Security Magazine logo
  • Sign In
  • Create Account
  • Sign Out
  • My Account
  • NEWS
  • MANAGEMENT
  • PHYSICAL
  • CYBER
  • BLOG
  • COLUMNS
  • EXCLUSIVES
  • SECTORS
  • EVENTS
  • MEDIA
  • MORE
  • EMAG
  • SIGN UP!
cart
facebook twitter linkedin youtube
  • NEWS
  • Security Newswire
  • Technologies & Solutions
  • MANAGEMENT
  • Leadership Management
  • Enterprise Services
  • Security Education & Training
  • Logical Security
  • Security & Business Resilience
  • Profiles in Excellence
  • PHYSICAL
  • Access Management
  • Fire & Life Safety
  • Identity Management
  • Physical Security
  • Video Surveillance
  • Case Studies (Physical)
  • CYBER
  • Cybersecurity News
  • More
  • COLUMNS
  • Cyber Tactics
  • Leadership & Management
  • Security Talk
  • Career Intelligence
  • Leader to Leader
  • Cybersecurity Education & Training
  • EXCLUSIVES
  • Annual Guarding Report
  • Most Influential People in Security
  • The Security Benchmark Report
  • The Security Leadership Issue
  • Top Guard and Security Officer Companies
  • Top Cybersecurity Leaders
  • Women in Security
  • SECTORS
  • Arenas / Stadiums / Leagues / Entertainment
  • Banking/Finance/Insurance
  • Construction, Real Estate, Property Management
  • Education: K-12
  • Education: University
  • Government: Federal, State and Local
  • Hospitality & Casinos
  • Hospitals & Medical Centers
  • Infrastructure:Electric,Gas & Water
  • Ports: Sea, Land, & Air
  • Retail/Restaurants/Convenience
  • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
  • Industry Events
  • Webinars
  • Solutions by Sector
  • Security 500 Conference
  • MEDIA
  • Videos
  • Podcasts
  • Polls
  • Photo Galleries
  • Videos
  • Cybersecurity & Geopolitical Discussion
  • Ask Me Anything (AMA) Series
  • MORE
  • Call for Entries
  • Classifieds & Job Listings
  • Continuing Education
  • Newsletter
  • Sponsor Insights
  • Store
  • White Papers
  • EMAG
  • eMagazine
  • This Month's Content
  • Advertise
Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
Security Leadership and ManagementSecurity & Business ResilienceCybersecurity News

CISO's Communication Breakdown

By Dan Holden
cyber-business
August 1, 2019

The relentless bombardment of cyber-attacks, and the fear of a breach and all that entails, have led to some rather dramatic changes in the Chief Information Security Officer position recently. It has long been considered the corporate hot seat, where job security is a misnomer and the average tenure is less than two years. That may still be true for many, but changes are happening that are finally allowing the CISO to emerge from the shadows of the IT department.

There is a move away from checkbox security towards a more business-minded, risk-based approach. This is highlighted by Gartner's move away from GRC to a new category called Integrated Risk Management. This is an important step in formalizing and elevating security to a place of strategic importance.

Another thing changing for the better is structural, who the CISO reports to. It used to be that the CISO reported into the CIO, or perhaps Legal. According to the PricewaterhouseCoopers (PwC) “2018 Global State of Information Security Survey”, 67 percent of top InfoSec executives reported to the CEO or directly to the Board; a mere 24 percent reported to the CIO. This is positive change from a 2015 a study by Georgia Tech Information Security Center that reported 40 percent of CISOs reported into technical leadership.

This executive visibility is even moving beyond the CEO to the Board. In Fact, New York state recently became the first state in the nation to mandate that CISO’s present annually to the Board of Directors. This is significant because it shifts the burden of ultimate responsibility where it should be, to the Board. They can no longer claim ignorance to security issues, point fingers towards the CISO. At least not as easily as they have in the past. The question is whether the CISO has the most pertinent information that matters and can be understood by the board.

Greater executive and Board level visibility has long been the dream of the CISO. The belief was that if they only had that connection, they could explain what they were doing, translate the technical to business terms, show what the threats were and to what level they could protect the organization. The reality is that to date CISO has been unable to measure, value and report on progress in terms that are immediately meaningful to the rest of the C-Suite.

Historically, CISO’s may have shown technical metrics of vulnerabilities patched, malware blocked, and compliance reached when presenting their programs to the C-Suite and Board. This has helped to reinforce the idea that security is a technical rather than a strategic role. With their status being elevated more formally, ad hoc presentations using the same old tools is no longer acceptable.

After all, the head of sales has, well, Salesforce, Marketing has Marketo, Finance has Workday, and on and on it goes. What does the CISO have as their single source of truth? Excel and PPT? This is a gaping hole for most organizations and leaves the CISO on the outside looking in when it comes to strategic investment decisions. Security is competing with the rest of the business (e.g. marketing, sales, R&D) for limited investment. These other business functions can much more easily demonstrate valuable returns than security can using conventional approaches. This issue will become even more pronounced when the next recession hits and the C-Suite budget battles make Game of Thrones seem civil.

If the CISO cannot justify spend, or demonstrate outcomes mapped against specific levels of threats and risk tolerance, then they will find themselves struggling to justify and maintain the budget and operational progress they’ve made so far.

To date, the CISO has been at a disadvantage to all of their executive peers and that has had cascading negative consequences on the organization, starting with the security posture itself and including the security team itself. If the security team sees and feels the disconnect, they will believe they are set up for failure and will begin to look elsewhere for employment. This is especially true of top talent who are in such high demand.

The communications breakdown has been allowed to continue because the CISO was on the outside looking in. They weren’t part of the executive team. They weren’t brought before the Board. They weren’t, frankly, viewed as business executives, but technical team leaders and subscribers of budget. All of this is changing for the better.

Now that the CISO is inside the circle of trust, how do they stay there? It certainly won’t be by teaching the Board the latest NIST recommendations. It will be through their ability to translate security into business terms, helping business leadership make specific investments by unifying the security program into a holistic and calibrated business plan that helps to transcend red-tape and politics.

What’s clear today is that future success of the CISO has as much to do with meaningful measurement, visualization, and communication, as it does with preventing and controlling threats.

This article originally ran in Today’s Cybersecurity Leader, a monthly cybersecurity-focused eNewsletter for security end users, brought to you by Security Magazine. Subscribe here.

KEYWORDS: CISO cyber threats cybersecurity data breaches

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Dan holden
Dan Holden is CEO of Pharos Security.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Cybersecurity
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Cybersecurity
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    New Security Technology
    By: Charles Denyer

Recommended Content

  • Light reflecting off pool surface

    Water Safety Starts with Perimeter Access Control

    Every summer, as the temperature rises across the U.S.,...
    Fire & Life Safety
    By: Matt Welty
  • Apartment building

    Outdated Security, Overlooked Costs: Why Multifamily Properties Must Modernize Now

    Many properties still rely on brass keys, manual...
    Physical
    By: Lee Miller
  • Campus building

    Protecting 14 Campuses, All With Different Needs

    Protecting 14 campuses and learning centers is almost...
    Security Newswire
    By: Security Staff

Recommended Content

  • Light reflecting off pool surface

    Water Safety Starts with Perimeter Access Control

    Every summer, as the temperature rises across the U.S.,...
    Fire & Life Safety
    By: Matt Welty
  • Apartment building

    Outdated Security, Overlooked Costs: Why Multifamily Properties Must Modernize Now

    Many properties still rely on brass keys, manual...
    Physical
    By: Lee Miller
  • Campus building

    Protecting 14 Campuses, All With Different Needs

    Protecting 14 campuses and learning centers is almost...
    Access Management
    By: Security Staff

Recommended Content

  • Light reflecting off pool surface

    Water Safety Starts with Perimeter Access Control

    Every summer, as the temperature rises across the U.S.,...
    Physical Security
    By: Matt Welty
  • Apartment building

    Outdated Security, Overlooked Costs: Why Multifamily Properties Must Modernize Now

    Many properties still rely on brass keys, manual...
    Physical
    By: Lee Miller
  • Campus building

    Protecting 14 Campuses, All With Different Needs

    Protecting 14 campuses and learning centers is almost...
    Physical
    By: Security Staff
Subscribe For Free!
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Security’s Top 5 – 2024 Year in Review

Security’s Top 5 – 2024 Year in Review

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

Internal computer parts

Critical Software Vulnerabilities Rose 37% in 2024

Coding

AI Emerges as the Top Concern for Security Leaders

Person working on laptop

Governance in the Age of Citizen Developers and AI

patient at healthcare reception desk

Almost Half of Healthcare Breaches Involved Microsoft 365

Half open laptop

“Luigi Was Right”: A Look at the Website Sharing Data on More Than 1,000 Executives

2025 Security Benchmark banner

Events

June 24, 2025

Inside a Modern GSOC: How Anthropic Benchmarks Risk Detection Tools for Speed and Accuracy

For today's security teams, making informed decisions in the first moments of a crisis is critical.

August 27, 2025

Risk Mitigation as a Competitive Edge

In today’s volatile environment, a robust risk management strategy isn’t just a requirement—it’s a foundation for organizational resilience. From cyber threats to climate disruptions, the ability to anticipate, withstand, and adapt to disruption is becoming a hallmark of industry leaders.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • The Uncharted Path for New Security Leaders

    Hiring a CISO: The evolving role of your security executive

    See More
  • SEC1119-awareness-Feat-slide1_900px

    Enterprise Cybersecurity: Three Topics to Discuss With Your CISO

    See More
  • Person holding cellphone

    Behind the Signal leak: Vulnerabilities in high-security communication

    See More
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing

Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!