paint-brush
Who Should the CISO Report to?by@chrisray

Who Should the CISO Report to?

by Chris Ray
Chris Ray HackerNoon profile picture

Chris Ray

@chrisray

Chris Ray is a senior member of a local 35+...

January 10th, 2022
Read on Terminal Reader
Read this story in a terminal
Print this story
Read this story w/o Javascript
Read this story w/o Javascript
tldt arrow

Too Long; Didn't Read

The CISO is primarily responsible for the curation, development and execution of cyber security strategy and policy. The CEO on the other hand is focused on developing the strategy for business operations, resource allocation and the overall development of the business. Most organizations are setup to have the CISO report to the CEO or CFO, but very few are designed to have it reporting to the board. This is exactly the type of clear thinking that is needed for a business to thrive with an empowered CISO. The board of directors is a powerful group of individuals that are appropriately abstracted from the operations of a business.

Company Mentioned

Mention Thumbnail
Soapbox

Coin Mentioned

Mention Thumbnail
Maker
featured image - Who Should the CISO Report to?
1x
Read by Dr. One voice-avatar

Listen to this story

Chris Ray HackerNoon profile picture
Chris Ray

Chris Ray

@chrisray

Chris Ray is a senior member of a local 35+ B-league hockey team and also occasionally blogs about cybersecurity topics.

About @chrisray
LEARN MORE ABOUT @CHRISRAY'S
EXPERTISE AND PLACE ON THE INTERNET.

For my non-technical friends and people who are on the perimeter of tech (or even security for that matter), the question of who does the CISO report to is a not a question at all. They always espouse the standard assumption that, like the CFO, CIO, and other C-suite seats, the CISO should report to the CEO. Sometimes I will have a friend suggest the CFO, but they are just screwing with me to get a reaction....

What this tells me though is that many people do not understand the fundamental duties most CISO's carry within an organization; nor do they understand the dynamics that reporting to the CEO carries with it. To understand why the CISO reporting the CEO is sub-optimal, we need to first agree that we know what a CISO does.

The CISO is primarily responsible for the curation, development and execution of cyber security strategy and policy. That's a very vague, broad term description but it must be because it encompasses a vast area of responsibility.

Also, in some organizations the CISO is really the senior technologist, the person who knows how to select and configure security solutions. This persona confuses many people, making answering the question "who should the CISO report to" that much more difficult to answer.

The CEO on the other hand is focused on developing the strategy for business operations, resource allocation and the overall development of the business.

So now, with that defined, let us ponder the question that we are here to answer. When the CISO, who is developing plans to secure an organizations data at all stages of its lifecycle, needs to receive authorization to implement global strategy changes - should the CEO be the sole decision-maker? The same individual who is trying to optimize and grow the business? This presents a conflict, and while the assumption is that the CEO would recognize the value in secure operations or that the CISO has prepared the CEO to make a good decision, this is not often the case.

This is a simple example, but a real scenario that plays itself out quite often. Quite simply, the CISO should report to a "body" that provides direction to the CEO.

The board of directors is a common representation of this "body".

In the financial world, the board is a powerful group of individuals that are appropriately abstracted from the operations of the business. This abstraction makes it easier for risks and value to be identified, this is exactly the type of clear thinking that is needed for a business to thrive with an empowered CISO.

I will get off my soapbox now; I did not want this to sound like a rant and it is my hope that it doesn't. Most organizations are set up to have the CISO report to the CEO or CFO, very few are designed to have the CISO report to the board. I simply want to cast a vote (in the vastness of the internet) for the CISO -> Board model because sub-optimal processes drive me nuts.

L O A D I N G
. . . comments & more!

About Author

Chris Ray HackerNoon profile picture
Chris Ray@chrisray
Chris Ray is a senior member of a local 35+ B-league hockey team and also occasionally blogs about cybersecurity topics.

TOPICS

THIS ARTICLE WAS FEATURED IN...

Permanent on Arweave
Read on Terminal Reader
Read this story in a terminal
 Terminal
Read this story w/o Javascript
Read this story w/o Javascript
 Lite
Also published here
Crunchbase
Essentials
Learnrepo
Learnrepo

Mentioned in this story

coins
companies
X REMOVE AD