Aug 13 2026
Artificial Intelligence

Q&A With ISACA’s Chris Dimitriades on Why AI Adoption Is Outpacing Governance, Security and ROI

Governance, workforce readiness and domain-specific deployment will determine whether enterprises realize long-term value from artificial intelligence.

As artificial intelligence rapidly transforms how organizations operate, many businesses still struggle to measure ROI, govern AI deployments and prepare for the cybersecurity risks the technology introduces. In a conversation with BizTech Managing Editor Bob Keaveney, Chris Dimitriades, chief global strategy officer at ISACA, discusses a recent ISACA poll that delves into why organizations still misunderstand AI adoption, how attackers weaponize AI faster than many companies can defend against it, and why governance and domain-specific deployments will determine whether enterprises realize long-term value from AI.

BIZTECH: The poll's findings indicate some uncertainty around AI’s return on investment. Most respondents don’t seem to think they’re finding significant ROI yet. What is going on there?

DIMITRIADES: There is still a misconception about AI. Many people treat it as a plug-and-play technology. They expect to apply it within the organization without redesigning processes and without really embedding and integrating AI within the business. In reality, AI is more of a structural economic force that will transform products and services as a whole. One of the reasons organizations struggle with ROI is the way many of them treat AI today. 

Another reason is the lack of talent and trained employees in different parts of an organization who can help management identify the right investments and the right expected returns. Another very significant part of the problem is that organizations approach AI horizontally. They expect ROI through a broad application of generic AI tools, while the real value may lie in domain-specific large language models and AI systems that address the transformation needs of a particular industry or sector.

Click the banner below to learn how AI is impacting cybersecurity strategies.


BIZTECH: Can you explain a little more about what you mean by “horizontal” AI versus “domain-specific” AI?

DIMITRIADES:  Many discussions around AI create the misconception that if you apply generic AI models within an organization, you will immediately — or at least soon enough — improve productivity, reduce costs or create more value. The right way to approach this is to identify the specific operational needs within the organization, or within the industry in which the organization operates, and then look for customized solutions — domain-specific AI systems that can truly transform operations and provide an ROI that makes sense.

Just to give you an idea, expectations for domain-specific AI systems in the finance sector are extremely high over the next few years. Manufacturing is also expected to see major adoption, as is healthcare. Simply applying generic AI tools across the organization is not going to transform the business. A domain-specific AI system gives organizations the opportunity to create new products, new services and a more embedded application of AI within the business.

LEARN MORE: How can businesses enhance security for legacy applications?

BIZTECH: Is part of the issue simply that organizations are trying to measure AI success too early? Are we still too early in this process to know what realistic ROI should look like?

DIMITRIADES: It starts with applying the right framework for adoption. This is one area where ISACA has invested through the AI component of CMMI (Capability Maturity Model Integration), a maturity assessment framework for applying AI technologies within specific industries. Organizations need to identify needs and prerequisites, and understand things like the data structures required for AI adoption. They need to design, build or acquire the right AI solution, and only then can they realistically budget for and forecast ROI.

AI adoption is a journey. It’s not plug and play. It’s not, “I installed a new AI solution, and here’s the result.” It requires transformation across several parts of an organization to bring real results. The organizations that are able to do that — and that use the right frameworks to measure improvement — will be able to calculate ROI in ways that actually make sense for the business.

Chris Dimitriades, ISACA


BIZTECH: It seems like many organizations leap into AI without having the right infrastructure, governance or data management practices in place. What kinds of risks does that create?

DIMITRIADES: First of all, they definitely risk the investment itself if they are not ready. But from a governance point of view, they also open themselves to an enormous amount of risk. This is something we discussed recently with the global ISACA community at our North America Conference — that maybe the biggest threat to an organization right now is not a hacker, but the AI system they just installed. Many organizations implement AI solutions without the appropriate governance structures in place and without really understanding the risks involved. If you don’t understand the risks, you’re not able to build the right controls around them.

AI introduces very specific risks from several perspectives. There are privacy risks, cybersecurity risks, and AI systems themselves can be exploited. Their behavior can be manipulated. They can lead to data leakage. If employees enter corporate information into untrusted AI platforms, they can unintentionally expose corporate secrets. Those organizations open themselves up to an enormous database of risks, and that’s pretty scary.

BIZTECH: Many organizations don’t know how long it would take to shut down an AI system during a security incident. What does that tell you about where organizations are right now in understanding the security implications of AI?

DIMITRIADES: From a cybersecurity point of view, I’m convinced that most organizations are not ready yet, for several reasons. First of all, a significant skills gap around AI across multiple professions still exists. When organizations don’t have employees with the right skills, it becomes very difficult to predict, identify and manage risks. More important, every day we see vulnerabilities emerging in AI systems that can be exploited and lead to disastrous scenarios for enterprises.

There are really two sides to this. One involves vulnerabilities and weaknesses in the AI systems organizations deploy internally. The other involves external AI systems being weaponized to launch attacks against organizations. For both, I believe the cybersecurity community is still unprepared. If you think about it, AI's sophistication — especially when weaponized — is becoming so high that very soon organizations may face attacks happening at the speed of intent.

We no longer need expert hackers with deep technical knowledge to launch sophisticated cyberattacks. AI has made those capabilities much more accessible. AI systems can identify zero-day vulnerabilities, orchestrate attacks and combine multiple weaknesses across systems to launch highly sophisticated attacks that many organizations will struggle to defend against. One of the questions we ask boards and directors is whether their organization is adopting AI for defense purposes faster than attackers are adopting AI to attack the company. In many cases, the answer is "no."

Click the banner below to learn how organizations are unlocking artificial intelligence’s potential.


BIZTECH: Respondents ranked misinformation, privacy violations and social engineering among the top AI risks. Are they missing anything?

DIMITRIADES: Those are definitely top risks, and we’ve already seen examples involving sophisticated social engineering attacks, misinformation campaigns and deepfakes. Another major category of risk is attack automation. AI systems increasingly identify zero-day vulnerabilities, write the code necessary to exploit them and then launch attacks automatically.

We’re at a crossroads right now. Organizations need to accelerate their own adoption of AI for defensive purposes to improve security systems and compete in what could become AI-versus-AI security battles. You may eventually have AI systems attacking organizations and AI systems defending them at the same time.

DISCOVER: Learn why it’s so difficult to measure the return on your artificial intelligence investments.

BIZTECH: Let’s talk about how AI is changing work inside organizations. Is AI merely changing the nature of what work gets done or is it actually making life easier for humans?

DIMITRIADES: Eventually, I think it will be both. Right now, the priority for many organizations is simply getting people trained on how to use AI, do prompt engineering and embed AI into workflows in ways that deliver value. There is going to be transformation across many professions as automation increasingly takes over simpler tasks. That means professionals will need to upskill and shift toward more sophisticated responsibilities, including configuring AI systems, monitoring them and designing AI-enabled solutions.

At the moment, workloads actually increase in many cases because people are still learning how to use AI and how to integrate it into the organization. Eventually, AI will reduce workloads in many areas and fundamentally change how work gets done.

BIZTECH: Most respondents also don’t think their boards fully understand AI risks and challenges. What should boards and executive teams do differently?

DIMITRIADES:  Organizations need to define governance and accountability structures around AI. They need clear ownership of AI initiatives and clear accountability. After putting those governance structures in place, they also need to elevate AI and cyber risks to the board level and make it part of the overall enterprise risk management framework instead of treating AI as a silo.

Boards and executives also need training so they can become more AI-savvy and better understand what AI means within the context of their organizations. That understanding will directly impact the decisions they make around AI adoption.

Organizations should also seek third-party assurance related to the security, accuracy and privacy of AI systems, and they need to invest heavily in building AI talent internally. Boards should ask a very simple question: Do we have the right talent to turn AI into a true business enabler within the organization?

BIZTECH: Is there anything else you think organizations should understand about the survey findings or the current state of AI adoption?

DIMITRIADES:  We've seen improvement in some areas. More organizations are building AI policies, and awareness of AI risks and governance is improving, but there is still a very large gap between organizations’ thirst to innovate through AI and the governance structures needed to support that innovation responsibly. Organizations are rushing to implement AI, but governance hasn’t caught up.

Courtesy of ISACA
Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.