Top Risk Focus: Cyber Threats and AI Risk in Enterprise Risk Management
Exploring executive perspectives on cybersecurity, generative AI, and talent gaps.
Cybersecurity and AI-related risks are among the most urgent issues shaping enterprise risk management today. In the 2025 Executive Perspectives on Top Risks report, authored by NC State’s ERM Initiative in partnership with Protiviti, these risk themes dominate the near-term outlook:
- #2: Cyber threats
- #9: Adoption of AI and emerging technologies requiring new skills
- #10: Emergence of new risks from implementing AI
This risk cluster reflects how artificial intelligence (AI) is both a performance accelerator and a risk amplifier. While organizations are leveraging AI for threat detection, automation, and decision-making, they are also encountering new challenges—ranging from governance gaps to AI-powered cyberattacks.
Why This Risk Is Rising in 2025
Senior executives and board members across industries are reporting growing concern over this risk category, fueled by:
- The growing use of generative AI in cyberattacks, including deepfakes and synthetic phishing
- Vulnerabilities introduced by third-party AI applications and shadow tech adoption
- Inadequate AI governance frameworks across departments
- Difficulty in finding and developing AI-fluent risk and security talent
- Rising regulatory scrutiny around algorithmic transparency, data privacy, and cross-border AI compliance
These insights are drawn directly from the 2025 Top Risks Survey, which includes perspectives from board members and C-suite executives across a broad range of industries and geographies.
Managing Cybersecurity & AI Risk in ERM Programs
To effectively manage this evolving category of risk, organizations should:
- Conduct a cross-functional inventory of AI use cases across business units
- Expand their cybersecurity posture to reflect AI-specific threats
- Update risk assessment tools to incorporate AI-driven impact
- Ensure clear governance frameworks for AI adoption, use, and monitoring
- Align ERM, IT, Compliance, and Strategic Planning teams in ongoing dialogue
These responses require collaboration at the leadership level—and a willingness to revisit assumptions about both risk ownership and mitigation strategy.
5 Questions to Guide a Leadership Conversation on Cyber & AI Risk
Use this tool to initiate a meaningful discussion with your executive team, board, or risk committee:
- How is AI currently being used in our organization—and what risks are emerging from those applications?
- Do we have visibility into all models and tools in use across departments?
- What controls are in place to manage third-party cybersecurity and AI-related risks across our ecosystem?
- When was our last assessment or simulation?
- How are we developing the skills and capabilities needed to manage AI-enabled threats?
- Are we hiring or upskilling for emerging risk roles?
- Do we have a governance framework that guides how AI is used, monitored, and evaluated across the enterprise?
- Does it address data use, algorithmic bias, and accountability?
- How often are we updating our cyber and AI risk scenarios—and are those response plans tested?
- Have we conducted tabletop exercises or red teaming?
These leadership questions reflect themes surfaced in executive conversations across industries, including in survey results collected by the ERM Initiative.
About the Experts Behind the Report
This article is based on insights from the 2025 Executive Perspectives on Top Risks Report, authored by:
- Mark S. Beasley, PhD – Director, ERM Initiative; Alan T. Dickson Distinguished Professor of Accounting
- Bruce C. Branson, PhD – Associate Director, ERM Initiative; Professor of Accounting
- Donald P. Pagach, PhD – Director of Research, ERM Initiative; Professor of Accounting
The report was developed by the ERM Initiative at NC State University’s Poole College of Management, in collaboration with global consulting firm Protiviti.
The NC State ERM Initiative is a leading source of applied research and executive guidance on risk management, strategy, and resilience.
Subscribe to ERM Insights
The latest research, insights and opportunities from the NC State ERM Initiative to help you and your organization lead with confidence.
- Types: