TECH NEWS
CISOs and DPOs: rising strategic importance, but ongoing challenges remain.
As their roles gain prominence, CISOs and DPOs continue to struggle with a persistent lack of resources, placing them firmly in the spotlight.
June 24, 2026

CISOs and DPOs are no longer operating behind the scenes.
This is the main finding of the 2026 study conducted by PwC Luxembourg with the support of the CNPD, CLUSIL, and the ILR. Increasingly involved in strategic decision-making, risk management, and artificial intelligence initiatives, these professionals are witnessing their growing influence. However, as explained by Maxime Pallez and Antonin Jakubse, who led this latest edition, this recognition is not always matched by the resources, autonomy, or positioning required to meet expanding responsibilities.
Long perceived primarily as compliance-focused roles, Chief Information Security Officers (CISOs) and Data Protection Officers (DPOs) now hold an increasingly central position within organisations. This is one of the key takeaways from the 2026 study Out of the Shadows: CISOs and DPOs in the Spotlight!.
In a context marked by the rise of cyber threats, the acceleration of artificial intelligence adoption, and the introduction of new European regulations such as DORA and NIS2, companies are gradually recognising the strategic value of these roles. Nevertheless, many challenges remain.
From compliance to strategic enablement
The study’s findings highlight a notable shift in perception. “While legal and regulatory requirements remain the primary driver behind the creation of these roles, more and more organisations are now viewing CISOs and DPOs as value creators,” explains Maxime Pallez, Cybersecurity Director at PwC Luxembourg.
As a result, 62% of CISOs believe their role was established to strengthen the organisation’s security, compared with 46% in 2024.
On the data protection side, a similar trend is emerging. “Companies are realising that they can no longer truly operate without these profiles. If they want to leverage new technologies and data, they need people who can frame and govern these uses,” adds Antonin Jakubse, Senior Manager, Privacy at PwC Luxembourg.
This shift also implies a change in how the DPO’s role is perceived. “The DPO should not be seen as someone who slows things down. Their role is to help the business move forward within a compliant and controlled framework,” Antonin Jakubse emphasises.
Growing influence, yet still limited resources
The study shows that CISOs and DPOs are gradually gaining influence within their organisations. Nearly three-quarters of respondents now consider their role to be influential in decision-making processes.
For Maxime Pallez, Cybersecurity Director at PwC Luxembourg, this evolution is a logical response to the growing number of digital risks. “The CISO role must take a broader perspective and be integrated into the organisation’s strategic decisions,” he notes. “It should become a true advisor to the executive committee on cybersecurity matters.”
This recognition has yet to fully translate into adequate resources. Fewer than one in two CISOs (44%) has a dedicated budget, while only 24% of DPOs manage their own financial resources. In other words, expectations are increasing faster than the resources being made available.
Artificial intelligence is reshaping the landscape
When looking at the concerns of cybersecurity and data protection professionals, it comes as no surprise that the adoption of artificial intelligence is now at the top of the list. 69% of CISOs now cite the increase in operational complexity linked to AI as a key challenge, compared with just 29% two years ago.
“While the technology is widely seen as a driver for improving detection and monitoring capabilities, it also raises new issues in terms of security, governance, and data protection,” explains Maxime Pallez, adding that the technology tends to amplify challenges already present within organisations.
AI has become a central topic for both roles. According to the study’s findings, half of CISOs are now involved from the early stages of AI projects, while 53% of DPOs are still only brought in on a case-by-case basis.
From control to enablement
One of the most striking developments is the emergence of “Shadow AI,” referring to the use of artificial intelligence tools without prior validation from IT, the CISO, or the DPO. “Teams sometimes experiment with AI solutions on their own. They then approach the DPO once they have already identified the tool they want to use,” notes Antonin Jakubse. “From a security or data protection perspective, that is often too late.”
In this context, and given business expectations, CISOs and DPOs are still often perceived as barriers to innovation. For both experts, the challenge is therefore to strike the right balance between innovation and risk management. “This involves putting in place an appropriate governance framework. If everything is blocked, the risk is that business teams will bypass it. Conversely, the absence of rules can expose the organisation to significant risks,” explains Maxime Pallez. “CISOs and DPOs need to move from a control mindset to a support-oriented approach.”
Organisational challenges now the main barriers
One of the most surprising findings of the study relates to the obstacles faced by CISOs and DPOs.
For 58% of CISOs, the main barriers are no longer technological but organisational: internal silos, power struggles, or poorly defined responsibilities. This is now the leading challenge cited, ahead of staff and budget shortages. For example, 54% also view Shadow IT or Shadow AI as a major barrier to their effectiveness.
“CISOs face so many challenges—new threats, AI-related risks, constant technological change—that it is both paradoxical and detrimental to see that internal politics remains their biggest obstacle,” summarises Maxime Pallez.
On the DPO side, the growing complexity of information systems is now the primary barrier to carrying out their responsibilities.
DORA and NIS2 will further strengthen these roles
Finally, new European regulations continue to reshape the responsibilities of CISOs and DPOs. While DORA is already largely embedded in the financial sector, NIS2—only recently transposed into Luxembourg law—is expected to extend cybersecurity requirements to several thousand organisations across the country.
This evolution also requires a shift in language. “It is no longer enough to talk about technical vulnerabilities. CISOs must be able to explain to executives what the concrete impact of an incident would be on a critical business function,” emphasises Maxime Pallez.
Ultimately, the study highlights a clear reality: CISOs and DPOs have definitively moved out of the shadows. However, for them to fully play their role in strengthening organisational resilience and enabling transformation, governance structures, resources, and ways of working will still need to evolve.
Want to know more? Take a look at the full study here: https://www.pwc.lu/en/advisory/digital-tech-impact/cyber-security/out-of-the-shadows-ciso-and-dpo-in-the-spotlight-2026.html