CHROs should take a more active role in digital security, Gartner advises

CHROs should take a more active role in digital security, Gartner advises

Summary

Gartner urges chief human resources officers to move from a passive to an active role in digital security as HR adopts more AI and automation. The analyst firm outlines four actions CHROs should lead: make security a strategic part of HR automation, proactively identify threats, establish third-party risk management for HR tools and build a stronger culture of security across the organisation. The advice responds to a string of breaches involving HR systems and vendors — for example the 2024 ManpowerGroup ransomware incident — and a Gartner finding that many CHROs lack strong digital awareness.

Source

Source: https://www.hrdive.com/news/chros-should-take-more-active-role-in-digital-security-gartner-cybersecurity/759866/

Key Points

  • Gartner recommends CHROs embed security into HR automation strategy from the start.
  • Organisations should proactively audit threats to HR systems and AI tools; a May 2025 survey found only 43% of companies regularly audit AI tools for cybersecurity compliance.
  • CHROs must set up third-party risk management for HR vendors, working with procurement and legal to verify vendor security and data-handling practices.
  • HR has a direct role in preventing and responding to breaches through anti-phishing training, incident response planning and fast employee-facing reactions.
  • Building psychological safety so employees report security concerns is key to strengthening a culture of security.
  • Real-world breaches (e.g. ManpowerGroup) show the reputational, legal and talent risks when HR data is exposed.

Why should I read this?

Look, if you’re involved in HR you can’t treat security like someone else’s problem any more. This piece tells you exactly where CHROs should step up — from asking the right vendor questions to making staff feel safe to flag issues. Short version: read this if you want to avoid a headline that ruins your employer brand.

Context and relevance

As HR adopts AI for hiring, onboarding and workforce management, it increasingly handles sensitive personal and organisational data. Gartner’s guidance matters because it reframes digital security as an HR leadership responsibility, not solely IT’s. That shift is timely given the rise in breaches affecting HR tools and vendors and the legal, reputational and retention consequences of exposed candidate or employee data. Upskilling HR teams, partnering with IT/security/procurement and auditing AI tools align with wider industry trends around responsible AI, vendor risk management and cross-functional cybersecurity governance.

Author’s take

Punchy and practical: this is a wake-up call for CHROs. If you’re leading people strategy, you now also need to lead on how people data and automation are protected — otherwise the fallout hits talent, trust and the bottom line.

Source

Source: https://www.hrdive.com/news/chros-should-take-more-active-role-in-digital-security-gartner-cybersecurity/759866/

Leave a Reply

Your email address will not be published. Required fields are marked *