U.S. Firms Shift Cybersecurity Focus to Enterprise Risk – ISG – August 21, 2026.
Enterprises in the U.S. are embedding cybersecurity into enterprise risk management and executive decision-making as AI adoption, expanding digital environments and a complex regulatory environment reshape business priorities, according to a new research report published today by Information Services Group (ISG), a global AI-centered technology research and advisory firm.
The 2026 ISG Provider Lens Cybersecurity — Services and Solutions report for the U.S. finds that cybersecurity is increasingly evaluated as a business-critical capability tied to resilience, financial exposure and executive accountability rather than a standalone IT function. Enterprises are adapting to expanding hybrid and multicloud environments, integration of operational technology and rising use of generative and agentic AI by replacing fragmented security approaches with integrated architectures that provide greater visibility, adaptive protection and coordinated risk management.
Doug Saylors, partner and head of ISG
“Cybersecurity has become a business discipline as much as a technology practice,” said Doug Saylors, partner and head of ISG Cybersecurity, Cloud and Infrastructure. “Organizations are aligning security investments with defense and risk reduction to strengthen long-term competitiveness.”
U.S. enterprises are replacing broad collections of security controls with risk-based programs that focus on material business exposure and measurable outcomes. Organizations increasingly use risk quantification, attack path analysis and scenario modeling to prioritize investments and communicate cyber risk to executive leadership. Boards expect clearer insight into security posture, leading companies to establish stronger accountability, defined decision rights and consistent reporting across security, IT, legal and business functions.
The rapid expansion of AI is reshaping cybersecurity from two directions. Enterprises are introducing protections for AI models, data pipelines and autonomous agents while also using AI to improve threat analysis, incident triage and security operations. Multiple AI tools require a wide range of tools to secure AI operations. Companies are adopting runtime safeguards, prompt inspection and identity-aware controls to improve visibility across AI environments and support transparent, auditable security practices as AI becomes more deeply embedded.
Business continuity and recovery readiness are increasingly central to cybersecurity strategies in U.S. organizations. Rather than measuring success solely by preventing attacks, enterprises are expanding crisis coordination to reduce operational disruption when incidents occur. Executive tabletop exercises and structured response planning have become more common as companies prepare for complex cyber events while addressing changing regulatory requirements and financial exposure, ISG says.
“The most effective cybersecurity programs no longer measure success by the number of controls they deploy,” said Yash Jethani, ISG principal analyst and lead author of the report. “Service providers are helping enterprises align security with business priorities by integrating risk analysis, AI safeguards and operational readiness into cohesive programs.”
To learn more, visit: www.isg-one.com