When Cyber Risk Becomes Enterprise Risk, Whose Job Did It Just Become?
Integrated risk management reached mainstream adoption this month. The discipline itself is not new. When the IRM category was defined in 2016, leading organizations were already managing cyber, technology, and operational risk as a single enterprise concern owned at the top. What was missing for the past decade was broad adoption. That gap is now closing in plain view. Rating agencies are pricing security governance into credit. Regulators are addressing corporate leaders directly rather than their security teams. And enterprise research now documents boards accepting accountability for exposures that used to live three levels down in a technology function.
Two publications captured the shift in the same week, without citing each other. On July 8, Cybersecurity Dive reported on new research from Information Services Group showing that U.S. enterprises are folding cyber risk into their overall enterprise risk strategy, with boards and C-suites taking direct accountability for business continuity, financial exposure, and regulatory compliance. One day later, Harvard Business Review published an argument that lands like a rebuttal to every executive hoping that accountability might live somewhere else: you can outsource the AI, but the risk stays with you.
Read together, the two describe a structural shift that most risk programs are not built for. The technology that creates the exposure is moving outside the enterprise. The accountability for that exposure is moving up and inside it. The distance between those two movements is the story.
The Convergence Is No Longer a Prediction
The ISG findings will sound familiar to anyone who has followed the integrated risk management thesis over the past decade. Cybersecurity spending decisions are merging with overall IT strategy. CISOs and CIOs are partnering with boards to shape business decisions rather than defending a standalone budget line. Jason Stading, ISG's cybersecurity director, described security as "a core business consideration rather than a standalone technology function."
That sentence could have appeared in the research note that defined the IRM category in 2016. The practice it describes existed then too, inside the organizations furthest ahead. What changed is the denominator. In 2016, integrated risk was how the leaders operated. In 2026, it is how U.S. enterprises at large tell a research firm they operate.
The external pressure is specific. S&P warned in June that weak internal security governance could affect a company's credit rating. UK authorities have pressed corporate leaders, not their security teams, to treat cyber risk as business strategy while attacks on critical infrastructure climb. When rating agencies, regulators, and enterprise buyers converge on the same expectation within weeks of each other, the question of whether cyber belongs in enterprise risk is settled. The open question is who inside the enterprise now owns it.
The Ownership Answer Nobody Wanted
This is where the HBR piece gets uncomfortable, and useful. Writing from Harvard Kennedy School's Mossavar-Rahmani Center, M. Alejandra Parra-Orlandoni and Paulo Carvão examined what happens when third party AI systems discriminate, mishandle data, or harm customers. The pattern across recent litigation involving Peloton, iTutorGroup, Workday, and Cigna is consistent: courts and regulators pursue the organization closest to the end user, not the company that built the model.
The deployer owns the outcome. Full stop. It does not matter that the model was trained elsewhere, that its inner workings are opaque to the buyer, or that the vendor's contract disclaims everything a lawyer could think to disclaim. The enterprise that put the system in front of a customer answers for what the system does.
The authors identify four exposures that most organizations manage poorly: opacity in upstream models, liability triggered by the buyer's own customization, dependence on vendors that are hard to replace, and regulatory demands that fragment across jurisdictions. Notice what those four have in common. None of them is a cybersecurity problem in the traditional sense. They are governance problems, procurement problems, resilience problems, and compliance problems. They cut across every domain a risk function touches, which is precisely why a standalone function cannot hold them.
An Answer Frameworks Cannot Give
So whose job did it just become? The honest answer is that it became everyone's, which in most organizations means it became no one's. Boards accepted accountability in principle. Litigation assigned it in practice. What sits between those two facts, in most enterprises, is a set of disconnected programs that were never designed to give a board a single, defensible view of exposure it now legally owns.
HBR's prescription is to anchor compliance in frameworks like the NIST AI RMF or ISO/IEC 42001, alongside stronger contracts and portability planning. Those are sound controls, and organizations should adopt them. But a framework tells an enterprise what good looks like. It does not tell an enterprise how to build the operating capability that connects board accountability to the systems, vendors, and decisions where the risk actually lives. Frameworks exist in abundance. Operating models that make ownership real are what most organizations lack.
That is the work in front of risk leaders for the rest of this decade. The convergence ISG documented is accountability moving to the top of the enterprise. The liability pattern HBR documented is exposure moving outside of it. Closing that gap requires an integrated architecture, one that treats performance, resilience, assurance, and compliance as connected disciplines rather than separate departments. The IRM Navigator Model from Wheelhouse Advisors maps that architecture. The market signals from a single week in July explain why boards no longer have the option of ignoring it.
The job became the board's. The build became everyone else's.