The AI cybersecurity war has a new front line star, and a seven-figure price

The AI breaches have promoted the CISO in the US hiring market, while NIS2 has required the board itself to own cybersecurity since before any of it happened


Privacy secure. Network security technology with computer processor chip on digital motherboard background
Image Credits Credit: Canva

AI agent breaches have pushed the chief information security officer into the boardroom in America, with seven-figure pay packages and a recruiting market one search firm compares to nothing since cloud. Europe reached the same place by statute, with NIS2 putting the duty on the management body and allowing regulators to bar a chief executive without any conviction.

The hack OpenAI’s agents ran on Hugging Face in July turned the chief information security officer into a boardroom job, CNBC reported on Saturday. Qualified candidates are clearing seven-figure pay packages.

It feels like my job has doubled or quadrupled,” said Wally Dalrymple, chief security officer at the education firm ETS. Dell’s security chief John Scimone said “the ground under our feet is shifting“.

Recruiter Michael Piacente said his team works 18 to 20 hour days and still loses a candidate a week per search. Cloud was a slow drift by comparison, and “it wasn’t everything, all at once together like AI is“.

Budgets have not moved as fast. Cybersecurity spending is forecast to rise 6% this year, and Gartner puts the market for securing AI at $2.8B against $2.59 trillion of AI spending overall.

The trigger is documented. OpenAI’s agents broke out of a sandbox and reached Hugging Face in July, an incident the company confirmed rather than disclosed.

It did not stop there. Reuters reported on Friday that another swarm broke containment in May and commandeered a German website.

Accountability in America is arriving through lawyers. 15 US states have already told OpenAI to preserve evidence from the Hugging Face breach.

In Europe the same promotion happened years earlier, and it did not need a hiring market.

The NIS2 directive requires the management body itself to approve and oversee cybersecurity risk measures, and to be trained to assess them. The duty sits with the board, not with the security chief.

Regulators can also bar the chief executive or legal representative of an essential entity from managerial functions for serious or repeated non-compliance. No criminal conviction is needed, and fines run to EUR 10M or 2% of worldwide turnover.

More arrives this week. Cyber Resilience Act reporting duties start on 11 September, giving manufacturers 24 hours for an early warning and 72 for a notification.

The American market is loading the risk onto one person. Europe put it on the board. Dalrymple told CNBC he feels “the weight of the world“.

CNBC also quotes Joe Sullivan, once security chief at Uber and Facebook. He was convicted in 2022 of obstruction and misprision of a felony over a concealed breach, and an appeals court upheld it in March last year. That is the other route to holding a security chief responsible.

Get the TNW newsletter

Get the most important tech news in your inbox each week.

Published
Back to top