What CISOs Told Me About Their 2027 Budgets (And What Should Worry Their Boards)

Blog Author Img
Karen Letain
Subscribe

Get reasoning, in your inbox.

Threat research and field notes from inside customer inboxes. Twice a month, no spam, unsubscribe anytime.

Blog Main Img

Ten mid-market CISOs. A July CISO Peer Group. One question on the table: how are you measuring AI security ROI in 2027?

What they told me was not what I expected.

Their 2027 focus is agent security. Non-human identity. Just-in-time access. Every dollar they can pull loose is going toward getting a handle on the AI tools their employees are already using, sanctioned or otherwise.

When I asked about email specifically, the answers were remarkably similar. Legacy. Not great. Not the focus for us today.

The problem is that most of the actual risk still comes through email. And the agents they are spending 2027 dollars to secure are the ones reading the inbox nobody is defending.

Here are five patterns from the conversation, and what I think they mean.

1. The mismatch is real, and it is widening

Agent security and identity own the 2027 mental model. Every CISO in the room named agent sprawl as a top-three concern for next year. Shadow copilots, MCP-connected assistants, procurement tools that started as agents-of-one and turned into agents-of-many.

Email got a shrug. The word I heard most often was "legacy." As in, we have something, it does something, we are not thinking about it.

Meanwhile the numbers have not moved in the direction CISOs would need for email to be a solved problem. The human element sits behind 62 percent of breaches in the 2026 Verizon DBIR, and most of that human element runs through the inbox. AI-generated phishing gets a 54 percent click rate compared to 12 percent for human-written (Microsoft 2025 Digital Defense Report). The attention has moved. The attack surface has not.

The insight: attention has drifted away from where attackers still live. The gap between where CISOs are spending mindshare and where breaches actually originate is 2027's most under-discussed risk.

2. Why the mismatch happened

Legacy email security did its job well enough, for long enough, to become invisible. Nobody gets promoted for fixing something that is not obviously broken. And a SEG that catches obvious spam and matches known-bad domains looks like it is working, right up until the moment an AI-generated wire-transfer request slides past it with perfect authentication.

Agents feel new. They feel urgent. They feel unbounded. Attention follows novelty. Budgets follow attention.

None of that is irrational. It is just incomplete.

The insight: legacy tooling that quietly stops working is a more dangerous failure mode than tooling that visibly falls behind. CISOs know how to defend a budget line for something new. They struggle to defend a budget line for something they thought was already handled.

3. Agents do not exist in a vacuum

Every one of the anchor prompt-injection cases from the last twelve months ran through email. EchoLeak, the zero-click vulnerability in Microsoft 365 Copilot, was triggered by a poisoned email. HackerOne reports prompt-injection submissions up 540 percent year over year, and the fastest-growing subcategory is instructions hidden in email bodies, attachments, and headers.

The inbox is where agents get their most dangerous inputs. Every agent with access to email is one poisoned message away from doing something its principal never intended. You cannot secure agents while ignoring the surface that feeds them.

The insight: the agent security problem and the email security problem are the same problem. Treating them as separate budget lines is how organizations end up spending on one and getting breached through the other.

4. The propriety gap runs through the inbox

At Black Hat this year, a closed-door session I sat in on landed on a phrase that has stuck with me. The propriety gap. The distance between what an agent can do and what it should do.

The example that opened the room: a deputy CISO had temporary eDiscovery access for an unrelated investigation. Later, on a different task, they pointed an MCP-connected assistant at their environment. The assistant correctly reasoned that eDiscovery permissions were available and used them to read cross-org email. Not because the agent was malicious. Because the agent did what it could do, not what it should have done.

Agent-era access controls are the tools CISOs are asking for: just-in-time access, non-human identity, mediation layers. Every one of them is important.

Every one of them also fails immediately when the agent's inputs come from an inbox nobody is mediating. A valet key starts your car and opens the door. It does not open the trunk or the glovebox. That is the model for agent access: scoped credentials, not master ones. But the most beautifully scoped valet key in the world will still start the car for whoever asks nicely in a poisoned email.

The insight: agent access control without inbox mediation is a lock on the front door of a house with no walls.

5. What the winning vendors will do in 2027

Position at the intersection. Not email security. Not agent security. The surface where they meet.

The vendors making 2027 shortlists will be the ones who can show a CISO, in the first meeting, why their agent investments are undermined by their email deprioritization. Not as a scare tactic. As a math problem. Here is what you are spending on agent security. Here is the input surface you are leaving open. Here is what that costs in expected loss.

The CISOs I talked to are smart. They will move fast when the connection is made clearly. They are not resistant to the argument. They just have not heard it framed this way yet.

The insight: 2027 belongs to vendors who help CISOs see the seam between the two conversations they are having in separate rooms, and to buyers who are willing to look at both at once.

What this means: CISOs are optimizing for the AI security narrative. Attackers are still exploiting the AI security reality.

If the boards of the companies represented in that room could see the gap between where their CISOs are spending 2027 dollars and where the actual breach vector still sits, they would ask the same question. Are we defending the surface attackers are using, or the surface we find more interesting to talk about?

That is the conversation the market needs to be having for the next six months.

Final Thoughts

The 2027 security conversation is moving toward agents, non-human identities, just-in-time access, and increasingly autonomous systems. That shift makes sense. The problem is what happens when organizations secure the agent but overlook the input that can influence it.

Email remains one of the most important paths into the enterprise. If an AI agent can read the inbox, then email is no longer just an employee-facing communication channel. It is part of the agent's attack surface.

That is the gap CISOs should be closing.

The goal isn't to choose between agent security and email security. It is to recognize that they are becoming part of the same security problem. Scoped permissions, non-human identities, and mediation layers matter—but they cannot fully compensate for an unmediated source of potentially malicious input.

The organizations that get ahead in 2027 will be the ones that stop treating these as two separate conversations.

Secure the agent. Secure the input. Secure the connection between them.

Frequently Asked Questions

Q1: Why is email still important if organizations are investing heavily in AI security?

Because AI agents increasingly consume information from email. If the inbox remains an under-defended input surface, investments in agent security can leave a critical part of the attack chain exposed.

Q2: Why are CISOs prioritizing agent security in 2027?

The article's CISO discussion points to growing concerns around agent sprawl, non-human identities, just-in-time access, and the AI tools employees are already using across the organization.

Q3: What is the connection between agent security and email security?

Email can provide the input that an AI agent consumes. If that input can influence an agent's behavior, securing the agent without securing the inbox leaves a gap between the two controls.

Q4: What is the “propriety gap”?

The propriety gap is the distance between what an agent can do and what it should do. An agent may have legitimate permissions and still perform an inappropriate action because those permissions are broader than the actual task requires.

Q5: Are scoped agent permissions enough?

No. Scoped access is an important control, but the article's argument is that an agent can still misuse legitimate access when its inputs are manipulated. A well-scoped permission can limit impact, but it does not solve the problem of malicious input.

Q6: What should organizations do about the gap between email and AI security?

Treat them as connected security surfaces. Organizations should understand which agents consume email, what those agents can access, how their actions are controlled, and where the inbox is being mediated before information reaches an agent.

Q7: What does this mean for 2027 security budgets?

The issue is not simply spending more on AI security. The article argues for looking at whether the areas receiving investment are actually connected to the surfaces attackers can still exploit—and whether email has been incorrectly treated as a solved or “legacy” problem.

Q8: What should boards be asking their CISOs?

A useful question is: Are we securing the surfaces attackers are using, or the surfaces that are currently getting the most attention? That gets directly to the budget mismatch at the heart of the article.

Subscribe to Our Newsletters!

Be the first to get exclusive offers and the latest news

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Talk To Us

Your gateway can't see
what's already inside.

Deploy in minutes, not months. Zero tuning. See what your current tools are missing.