Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity NewswireSecurity Leadership and ManagementLogical SecurityCybersecurity News

CISOs respond: 49% of CISOs plan to leave role without industry action

By Jordyn Alger, Managing Editor
Man standing in front of window

Image via Unsplash

October 23, 2024

A survey from Trellix reveals key insights into the current state of the CISO role. The survey reveals expectations, challenges and responsibilities associated with the role. Furthermore, the report dives into recent changes the CISO role has seen. 91% of respondents believe the expanded expectations will cause a higher turnover rate in the CISO role, and 84% assert that the position should be divided into two roles: a technical role (CISO) and a business-oriented role (BISO). Notably, if no positive change is seen in the industry, nearly half (49%) if CISOs say they do not see themselves in a CISO role in the future. 

George Jones, Chief Information Security Officer at Critical Start, offers the following insights into how a division of responsibilities between multiple roles could be beneficial. 

“The division between a technically focused CISO and a business-focused BISO could create a more balanced leadership structure, allowing for specialized attention on critical areas. The technical role would focus on threat mitigation, incident response, and proactive defense mechanisms, while the business role would ensure cybersecurity aligns with business objectives, compliance, and risk management. This separation could streamline decision-making, as both roles could operate independently without becoming overextended, ultimately improving overall security posture and resilience,” Jones states. “The challenge, however, lies in ensuring that both roles remain in lockstep, with clear and consistent communication, so their priorities support the same strategic goals and align with the organization’s broader business objectives.

CISOs also report difficulties in board and C-level comprehension. 66% report the board does not fully understand the cybersecurity issues presented to them, and 59% of CISOs say their perspectives are not aligned with the CIO or CEO.

Jones elaborates on these challenges, saying, “There are a number of challenges in communicating cybersecurity risks to board members who may lack technical expertise. The key challenge is communicating and translating cybersecurity risks into business language that aligns with, and resonates with, the board’s priorities. These priorities typically include financial impact, operational disruption, and reputational damage. CISOs need to present cybersecurity metrics in terms of risk management and potential business outcomes. Using analogies and visual aids can help simplify these complex issues. Storytelling is also a powerful tool that allows CISOs to connect security events to real-world examples, thus making them more relatable. Building strong relationships with individual board members outside of formal meetings can further facilitate understanding and alignment on risk tolerance.

“As more boards recognize the importance of cybersecurity knowledge among their members, investing in cybersecurity education and ongoing training becomes essential to ensure they stay ahead of evolving threats and understand their potential impact on business operations. Providing board members with access to cybersecurity briefings, workshops, and industry events can help bridge the knowledge gap. Regular tabletop exercises involving the board, or debriefing them afterward, can also be effective, as they offer hands-on experience with the decision-making process required during a crisis. Additionally, establishing an advisory committee focused on technology and security can significantly elevate the board’s awareness and preparedness.”

How can CISOs manage the challenges of the role? 

Although the challenges of the role are increasing, it is still possible to save CISOs. 

To ensure future success in the CISO role, CISOs should be able to rely on team members for support. Jason Fruge, Resident CISO at XM Cyber, says, “Now more than ever, CISOs need to empower (and hold accountable) their entire chain of command so they can elevate the level at which they operate. Evaluating the CISO organizational model may be necessary to ensure the proper leadership structure and that technical leaders support the CISO in developing technical capabilities to reduce risks.

“Every CISO should strongly partner with internal and external legal counsel and participate in CISO professional information-sharing networks such as the various ISACs, which keep members apprised of relevant regulatory matters for their sector.

“Board members understand business risk quite well, and governance is the primary aspect of the board members’ role. The CISO needs to put cybersecurity risk into a business context and update the board consistently with how other risks are discussed. A good practice to make this successful is to work offline with the corporate secretary or someone similarly close to the board to review the best approach for that board. Every board is unique in its capabilities and expectations.”

Mr. Agnidipta Sarkar, Vice President CISO Advisory at ColorTokens, offers the following advice: 

“While it may be difficult for brilliant technical people to understand and expand their understanding of the business, there is a method to that madness. CISOs need to know and clearly understand what really makes their business succeed and win in the market. Once that is understood, CISOs need to determine what digital systems need to be available for the business to succeed. From there the CISOs will find it easier to navigate because it begins to get technical. So if you connect the dots and find out, for example, what digital systems make patient care succeed at a hospital, it can be the focus of a CISOs initiatives to prevent the spread of ransomware, by putting in foundational capabilities.

“There are a few strategies that I would recommend for staying ahead of cybersecurity regulations without overwhelming resources. The most important is to divide and conquer. Work closely with the General Counsel and his team to find regulatory changes that will affect the business. Also be part of CISO communities that help other CISOs to learn about new regulations. At ColorTokens, I am continuously getting updated, not only about the laws that change, but also the laws that have been proposed to be changed. 

“CISOs must educate the board members. In fact, that should be an initiative on the CISOs table, and someone should be tasked to do it. Today, there are many Saas solutions that do this too. Educating the Board is a non-negotiable if the CISOs expect the Board to understand the difference between a NAC and IAM. The other thing to do is to change the tech language. I would have a pre-read that explained all the jargon on my slide, and that would be available to all participants before the board meeting.”

KEYWORDS: CISO CISO leadership security career security career satisfaction security leaders

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Jordynalger

Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Security Leadership and Management
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Education & Training
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Paparazzi

When Private Events Become Public Infrastructure: What Celebrity OSINT Teaches Security Leaders

Broken wet floor sign

Why Response Time Is Becoming the Missing Metric in Workplace Safety and Security

People watching fireworks

Security Guard Assaulted at Firework Show

Cargo ship sailing

You Can’t Secure a Ship Like a Laptop

Medical professional

Nearly 85% of Nurses Experienced Workplace Violence in the Last Year

Kaseware sponsored webinar
Schneider Electric sponsored webinar

Events

August 19, 2026

From Investigative Question to Defensible Answer: AI in Digital Forensics and Incident Response

LIVE: August 19, 2026 at 2 PM EDT We'll examine where AI can deliver meaningful value, where incomplete context or black-box reasoning can introduce risk, and what governance, validation, and evidence-traceability controls organizations should establish.

August 25, 2026

Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • red digital screen

    CISOs plan to invest in automation in 2023

    See More
  • 5 Minutes with Marlatt

    3 Types of CISOs and How to Recognize Them

    See More
  • AI

    93% of Organizations Use or Plan to Use AI Agents for Sensitive Security Tasks

    See More

Related Products

See More Products
  • 9780367221942.jpg

    From Visual Surveillance to Internet of Things: Technology and Applications

  • Security of Information and Communication Networks

  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing