<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/whatever-happened-to-the-36-month-it-security-roadmap--irlcc4n6n" -->

---
title: Whatever happened to the 36-month IT security roadmap?
description: Security leaders describe abandoning fixed multi-year security roadmaps in favor of tiered planning: long-horizon commitments (compliance, major architecture...
canonical: https://daily.dev/posts/whatever-happened-to-the-36-month-it-security-roadmap--irlcc4n6n
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Whatever happened to the 36-month IT security roadmap? | daily.dev
og:description: Security leaders describe abandoning fixed multi-year security roadmaps in favor of tiered planning: long-horizon commitments (compliance, major architecture...
og:url: https://daily.dev/posts/whatever-happened-to-the-36-month-it-security-roadmap--irlcc4n6n
og:image: https://api.daily.dev/og/posts/IRlCC4N6N.png
og:image:alt: Whatever happened to the 36-month IT security roadmap?
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Whatever happened to the 36-month IT security roadmap?

**[CSO Online](https://daily.dev/sources/csoonline)** · 8 min read · 0 upvotes · 0 comments

## Summary

Security leaders describe abandoning fixed multi-year security roadmaps in favor of tiered planning: long-horizon commitments (compliance, major architecture bets) remain stable for years, while tools and tactics are reassessed monthly, weekly, or continuously. CISOs from Insight Global, Grafana Labs, Fable Security, and AIVONS explain how rapid AI adoption, shadow AI/code, and non-human identity sprawl forced faster replanning cycles, and how they decide what belongs in long-term versus continuous review buckets. Governance is shifting from a single annual sign-off to ongoing communication with boards, who increasingly demand evidence over assurances.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.csoonline.com/article/4228518/whatever-happened-to-the-36-month-it-security-roadmap.html>

## Questions this post answers

### Why are CISOs moving away from fixed 2-3 year security roadmaps?

Rapid AI adoption, shadow AI, and shadow code created risks that shifted faster than annual planning cycles could track. Security leaders like Insight Global's John Dickson now reassess strategy quarterly rather than annually, while Grafana Labs runs weekly tactical sprints with six-week turnarounds instead of long threat-modeling engagements, keeping only compliance and major architecture bets on a multi-year horizon.

_Teams rethinking planning cadence can follow evolving security strategy debates on daily.dev._

### How do security teams decide what belongs in a long-term roadmap versus a short-term one?

Fable Security's Jacob Berry asks how many people an initiative requires and whether it ties to an existing strategic business commitment; broad, commitment-tied work gets a longer horizon while narrower work goes into continuous review. AIVONS founder Raja Chris asks whether a commitment would still hold if every vendor involved were replaced next year, since outcomes like identity and resilience endure even when the underlying technology doesn't.

_Developers and security teams weighing strategic versus tactical priorities can track this reasoning on daily.dev._

## Similar posts on daily.dev

- [In the AI Era, Cyber Defense Needs a New Playbook](https://daily.dev/posts/in-the-ai-era-cyber-defense-needs-a-new-playbook-0negqu01c) · Cisco · 0 upvotes · 0 comments
- [Beyond the checklist: Shifting from compliance frameworks to real-time risk assessments](https://daily.dev/posts/beyond-the-checklist-shifting-from-compliance-frameworks-to-real-time-risk-assessments-igdgrtd2h) · CSO Online · 0 upvotes · 0 comments
- [Cloud Security LIVE 2026: Top 10 Takeaways CISOs Can Use Now \(and What to Do Next\)](https://daily.dev/posts/cloud-security-live-2026-top-10-takeaways-cisos-can-use-now-and-what-to-do-next--nzyuoce0b) · Orca Security Blog · 0 upvotes · 0 comments
- [The one structural shift CISOs must make before AI outpaces their security strategy](https://daily.dev/posts/the-one-structural-shift-cisos-must-make-before-ai-outpaces-their-security-strategy-ln22bpl7z) · The New Stack · 0 upvotes · 0 comments
- [Gartner Security Summit 2026: Huntress 5 Key Takeaways](https://daily.dev/posts/gartner-security-summit-2026-huntress-5-key-takeaways-dcwyaiun9) · Huntress Blog · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#ai-governance](https://daily.dev/tags/ai-governance)

[View this post on daily.dev](https://daily.dev/posts/whatever-happened-to-the-36-month-it-security-roadmap--irlcc4n6n)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Whatever happened to the 36-month IT security roadmap?","url":"https://daily.dev/posts/whatever-happened-to-the-36-month-it-security-roadmap--irlcc4n6n","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/whatever-happened-to-the-36-month-it-security-roadmap--irlcc4n6n"},"datePublished":"2026-09-30T08:31:15.299Z","dateModified":"2026-09-30T08:51:45.318Z","description":"Security leaders describe abandoning fixed multi-year security roadmaps in favor of tiered planning: long-horizon commitments (compliance, major architecture...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e48be442fb514b0121f84002300e35c4?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e48be442fb514b0121f84002300e35c4?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"CSO Online","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"CSO Online","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/98667e4b5cac46cf9c470819c6cf71cd","url":"https://daily.dev/sources/csoonline"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/whatever-happened-to-the-36-month-it-security-roadmap--irlcc4n6n","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,ai-governance","timeRequired":"PT8M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"CSO Online","item":"https://daily.dev/sources/csoonline"},{"@type":"ListItem","position":3,"name":"Whatever happened to the 36-month IT security roadmap?"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/whatever-happened-to-the-36-month-it-security-roadmap--irlcc4n6n#faq","mainEntity":[{"@type":"Question","name":"Why are CISOs moving away from fixed 2-3 year security roadmaps?","acceptedAnswer":{"@type":"Answer","text":"Rapid AI adoption, shadow AI, and shadow code created risks that shifted faster than annual planning cycles could track. Security leaders like Insight Global's John Dickson now reassess strategy quarterly rather than annually, while Grafana Labs runs weekly tactical sprints with six-week turnarounds instead of long threat-modeling engagements, keeping only compliance and major architecture bets on a multi-year horizon. Teams rethinking planning cadence can follow evolving security strategy debates on daily.dev."}},{"@type":"Question","name":"How do security teams decide what belongs in a long-term roadmap versus a short-term one?","acceptedAnswer":{"@type":"Answer","text":"Fable Security's Jacob Berry asks how many people an initiative requires and whether it ties to an existing strategic business commitment; broad, commitment-tied work gets a longer horizon while narrower work goes into continuous review. AIVONS founder Raja Chris asks whether a commitment would still hold if every vendor involved were replaced next year, since outcomes like identity and resilience endure even when the underlying technology doesn't. Developers and security teams weighing strategic versus tactical priorities can track this reasoning on daily.dev."}}]}
```

