{"id":2397,"date":"2024-01-19T18:05:00","date_gmt":"2024-01-19T18:05:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-operations\/cisos-struggle-csuite-status-expectations-skyrocket"},"modified":"2024-01-19T18:05:00","modified_gmt":"2024-01-19T18:05:00","slug":"cisos-struggle-for-c-suite-status-even-as-expectations-skyrocket","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/01\/19\/cisos-struggle-for-c-suite-status-even-as-expectations-skyrocket\/","title":{"rendered":"CISOs Struggle for C-Suite Status Even as Expectations Skyrocket"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltc1a0276e623f6a44\/65aaa12fbc4376040a01422c\/ciso_Zhanna_Hapanovich_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/cisos-struggle-for-c-suite-status-even-as-expectations-skyrocket.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/cisos-struggle-for-c-suite-status-even-as-expectations-skyrocket.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">CISOs are increasingly being asked to assume the responsibilities of what would normally be considered a C-suite role, but without being regarded or treated as such at many organizations, a new survey of 663 security executives has shown.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The survey was conducted by IANS in collaboration with Artico Search, and polled CISOs on a variety of issues related to their jobs, their responsibilities, management support and other topics.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A full 75% of them said they are looking for a job change.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Expectations for the CISO Role Have Changed<\/span><\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The responses showed that expectations for the CISO role have changed dramatically at public and private sector organizations because, among other things, of increased scrutiny from regulators, and growing demands for accountability for security breaches.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As an example, the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.iansresearch.com\/resources\/infosec-content-downloads\/research-reports\/2023-2024-state-of-the-ciso-benchmark-report\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">survey report<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> pointed to rules like those adopted by the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.sec.gov\/files\/rules\/final\/2023\/33-11216.pdf\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Securities and Exchange Commission<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> (SEC) last July that require publicly traded companies to report all material security incidents within four days of the incident happening. Another example is the New York State Department of Financial Services (NYDFS) issuing <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.dfs.ny.gov\/system\/files\/documents\/2023\/12\/rf23_nycrr_part_500_amend02_20231101.pdf\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">new cybersecurity requirements<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> for financial services companies.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Regulators now hold&nbsp;CISOs&nbsp;accountable for transparency and even fraud on behalf of their organizations,&#8221; the IANS and Artico report said. There is a growing expectation that the CISO will primarily serve as a business risk-management function, with a clear voice at executive leadership meetings and a direct line of communication with the CEO and C-suite. Yet, &#8220;despite the role expectations being elevated to C-Level,&nbsp;CISOs&nbsp;struggle to be viewed as such, and the&nbsp;CISO&nbsp;role is frequently not part of the senior leadership team.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The survey showed for example that while more than 63% of CISOs have a vice president or director-level position, only 20% are at the C-suite level despite having &#8220;chief&#8221; in their title. In the case of organizations with revenues of more than $1 billion, that number is even smaller, at 15%. From a reporting standpoint, a troubling 90% of CISOs are at least two or more organizational levels removed from the CEO and C-suite. Just 50% engage with their company&#8217;s board on a quarterly basis. A quarter engage with the board just once or twice per year, 12% meet the board purely on an ad hoc basis, and 13% report having no contact with the board at all.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">A Lack of Guidance for CISO Responsibility<\/span><\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In many instances, CISOs who want clear risk guidance from their board don&#8217;t get it. Barely more than one-third (36%) described their board as offering them clear enough insight into their organization&#8217;s risk tolerance levels for them to act upon.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The evolution of the&nbsp;CISO&nbsp;role over the past few years has accelerated dramatically,&#8221; says Nick Kakolowski, research director at IANS. With organizations digitizing more of their operations, CISOs are taking on more responsibilities and have become de facto owners of digital risk, he says. &#8220;[But] organizations haven&#8217;t figured out how to support and empower them as the scope of the role grows.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Concerns have been growing within the CISO community in recent years about the escalating expectations around the role, even as their ability to meet those expectations has remained largely unchanged. Incidents like one last October where the SEC charged SolarWinds CISO Tim Brown with <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/sec-charges-against-solarwinds-ciso-send-shockwaves-through-security-ranks\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">fraud and internal control failures<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> over the 2020 breach at the company, and where a judge <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/judge-spares-former-uber-ciso-jail-time-over-2016-data-breach-charges\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">sentenced former Uber CISO Joe Sullivan<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to three years of probation over a 2016 breach, have fueled those concerns. While there is some debate about whether the actions against the security executives in these incidents were justified, many have argued that it is unfair to hold them alone accountable for the breaches.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Historical Bias Against Security As a C-Level Function<\/span><\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One of the reasons why many organizations still don&#8217;t perceive the CISOs role as belonging in the C-suite is historical bias, Kakolowski says. &#8220;CISOs&nbsp;tend to be perceived \u2014 often unfairly \u2014 as techies who can&#8217;t speak the business&#8217; language,&#8221; he says, adding that they often tend to get siloed when it comes to skills development. Efforts there often tend to focus on technical capabilities and team leadership, rather than on executive skills development.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Some of it is also inertia. Large, complex organizations take time to adjust to new challenges and organizational shifts.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The biggest challenge is the struggle to find alignment between the&nbsp;CISOs&nbsp;and the rest of the C-suite,&#8221; Kakolowski says. &#8220;Business leaders are beginning to become aware of the risk of underutilizing&nbsp;CISOs&nbsp;as business executives, and there&#8217;s an opportunity for&nbsp;CISOs&nbsp;to demonstrate their ability to offer value to the organization beyond the back office.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Elevating the CISO role to where it belongs, in the C-suite, can have many benefits, Kakolowski argues. Being part of top management gives CISO better awareness and visibility into where the organization is going, and makes it easier for them to collaborate with other stakeholders on digital risk-management.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;It positions the&nbsp;CISO&nbsp;to get ahead of risk, thereby reducing the friction that may come when mitigating risks,&#8221; he notes.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/cisos-struggle-csuite-status-expectations-skyrocket\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CISOs are increasingly being asked to assume the responsibilities of<\/p>\n","protected":false},"author":12,"featured_media":2398,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2397","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/cisos-struggle-for-c-suite-status-even-as-expectations-skyrocket.jpg?fit=1000%2C584&ssl=1",1000,584,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/cisos-struggle-for-c-suite-status-even-as-expectations-skyrocket.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/cisos-struggle-for-c-suite-status-even-as-expectations-skyrocket.jpg?fit=300%2C175&ssl=1",300,175,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/cisos-struggle-for-c-suite-status-even-as-expectations-skyrocket.jpg?fit=640%2C374&ssl=1",640,374,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/cisos-struggle-for-c-suite-status-even-as-expectations-skyrocket.jpg?fit=640%2C374&ssl=1",640,374,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/cisos-struggle-for-c-suite-status-even-as-expectations-skyrocket.jpg?fit=1000%2C584&ssl=1",1000,584,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/cisos-struggle-for-c-suite-status-even-as-expectations-skyrocket.jpg?fit=1000%2C584&ssl=1",1000,584,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/cisos-struggle-for-c-suite-status-even-as-expectations-skyrocket.jpg?fit=1000%2C584&ssl=1",1000,584,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/cisos-struggle-for-c-suite-status-even-as-expectations-skyrocket.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/cisos-struggle-for-c-suite-status-even-as-expectations-skyrocket.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/01\/cisos-struggle-for-c-suite-status-even-as-expectations-skyrocket.jpg?fit=1000%2C584&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2397","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2397"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2397\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2398"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2397"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2397"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2397"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}