California and Colorado SaaS Sales Tax Changes: What Software Companies Need to Know
California and Colorado will begin taxing many SaaS transactions on January 1, 2027. Software companies should start evaluating the sales tax implications now.
As organizations adopt AI tools and rely more heavily on data, one question becomes increasingly important: Who is responsible for governing the policies, risks, and decisions that shape how that data is used?
A surprising number of leadership teams can answer detailed questions about their cybersecurity tools but struggle with a more fundamental question: Who owns cybersecurity risk? The answer often lives somewhere between IT, executive leadership, and operational teams. Everyone has a role. Accountability, however, is less defined.
For years, that arrangement has been easy to overlook. Cybersecurity discussions often focused on systems, software, and technical safeguards. Today, organizations are asking different questions. How should data be governed? Who decides whether a new AI tool can be used? What happens when sensitive information moves across platforms, vendors, and departments? Who determines whether the associated risks are acceptable?
Those are leadership questions. As artificial intelligence becomes part of everyday business operations, many organizations are discovering they have never clearly assigned ownership for answering them.
Many organizations invested in cybersecurity tools long before they established clear ownership of cybersecurity risk. For years, that was often manageable. Security discussions largely stayed within IT, and leadership’s attention naturally focused on other business priorities.
AI is changing that.
As organizations begin incorporating AI into everyday work, they become more reliant on data and more aware of how that data is collected, accessed, shared, and protected. Questions that once seemed operational are increasingly finding their way into leadership discussions.
Leadership teams may find themselves asking:
While these questions may arise in the context of AI, they point to a broader issue. They require organizations to think about governance—how decisions are made, who makes them, and how risk is evaluated when technology, data, and business objectives intersect.
That can be a challenging exercise because many organizations already have capable IT teams, trusted technology partners, and meaningful investments in security tools. Responsibilities related to cybersecurity may also extend across multiple functions. Technology leaders oversee systems and infrastructure. Compliance teams help address regulatory obligations. Department leaders influence how information is used throughout the organization. Executive leadership ultimately makes decisions about strategy, investment, and risk.
As more people become involved, ownership can become harder to define.
This matters because cybersecurity has become a business issue as much as a technology one. Decisions about data governance, privacy, access, and acceptable risk can influence customer relationships, regulatory readiness, operational resilience, and long-term growth. Organizations that establish clear ownership are often better positioned to navigate those decisions consistently as technology, regulations, and business expectations continue to evolve.
Most organizations do not ignore cybersecurity. In fact, many invest significant time, effort, and resources into managing it. Security initiatives move forward, technology decisions receive careful consideration, and risks are discussed in leadership meetings. From the outside, it can appear that ownership is well established. Yet active involvement is not always the same as clear accountability.
The challenge is that cybersecurity does not fit neatly into any single department. It touches nearly every part of the organization, which can make ownership difficult to define. When responsibility is shared broadly, leadership may assume someone is overseeing the bigger picture when, in reality, no one has been formally charged with doing so. The distinction is subtle, but significant.
Managing technology is different from managing cyber risk. A technology team may be responsible for maintaining systems, supporting users, implementing new applications, and resolving day-to-day issues. Cyber risk management requires a different perspective. It asks broader questions: How much risk is the organization willing to accept? Have the most significant exposures been identified and prioritized? Are policies keeping pace with how employees actually work? How will leadership respond if a critical vendor experiences a breach or a key system becomes unavailable?
These decisions extend beyond technology to affect operations, compliance, customer relationships, and the organization’s ability to execute its strategy.
This is one reason governance gaps often remain hidden until an organization faces a new challenge. The trigger may be an audit request, a customer security questionnaire, a cyber insurance renewal, a regulatory requirement, or the adoption of a new technology such as AI. The issue itself is rarely the problem. Instead, these moments reveal a more fundamental question: Who is responsible for evaluating the risk, making decisions, and ensuring the organization is prepared?
Organizations with clear ownership tend to answer those questions more confidently. They have someone responsible for connecting policy, risk, technology, and business objectives. Decisions are documented. Priorities are understood. Leadership has visibility into areas that require attention.
Organizations without that structure often find themselves reacting rather than planning. That does not mean every organization needs a large cybersecurity department or a full-time security executive. It does mean that cybersecurity risk deserves the same level of accountability that organizations routinely apply to other critical business functions.
Clear ownership gives cybersecurity a place to live within the organization. Decisions have a defined path. Risks can be evaluated consistently. Leadership has greater visibility into where attention and resources are needed.
That responsibility extends beyond technology. As organizations evaluate new AI tools, adopt cloud platforms, or expand the ways data is used across the business, questions arise that require both business judgment and security expertise. A leadership team may be comfortable with the expected benefits of a new technology while still needing to understand how sensitive information will be protected, whether regulatory obligations apply, and how new risks fit within the organization’s overall risk tolerance.
These are governance decisions. They shape policy, influence investment priorities, and help establish accountability around how cybersecurity risk is managed. The organizations that navigate these decisions most effectively typically have someone responsible for bringing together the operational, regulatory, and strategic dimensions of cybersecurity, so leadership can make informed decisions with a clear understanding of the implications.
Organizations approach this responsibility in different ways. Some maintain a dedicated Chief Information Security Officer (CISO). Others designate internal leadership to oversee cybersecurity governance or engage a virtual Chief Information Security Officer (vCISO) to provide strategic guidance. The structure itself is only one part of the discussion. What matters is that leadership has confidence that cybersecurity risk is being evaluated, communicated, and governed in a deliberate way.
As AI adoption continues to accelerate and data plays an increasingly central role in business operations, expectations around governance are likely to grow alongside it. Organizations that establish clear ownership today place themselves in a stronger position to adapt to new technologies, evolving regulations, and changing business requirements.
Artificial intelligence is prompting organizations to take a closer look at how data is used, protected, and governed. In many cases, that process is bringing a broader question into focus: Who is responsible for cybersecurity risk across the organization?
The answer carries implications far beyond the technology function. Cybersecurity influences customer trust, regulatory readiness, operational resilience, and strategic decision-making. Clear ownership helps organizations approach those responsibilities with greater consistency and confidence while providing leadership with the visibility needed to make informed decisions.
Technology will continue to evolve. Expectations around governance will evolve with it. Organizations that establish accountability, define ownership, and create a framework for ongoing oversight are often better equipped to manage risk while supporting long-term business objectives.
AAFCPAs helps organizations strengthen governance as they adopt artificial intelligence, automation, and other emerging technologies. Our specialists work with leadership teams to evaluate cybersecurity risk, establish policies, improve oversight, and align technology initiatives with business objectives. For organizations seeking strategic cybersecurity leadership, our Virtual Chief Information Security Officer (vCISO) services provide executive-level guidance on governance, risk management, regulatory readiness, incident response planning, and cybersecurity strategy. We also help clients implement Responsible AI practices and intelligent automation solutions that support innovation while maintaining appropriate safeguards around data, security, and compliance.
These insights were contributed by Vassilis Kontoglis, Partner, AI Digital Transformation & Security and Michael Anderson, MCSE, CCNP, CISSP, CEH, Consulting CISO & Certified Ethical Hacker.
Questions? Reach out to our authors directly or your AAFCPAs partner.
AAFCPAs offers a wealth of resources on smart automation, AI, and RPA. Subscribe to get alerts and insights in your inbox.
California and Colorado will begin taxing many SaaS transactions on January 1, 2027. Software companies should start evaluating the sales tax implications now.
The systems and processes that helped your organization reach one stage of success are not always the ones that support the next.
Beginning in 2026, eligible Massachusetts pass-through entities can elect the new Chapter 63E PTE excise. Business owners subject to the state's surtax should understand how...