Opens in a new tab
vmblog logo 2024 wht (updated)

Why Enterprise Security Teams Must Adopt Federated Authority in 2026

Share: 

David Marshall | Published: February 5, 2026

By Josh Lemos, CISO at GitLab

Enterprise security teams face an impossible scaling challenge. As AI systems leverage enterprise data at unprecedented scale and attack surfaces grow exponentially, centralized security models are reaching their operational limits. The traditional approach of routing every security decision through a central team creates bottlenecks that slow business velocity without meaningfully reducing risk. 

Tactical responses like hiring more security staff, purchasing additional tools, or extending work hours cannot solve this fundamental scaling problem. At enterprise scale, these approaches fail to address the core issue: centralized security authority cannot keep pace with, or match the complexity of modern business operations. 

The organizations that will succeed in managing security at scale are those implementing federated governance models now. In this approach, CISOs set enterprise-wide policy and risk strategy, while data owners and technical teams own security implementation within their respective business units. This distribution of authority allows technical teams to apply policies with greater flexibility so they can adjust implementation details and specific controls to better achieve policy objectives. 

Three strategic advantages of federated security 

Traditional security models require CISOs to be experts for various business units servicing different audiences, each requiring a deep contextual understanding of the challenges. In contrast, organizations that implement federated security models will realize immediate benefits: 

Context-aware security decisions reduce friction and accelerate delivery. Security decisions happen faster when stakeholders make them with direct context and expertise. Service and application owners understand the specific risk profiles, regulatory requirements, and operational constraints of their domains. Delegated authority allows companies to seize market opportunities, deploy new tools, and reduce or eliminate escalations and delays. 

Flexible policy frameworks enable smarter technology adoption. When governance is delegated to business units, security teams can evaluate how a new technology’s attack surface impacts their unique risk profile and establish controls based on their data classifications and regulatory constraints. CISOs maintain responsibility for organizational standards while their technical partners in the business own implementation. The partnership approach ensures policies strike the right balance for productive adoption and avoid overly strict or broad security controls. 

Scalable security structures support organizational growth. Acquisitions, new product launches, or geographic expansions create new challenges that often exceed the capacities of centralized teams. Organizations must decide which security functions benefit from centralization and which should be federated to business units. For example, identity and data governance are domains in security that federate well with the support of centralized technology platforms. Business units can manage, delegate, and provision access autonomously while operating within the enterprise frameworks. This delivers velocity while enabling security programs to scale. 

Making the transition to federated security 

Successfully transitioning to federated security requires organizational commitment and cultural adaptation. It won’t be easy, but the payoffs are too great to ignore. Security ownership becomes shared responsibility, with CISOs and business unit leaders operating as partners to ensure smooth policy adoption. 

CISOs must establish standards and policies that account for the operational realities of modern technology stacks. Policies oriented around forced compliance will be less successful than policies designed to encourage adoption and make it easy. Business unit partners must ensure their control structures are appropriate for the sensitivity and classification of the data they manage. 

In practice, that might look like a CISO setting data classification standards, while partner teams are responsible for implementing these standards as a set of low-friction security policies and capabilities at the source of record for the data. 

Netflix’s security team’s “Paved Roads” philosophy is an example of this. They achieved policy adoption success by building secure options that meet policy guidelines and making them the easiest ones for developers to use. 

Beyond engineering, enterprise-wide standards also need to offer sufficient flexibility to remain relevant to each business unit. Self-service risk exception processes allow for special circumstances that consider business context and impact, so security doesn’t hinder business unit functions. 

Federation delivers stronger security ROI 

Boards and executive leadership increasingly evaluate security investments based on their ability to mitigate risk while advancing broader business objectives. For enterprise CISOs, this requires demonstrating that risk mitigation investments deliver returns commensurate with their costs. 

Federated security models give CISOs visibility across organizational risks and threats while empowering business units to implement security measures appropriate to their contexts. This approach delivers the impact leadership craves by eliminating bottlenecks, accelerating the adoption of secure technology, and enabling security teams to focus on enterprise-wide threats rather than getting bogged down in approvals. 

As AI systems become increasingly autonomous and interconnected, the attack surfaces they create will exceed any centralized team’s capacity to govern effectively. Federation will become a necessity in 2026. It will also reshape how enterprises organize, budget for, and execute security. The strategic advantage will belong to organizations that adopt federated security models and embrace a more collaborative security culture. Those that do will find security becomes a business enabler rather than an impediment to growth.

##

ABOUT THE AUTHOR

Josh Lemos 

Josh Lemos is the Chief Information Security Officer at GitLab Inc., where he brings 20 years of experience leading information security teams to his role. He is responsible for establishing and maintaining the enterprise vision, strategy, and program to ensure information assets and technologies are adequately protected, fortifying the Gitlab DevSecOps platform and ensuring the highest level of security for customers.

A talented security practitioner and technology leader, Josh is widely recognized for his strategic vision, his ability to drive growth and innovation, and his passion for building and empowering teams. He believes in technology’s potential to transform the world and the need to secure it against emerging threats. Josh has led security teams at numerous high-growth technology companies including ServiceNow, Cylance, and most recently Block (formerly known as Square).

Josh’s commitment to securing technologies to make a positive impact in the world has been a common thread throughout his career. He serves as a mentor to aspiring information security professionals, and is active in supporting organizations that promote diversity and inclusion in the technology industry. Josh holds a B.S. in Computer and Information Systems Security from the University of San Francisco.