CHROs Urged to Take Charge of Cybersecurity Amid Digital Shift
As artificial intelligence and automation continue to reshape human resources operations, Gartner is urging Chief Human Resources Officers (CHROs) to step up and play a more proactive role in digital security. A recent report from the research and advisory firm highlights the vital role HR leaders must take in safeguarding organizational data and maintaining trust in HR systems.
According to Gartner’s findings, many HR executives lack the digital fluency necessary to guide their teams through AI-driven transformations. “Many CHROs do not have strong digital awareness and are struggling to lead and influence AI and digital transformation,” said Emi Chiba, a senior principal analyst in Gartner’s HR practice. This gap in digital leadership can leave HR departments vulnerable to significant cybersecurity threats.
Strategic Security Integration in HR Automation
Gartner recommends that CHROs embed cybersecurity considerations into every stage of their automation and AI strategies. This includes not only purchasing decisions but also ongoing management of digital tools. As more HR processes—from hiring and onboarding to benefits administration—rely on technology, ensuring these systems are secure becomes a business imperative.
For example, AI-driven recruiting platforms collect sensitive applicant information. A breach in such a system could expose personal data, lead to legal complications, and damage the employer brand. “When data breaches occur, there are massive implications on talent, including the risk to the employment brand and intellectual property theft,” Chiba noted.
Proactive Threat Identification and Risk Management
One of the core actions Gartner advises is the proactive identification of digital threats. HR departments should conduct regular audits of the AI and automation tools they use, ensuring compliance with cybersecurity policies. However, this is not yet standard practice. In a May 2025 survey of 300 cybersecurity leaders, only 43% reported their organizations regularly audit AI tools for security compliance.
To address this, HR must collaborate closely with IT, security, and vendor management teams. Joint efforts are necessary to assess vulnerabilities and develop protocols for managing risks associated with third-party vendors.
Third-Party Risk in HR Technology
Third-party tools are a significant part of modern HR infrastructure. From payroll software to performance management platforms, these vendors often have access to sensitive employee information. Gartner emphasizes the importance of establishing third-party risk management strategies within HR functions. CHROs should work with procurement and legal teams to vet vendors, review security certifications, and ensure proper handling of personal data.
Recent incidents underscore the importance of such vigilance. In December 2024, ManpowerGroup experienced a data breach at a Michigan franchise. Hackers reportedly accessed files containing Social Security numbers, passports, and other sensitive documents. This breach highlights how lapses in vendor security can have far-reaching impacts on both individuals and the organizations involved.
Building a Culture of Security
Beyond technical measures, Gartner stresses the need for CHROs to foster a culture of cybersecurity awareness across the workforce. This involves training employees to recognize phishing attempts, encouraging them to report suspicious activity, and supporting a psychologically safe environment where concerns can be voiced without fear.
“Employees who feel safe to speak up are more likely to identify and report potential threats,” the report says. This cultural approach ensures that cybersecurity becomes a shared responsibility, not just the domain of IT professionals.
HR’s Expanding Role in Cybersecurity Preparedness
Experts agree that cybersecurity is no longer confined to the IT department. HR leaders must contribute by preparing the workforce through training programs, incident response planning, and rapid action protocols when breaches occur. In doing so, HR serves as the bridge between technology and people, ensuring that digital tools enhance rather than compromise organizational integrity.
By becoming digitally fluent and actively engaging in security strategies, CHROs can better protect employee data, support organizational resilience, and drive trust in emerging technologies used across HR functions.
This article is inspired by content from Original Source. It has been rephrased for originality. Images are credited to the original source.





