management (IAM)
28 mentions – 11 % of all initiatives
Identity remains a foundational, yet still unresolved, challenge. Executives are expanding IAM programs to cover non‑human identities (service accounts, AI agents), modernizing identity governance and deploying detection capabilities that surface anomalous credential use. Every new cloud workload or AI service adds a fresh identity exposure, so scaling IAM is now a top‑tier priority.
4. Data Security & Governance
27 mentions – 11 % of all initiatives
Data‑centric controls—DLP, data classification and data‑loss prevention—continue to dominate. With AI models ingesting massive datasets, organizations are also looking at DSPM (Data‑Security Posture Management) as a more architectural answer. The core problem—knowing where sensitive data lives and stopping its unauthorized movement—is still unsolved for most respondents.
5. Cloud Security & SaaS Protection
22 mentions – 9 % of all initiatives
As workloads migrate to public clouds and SaaS, security teams are investing in CSPM/SSPM tools, secure migration frameworks and cloud‑native detection. The data show a strong desire to gain visibility across multi‑cloud environments and to embed security controls directly into the development pipeline.
How we derived the top five
| Step | What we did |
| 1. Extraction | Copied every entry from the three “Cyber Initiative” columns (≈ 360 rows). |
| 2. Normalization | Unified synonymous wording (e.g., “AI Governance”, “AI Security” → AI Governance & Security; “Zero‑Trust”, “ZTNA”, “micro‑segmentation” → Zero‑Trust Architecture; “IAM”, “Identity Management”, “Access Management” → Identity & Access Management). |
| 3. Tally | Counted each distinct, cleaned entry. |
| 4. Ranking | Sorted by total count; the five highest‑frequency items became the list above. |
| 5. Validation | Re‑ran the count script and cross‑checked manually; totals match the raw spreadsheet values. |
Raw counts from the spreadsheet (top ten for reference)
| Initiative (standardized) | Frequency |
| AI Governance & Security | 48 |
| Zero‑Trust Architecture | 31 |
| Identity & Access Management | 28 |
| Data Security & Governance | 27 |
| Cloud Security & SaaS Protection | 22 |
| Application Security / DevSecOps | 15 |
| Third‑Party Risk Management | 14 |
| Incident Response / DR | 13 |
| OT/Industrial Resilience | 11 |
| AI Guardrails / Model Protection | 9 |
(Only the top ten are shown; all remaining initiatives appeared fewer than nine times.)
These five conversations will set the agenda in Scottsdale
As AI reshapes identity, data and cloud workloads simultaneously, the question we’ll wrestle with is: are security programs being rebuilt around that new reality—or merely patched on top of legacy structures? We look forward to the debate, the collaboration and the insights that only an in‑person gathering can spark.