Hello. This is Alex Bakker with what’s important in the IT and business services industry this week.
If someone forwarded you this briefing, consider subscribing here.
Going Faster
Thirteen years ago, at our Cloud Business Summit, Gary Lynch, then a managing director and global practice leader at insurance brokerage and consulting firm Marsh, asked the audience a simple question: “Why do cars have brakes?”
The obvious answer was so they could stop. Lynch’s answer was, “so they can go faster.”
His point was that risk management is commonly mistaken as a constraint. Controls, reviews and governance appear to slow the adoption of new technology. In reality, they speed it up. By creating confidence and operating boundaries, they allow an organization to accelerate safely.
That distinction is even more important in the age of AI. AI increases the capabilities of attackers, but it also increases the speed at which ordinary employees can write code, move data, automate processes and make consequential mistakes. The emerging challenge for cybersecurity is, therefore, larger than keeping bad actors out. It is enabling the entire business to make AI-speed decisions that do not become AI-speed losses.
In our recent ISG Market Lens Cybersecurity study, we can see this transformation fully underway. Of the enterprises we spoke to, 71% described the role of cybersecurity in AI delivery as either a partner or advisor – both playing collaborative roles to guide and govern AI adoption. (see Data Watch)
Data Watch

Going Somewhere?
Thirteen years ago, when Lynch asked his question, the consequential challenge was discerning whether adopting cloud and multi-tenant SaaS applications represented an acceptable security risk. The business cases were clear, but many organizations still approached security primarily through firewalls and perimeter defenses.
AI has the opposite problem. Adoption is accelerating even as many business cases remain unproven. Cybersecurity and governance teams are already positioned to establish the operating boundaries within which organizations can experiment, learn and scale.
We’ve talked before about a variety of challenges facing enterprises that are adopting AI: the validation bottleneck, difficulties in valuing AI time savings and maintaining data quality. Although these challenges surface in technology programs, they are ultimately questions of business objectives and operating models: What outcomes are worth pursuing? How will value be measured? What changes to work and data will be required?
Recently, there has been a growing concern in the market about AI value, with many organizations balking at their token spend or struggling to attribute value to their use cases.
Whether this impacts the long-term AI market or not remains to be seen, but a reckoning about AI value means not only are enterprise governance frameworks working, but that organizations are willing to use them.
Controls can create permission to move faster, but they cannot supply the destination. The question for the market today is, now that we know the brakes work, how do we hit the accelerator?