This Market Vision Paper is for chief information security officers, CIOs, and enterprise security leaders navigating how to govern and protect AI systems using the NIST Cybersecurity Framework 2.0.
Enterprise CISOs are splitting into two camps on AI. One group is fully behind their company’s AI-first vision; the other is firmly adhering to a security-first ideology. The truth is, AI innovation without security invites chaos, while rigid control without innovation ensures irrelevance. The real task for CISOs is to integrate governing AI with the same rigor they use to defend the enterprise.
At HFS Research and OakTruss Group, we see AI growth hinging on how well organizations are strengthening their security, governance, and control over the data that drives it. However, the real word of warning would be that AI won’t scale if CISOs don’t adapt their approach to data and application security to align with new AI realities. If they don’t change how their enterprises approach security, CISOs will expose data, processes, and intellectual property, leaving enterprises at risk and CISOs looking for new jobs.
In this MVP, we examine the latest version of the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF 2.0) and some of our own cybersecurity frameworks that enterprise CISOs can use to understand the intersection of AI and cybersecurity better. These models support the development of a cybersecurity framework that spans the fit assessment of AI, deployment, and the ongoing audit and enforcement needed to scale and protect.
The fastest-growing standard ever has been Anthropic’s Model Context Protocol (MCP). This standard is being adopted at an unprecedented pace to integrate and share data across AI agents, models, and applications. Yet, a lack of security planning can result in MCPs (and many APIs for that matter) exposing sensitive information through poorly governed authorization, allowing even legitimate AI agents to access inappropriate data or interact with unverified content providers.
If CISOs get this wrong, the impact is brutal: sensitive data leaks, AI systems break, regulators step in, and the board loses trust. One bad MCP setup can take down workflows, expose customer information, and derail multimillion-dollar AI programs.
As illustrated in Exhibit 1, HFS believes AI and cyber are a flywheel that increases both benefits and risks associated with AI. To address this amplification and velocity of development and dependence on AI, CISOs need to act now, and with frameworks they can trust.

Source: HFS Research, 2025
The National Institute of Standards and Technology (NIST) offers guidance and frameworks for various technology topics. For this report, we are focusing on how NIST CSF 2.0 will be crucial to the adoption of AI, from automation and copilots to agentic AI. Exhibit 2 is NIST’s CSF 2.0 model, which we’ll discuss and amplify based on our research. We’ll also outline how a CISO can apply these models to their security and governance efforts.

Source: NIST, 2025
NIST argues that all functions must be addressed concurrently to offer effective threat detection, action, and management. As a starting point, a CISO will need to rethink their governance model with respect to how their business and teams are evolving in the context of AI.
NIST CSF 2.0 tells you what good security looks like, but it doesn’t tell you how to run it in an AI-driven enterprise. That’s where the HFS security frameworks come in. These lenses translate NIST’s high-level pillars into practical controls and operating models for AI. CISOs can use these HFS models in conjunction with NIST to transform governance, protection, and detection into actionable workflows that teams can effectively execute.

Source: HFS Research, 2025
Governance is now the backbone of resilience in the AI era. It’s not paperwork, and it’s not a checkbox. Annual audits can’t keep pace with AI systems that change every week. Without clear ownership and decision authority, enterprises lose visibility and control over how AI is deployed.
HFS has noted that AI is arriving in two main ways: either via a planned rollout led by the organization, or by slipping in through feature advancements of Software-as-a-Service (SaaS) or cloud apps and services—unintentional AI. Sources of unintentional AI include Microsoft Copilot, Salesforce’s Agentforce, SAP’s Joule, or cursor.ai. Along with MCPs, tools like these expand capability but also expose data and create dependencies before CISOs even approve their use.
These uninvited “guest apps” often skip governance guardrails, introducing hidden risks. NIST is emphasizing governance and enforcement at the core of its framework because CISOs can’t focus solely on what they intentionally install; they must also be vigilant for uninvited AI threats.
The result is that governance falls short when it’s treated like just another dashboard. The board and leadership teams need to link governance directly to business outcomes. They need to maintain lists of models, datasets, and vendor AI to facilitate transparency, track AI touchpoints, and stay in control. The HFS GUARD model in Exhibit 4 expands this accountability into five layers, from access control to disclosure and compliance, helping CISOs operationalize responsible AI governance.

Source: HFS Research, 2025
CISOs can’t protect what they don’t know is there, and AI is making it more challenging to see every corner. Counting old endpoints and applications is no longer effective when AI models, APIs, and third-party connections continuously change the attack surface. The real challenge now isn’t system identification; instead, it is recognizing how each asset or model impacts the flow of data or information across business operations.
AI makes things even trickier by linking both structured and unstructured data across clouds, systems, and partners. It’s built to surface insights, but it also pulls data into places where it wasn’t intended to be shared. Unless CISOs map out how information flows, it’s tough to know which AI tools are handling sensitive or regulated material. This lack of clarity is why the core functions of the NIST model must now apply across both categories and subcategories of data workflows, applications, and user interactions. With AI agents now providing non-technical employees direct access to enterprise data, governance must ensure that authorization, context, and usage boundaries are enforced because the agent itself won’t.
The latest NIST CSF extends the Identify pillar beyond simple service desk inventory and toward understanding how information flows across an organization and how AI might surface it. CISOs need real-time visibility into how planned and unintentional AI connect the “data dots,” then they can tie each “dot” back to risk, enforcement, and oversight. Identification is the starting point for building a strong and defensible AI security approach.
Security can no longer be reactive, because identities, devices, and data behave differently every time you interact; static rules can’t keep up. CISOs must pair AI controls with “human-at-the-helm” governance. Due to increasing AI usage, enterprises are now often applying zero-trust architectures in an attempt to control access for users and systems and mitigate unchecked AI adoption.
However, CISOs must understand that automating oversight or access without enforcement guardrails is likely to reduce, rather than eliminate, risk. They cannot blindly expect AI solutions of their own to automatically quarantine systems or block users without explainability because this will erode trust and compliance, leading to more shadow usage rather than less.
The NIST CSF 2.0 reframes the Protect pillar as a balance between automation and accountability. It emphasizes that control systems should learn continuously while still allowing for human review. Our own take on this is the HFS DEFEND framework in Exhibit 5, which provides the technical foundation for this balance: six pillars covering data integrity, execution control, and endpoint hardening that secure AI environments against emerging risks.
However, the world of protection is changing quickly. With AI-driven attacks scaling through thousands of autonomous agents, even today’s API gateways, firewalls, and authentication systems will struggle to keep up. The next layer of protection must evolve toward quantum-safe, non-session-based encryption that secures data in transit because what and how you protect will soon matter more than where you protect.

Source: HFS Research, 2025
Detection is the first stage of a reality check for enterprises, as AI-backed attacks target systems, imitating real human behavior, and evolve. Traditional detection methods miss this because they only look for known threats.
CISOs require a detection mechanism that can now predict behavioral anomalies. AI threat detection can detect even the faint signals using the principle of correlation. However, attackers are also using the same AI to evade detection. Success goes to the side that, in record time, will build a detection system that predicts, spans multiple domains, and learns continuously, powered by AI but always checked by human judgment.
The HFS SHIELD model outlines six ways AI strengthens cyber defense, from situational awareness to incident response, guiding CISOs on where to embed AI for proactive detection and faster containment.

Source: HFS Research, 2025
Response is where the rubber meets the road and where resilience is put to the test. An AI-powered enterprise can’t depend on manual playbooks because by the time humans get involved, the breach has already occurred. Automation must act first to isolate, contain, and neutralize a threat in seconds.
Is speed alone enough? No. A successful response still requires human judgment. The most effective CISOs are those who will use AI to move quickly while maintaining control. The future is where automation takes the lead, but humans make the final decision.
In the AI era, NIST’s Respond pillar has become a test of leadership, not technology. CISOs will need to have response systems that operate at machine speed while being able to explain every action in human terms. The real mark of resilience is being transparent about what was done, why it was triggered, and who approved it.
Recovery is where CISOs are truly tested, because it extends beyond maintaining uptime; CISOs must also prove system integrity. Recovered data, models, or backups need to be clean and uncompromised. AI presents an additional challenge in that it involves multiple dependencies. One compromised dataset can re-infect everything it is connected to.
In the AI era, NIST’s Recover pillar is the proof of trust. CISOs will have to treat recovery as a continuous demonstration, not an afterthought. They will have to keep the confidence of boards, regulators, and customers.
In 2025, CISOs cannot afford to keep reacting to what AI is doing; they need to lead with it. NIST CSF 2.0 can serve as an excellent framework for designing a security structure that keeps pace with the rapid advancements of AI. The catch is that structures are spineless without execution.
The signal here is clear: Use NIST CSF 2.0 and make your security posture more explainable, measurable, and accountable.
Register now for immediate access of HFS' research, data and forward looking trends.
Get StartedIf you don't have an account, Register here |
With the exception of our Horizons reports, most of our research is available for free on our website. Sign up for a free account and start realizing the power of insights now.
Our premium subscription gives enterprise clients access to our complete library of proprietary research, direct access to our industry analysts, and other benefits.
Contact us at [email protected] for more information on premium access.