Market Vision Paper

CISOs, reshape your response to AI-shifted threats with NIST CSF 2.0

This Market Vision Paper is for chief information security officers, CIOs, and enterprise security leaders navigating how to govern and protect AI systems using the NIST Cybersecurity Framework 2.0.

Enterprise CISOs are splitting into two camps on AI. One group is fully behind their company’s AI-first vision; the other is firmly adhering to a security-first ideology. The truth is, AI innovation without security invites chaos, while rigid control without innovation ensures irrelevance. The real task for CISOs is to integrate governing AI with the same rigor they use to defend the enterprise.

At HFS Research and OakTruss Group, we see AI growth hinging on how well organizations are strengthening their security, governance, and control over the data that drives it. However, the real word of warning would be that AI won’t scale if CISOs don’t adapt their approach to data and application security to align with new AI realities. If they don’t change how their enterprises approach security, CISOs will expose data, processes, and intellectual property, leaving enterprises at risk and CISOs looking for new jobs.

In this MVP, we examine the latest version of the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF 2.0) and some of our own cybersecurity frameworks that enterprise CISOs can use to understand the intersection of AI and cybersecurity better. These models support the development of a cybersecurity framework that spans the fit assessment of AI, deployment, and the ongoing audit and enforcement needed to scale and protect.

Look no further than MCP for a reason to get on top of securing your AI efforts

The fastest-growing standard ever has been Anthropic’s Model Context Protocol (MCP). This standard is being adopted at an unprecedented pace to integrate and share data across AI agents, models, and applications. Yet, a lack of security planning can result in MCPs (and many APIs for that matter) exposing sensitive information through poorly governed authorization, allowing even legitimate AI agents to access inappropriate data or interact with unverified content providers.

If CISOs get this wrong, the impact is brutal: sensitive data leaks, AI systems break, regulators step in, and the board loses trust. One bad MCP setup can take down workflows, expose customer information, and derail multimillion-dollar AI programs.

As illustrated in Exhibit 1, HFS believes AI and cyber are a flywheel that increases both benefits and risks associated with AI. To address this amplification and velocity of development and dependence on AI, CISOs need to act now, and with frameworks they can trust.

Exhibit 1: The HFS AI–cyber risk flywheel increases AI’s risks and benefits with each spin

A circular flywheel diagram illustrating the self-reinforcing relationship between AI adoption and cybersecurity risk. Four stages are arranged in a continuous clockwise loop around a central label reading "AI-cyber risk flywheel": AI adoption expands (upper right), threat vectors evolve (lower right), cyber defense responds (lower left), and governance adapts (upper left). Each quadrant of the circle is filled with a distinct color: purple, blue, gray, and violet. The diagram conveys that as AI adoption grows, threats multiply, defenses must respond, and governance must continuously update, completing a loop that amplifies both benefits and risks with each cycle. Source: HFS Research, 2025.

Source: HFS Research, 2025

The NIST CSF 2.0 model should be the core of framing AI and cybersecurity

The National Institute of Standards and Technology (NIST) offers guidance and frameworks for various technology topics. For this report, we are focusing on how NIST CSF 2.0 will be crucial to the adoption of AI, from automation and copilots to agentic AI. Exhibit 2 is NIST’s CSF 2.0 model, which we’ll discuss and amplify based on our research. We’ll also outline how a CISO can apply these models to their security and governance efforts.

Exhibit 2: NIST’s CSF 2.0 should be the foundation for securing AI in your enterprise

A circular segmented diagram representing the six functions of the NIST Cybersecurity Framework 2.0. The outer ring is divided into six labeled segments: Govern (top center, dark navy), Identify (upper right, violet), Protect (right, purple), Detect (bottom center, gray), Respond (left, dark purple), and Recover (upper left, blue). The center of the circle reads "NIST cybersecurity framework." The diagram visually emphasizes that all six functions operate concurrently and that Govern sits at the top as the integrating function. Source: NIST, 2025.

Source: NIST, 2025

NIST argues that all functions must be addressed concurrently to offer effective threat detection, action, and management. As a starting point, a CISO will need to rethink their governance model with respect to how their business and teams are evolving in the context of AI.

HFS security frameworks make NIST CSF 2.0 actionable

NIST CSF 2.0 tells you what good security looks like, but it doesn’t tell you how to run it in an AI-driven enterprise. That’s where the HFS security frameworks come in. These lenses translate NIST’s high-level pillars into practical controls and operating models for AI. CISOs can use these HFS models in conjunction with NIST to transform governance, protection, and detection into actionable workflows that teams can effectively execute.

Exhibit 3: HFS security frameworks help CISOs action every pillar of NIST CSF 2.0

A four-row reference table mapping HFS proprietary security frameworks to the NIST CSF 2.0 pillars they address and the practical use each framework provides. Row 1: Guard (governance model for AI, defining who owns what, who can use what, and how decisions are audited) maps to Govern, with secondary support for Identify and Respond; practical use is setting ownership, access rules, approvals, disclosure, and compliance for enterprise AI. Row 2: Defend (technical controls for securing AI systems, data, models, pipelines, and endpoints) maps to Protect, with secondary support for Recover; practical use is hardening systems with data-integrity checks, model and package signing, secured CI/CD, and runtime controls. Row 3: Shield (using AI to strengthen cyber defense through better visibility, faster detection, and smarter triage and incident response) maps to Detect, with secondary support for Respond; practical use is deploying behavioral analytics, weak-signal correlation, automated triage, and learning loops. Row 4: AI-cyber risk flywheel (continuous loop connecting AI adoption, threat evolution, control response, and governance updates) maps to all pillars; practical use is treating security as a living system and keeping controls adaptive as AI and threats evolve. Source: HFS Research, 2025.

Source: HFS Research, 2025

Pillar 1: Governance is key to becoming an AI-ready enterprise

Governance is now the backbone of resilience in the AI era. It’s not paperwork, and it’s not a checkbox. Annual audits can’t keep pace with AI systems that change every week. Without clear ownership and decision authority, enterprises lose visibility and control over how AI is deployed.

HFS has noted that AI is arriving in two main ways: either via a planned rollout led by the organization, or by slipping in through feature advancements of Software-as-a-Service (SaaS) or cloud apps and services—unintentional AI. Sources of unintentional AI include Microsoft Copilot, Salesforce’s Agentforce, SAP’s Joule, or cursor.ai. Along with MCPs, tools like these expand capability but also expose data and create dependencies before CISOs even approve their use.

These uninvited “guest apps” often skip governance guardrails, introducing hidden risks. NIST is emphasizing governance and enforcement at the core of its framework because CISOs can’t focus solely on what they intentionally install; they must also be vigilant for uninvited AI threats.

The result is that governance falls short when it’s treated like just another dashboard. The board and leadership teams need to link governance directly to business outcomes. They need to maintain lists of models, datasets, and vendor AI to facilitate transparency, track AI touchpoints, and stay in control. The HFS GUARD model in Exhibit 4 expands this accountability into five layers, from access control to disclosure and compliance, helping CISOs operationalize responsible AI governance.

Exhibit 4: The HFS GUARD model includes five layers of operational governance for responsible AI

A horizontal five-stage process diagram labeled "GUARD framework for AI governance." Five interlocking diamond shapes are arranged left to right, each representing one layer of the framework. From left to right: Governance structure (clear policies and oversight for AI governance), User access control (define and restrict access based on role and accountability), Adversarial robustness (testing to defend against AI attacks), Responsibility mapping (assign accountability for AI behavior and decisions), and Disclosure and compliance (maintain transparency and meet regulatory requirements). The diamonds overlap to suggest that each layer connects to and depends on the next. Source: HFS Research, 2025.

Source: HFS Research, 2025

Pillar 2: Identification must link assets to business risk

CISOs can’t protect what they don’t know is there, and AI is making it more challenging to see every corner. Counting old endpoints and applications is no longer effective when AI models, APIs, and third-party connections continuously change the attack surface. The real challenge now isn’t system identification; instead, it is recognizing how each asset or model impacts the flow of data or information across business operations.

AI makes things even trickier by linking both structured and unstructured data across clouds, systems, and partners. It’s built to surface insights, but it also pulls data into places where it wasn’t intended to be shared. Unless CISOs map out how information flows, it’s tough to know which AI tools are handling sensitive or regulated material. This lack of clarity is why the core functions of the NIST model must now apply across both categories and subcategories of data workflows, applications, and user interactions. With AI agents now providing non-technical employees direct access to enterprise data, governance must ensure that authorization, context, and usage boundaries are enforced because the agent itself won’t.

The latest NIST CSF extends the Identify pillar beyond simple service desk inventory and toward understanding how information flows across an organization and how AI might surface it. CISOs need real-time visibility into how planned and unintentional AI connect the “data dots,” then they can tie each “dot” back to risk, enforcement, and oversight. Identification is the starting point for building a strong and defensible AI security approach.

Pillar 3: Protection must adopt adaptive, context-driven controls

Security can no longer be reactive, because identities, devices, and data behave differently every time you interact; static rules can’t keep up. CISOs must pair AI controls with “human-at-the-helm” governance. Due to increasing AI usage, enterprises are now often applying zero-trust architectures in an attempt to control access for users and systems and mitigate unchecked AI adoption.

However, CISOs must understand that automating oversight or access without enforcement guardrails is likely to reduce, rather than eliminate, risk. They cannot blindly expect AI solutions of their own to automatically quarantine systems or block users without explainability because this will erode trust and compliance, leading to more shadow usage rather than less.

The NIST CSF 2.0 reframes the Protect pillar as a balance between automation and accountability. It emphasizes that control systems should learn continuously while still allowing for human review. Our own take on this is the HFS DEFEND framework in Exhibit 5, which provides the technical foundation for this balance: six pillars covering data integrity, execution control, and endpoint hardening that secure AI environments against emerging risks.

However, the world of protection is changing quickly. With AI-driven attacks scaling through thousands of autonomous agents, even today’s API gateways, firewalls, and authentication systems will struggle to keep up. The next layer of protection must evolve toward quantum-safe, non-session-based encryption that secures data in transit because what and how you protect will soon matter more than where you protect.

Exhibit 5: In the HFS DEFEND framework, six components of technical security link AI systems to defend against bad actors or actions

A circular hexagonal arrangement of six components forming the HFS DEFEND framework, connected by a continuous loop of arrows to indicate that each element reinforces the others. The six components are: Data integrity (ensures clean and validated datasets), Execution control (secures AI model training environments), Federated learning (enables privacy-preserving model training), Endpoint hardening (defends APIs and model-serving endpoints), Network vigilance (monitors AI system interactions), and Dynamic audit trails (maintains immutable logs for compliance). Each component is represented by a labeled icon positioned around the circular flow. Source: HFS Research, 2025.

Source: HFS Research, 2025

Pillar 4: Detection must think like a human because today’s AI hides like them

Detection is the first stage of a reality check for enterprises, as AI-backed attacks target systems, imitating real human behavior, and evolve. Traditional detection methods miss this because they only look for known threats.

CISOs require a detection mechanism that can now predict behavioral anomalies. AI threat detection can detect even the faint signals using the principle of correlation. However, attackers are also using the same AI to evade detection. Success goes to the side that, in record time, will build a detection system that predicts, spans multiple domains, and learns continuously, powered by AI but always checked by human judgment.

The HFS SHIELD model outlines six ways AI strengthens cyber defense, from situational awareness to incident response, guiding CISOs on where to embed AI for proactive detection and faster containment.

Exhibit 6: The HFS SHIELD model includes ways AI strengthens your cyber defense shield

A circular arrangement of six components forming the HFS SHIELD model, illustrating how AI strengthens cyber defense across six dimensions. The components are positioned in pairs around a central area: Decision support (summarizes alerts and aids faster triage) and Situational awareness (enhances visibility across devices and cloud workloads) at the top; Learning loops (continuously tunes detection models) and Hunting and detection (identifies anomalies and weak signals faster) in the middle; Engineering efficiency (automates workflows, freeing analysts for strategy) and Incident response (guides real-time containment and communication) at the bottom. Connecting lines and icons suggest the components work in concert to produce faster, smarter, and more adaptive cyber defense. Source: HFS Research, 2025.

Source: HFS Research, 2025

Pillar 5: Response requires confidence and speed

Response is where the rubber meets the road and where resilience is put to the test. An AI-powered enterprise can’t depend on manual playbooks because by the time humans get involved, the breach has already occurred. Automation must act first to isolate, contain, and neutralize a threat in seconds.

Is speed alone enough? No. A successful response still requires human judgment. The most effective CISOs are those who will use AI to move quickly while maintaining control. The future is where automation takes the lead, but humans make the final decision.

In the AI era, NIST’s Respond pillar has become a test of leadership, not technology. CISOs will need to have response systems that operate at machine speed while being able to explain every action in human terms. The real mark of resilience is being transparent about what was done, why it was triggered, and who approved it.

Pillar 6: Recovery needs to prove resilience, because just restarting the systems is not enough

Recovery is where CISOs are truly tested, because it extends beyond maintaining uptime; CISOs must also prove system integrity. Recovered data, models, or backups need to be clean and uncompromised. AI presents an additional challenge in that it involves multiple dependencies. One compromised dataset can re-infect everything it is connected to.

In the AI era, NIST’s Recover pillar is the proof of trust. CISOs will have to treat recovery as a continuous demonstration, not an afterthought. They will have to keep the confidence of boards, regulators, and customers.

The Bottom Line: NIST CSF 2.0 turns resilience from aspirational to predictable when AI-driven failures or attacks hit.

In 2025, CISOs cannot afford to keep reacting to what AI is doing; they need to lead with it. NIST CSF 2.0 can serve as an excellent framework for designing a security structure that keeps pace with the rapid advancements of AI. The catch is that structures are spineless without execution.

The signal here is clear: Use NIST CSF 2.0 and make your security posture more explainable, measurable, and accountable.

Sign in to view or download this research.

Login

Register

Insight. Inspiration. Impact.

Register now for immediate access of HFS' research, data and forward looking trends.

Get Started

Download Research

    Sign In

    Sign up for a free
    research account

    With the exception of our Horizons reports, most of our research is available for free on our website. Sign up for a free account and start realizing the power of insights now.

    By registering you agree to our privacy policy.

    I hereby consent that HFS Research can process my personal data.

    Digests/Newsletters: Overviews of the latest news, insight, and research by HFS.

    HFS Events: Exclusive invitations to HFS webinars, roundtables, and summits, bringing together key industry stakeholders focused on major innovations impacting business operations.

    Premium Access

    Our premium subscription gives enterprise clients access to our complete library of proprietary research, direct access to our industry analysts, and other benefits.

    Contact us at [email protected] for more information on premium access.

      Contact Ask HFS AI Support