Whatever happened to the 36-month IT security roadmap?
CISOs are dropping fixed multi-year security roadmaps as AI and fast-moving threats force quarterly reprioritization.
CSO Online reports that CISOs, including leaders at Insight Global and Grafana Labs, are replacing fixed two- to three-year security roadmaps with quarterly or faster reprioritization as AI use and threats shift. Gartner's 2026 Leadership Perspective Survey of more than 1,000 CISOs frames agility as rapidly changing roadmaps and investments. Long-horizon plans still cover compliance, architecture, data governance, and quantum risk, while tools and tactics are revisited weekly or in the moment. KPMG's survey of 310 security leaders at companies above $1 billion in revenue found many expect AI-powered attacks to become the leading threat within two to three years.