{"id":7074,"date":"2025-01-24T16:45:57","date_gmt":"2025-01-24T22:45:57","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/cisos-gaining-c-suite-swagger"},"modified":"2025-01-24T16:45:57","modified_gmt":"2025-01-24T22:45:57","slug":"cisos-are-gaining-c-suite-swagger-but-has-it-come-with-a-cost","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2025\/01\/24\/cisos-are-gaining-c-suite-swagger-but-has-it-come-with-a-cost\/","title":{"rendered":"CISOs Are Gaining C-Suite Swagger, but Has It Come With a Cost?"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blte690f7adb7821ae1\/67940b015e768623e5ebfc99\/Business_Hurdle_TongRo_Images_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cisos-are-gaining-c-suite-swagger-but-has-it-come-with-a-cost.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">After years of leaning into learning the ethos of business leadership and risk management, chief information security officers (CISOs) have gotten their seat at the boardroom table and the power to make decisions. But even so, many say their jobs are more arduous than ever, and that&#8217;s not how it was supposed to happen.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A full 82% of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.splunk.com\/en_us\/campaigns\/ciso-report.html\">CISOs who responded<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to a recent survey from Splunk said they report directly to the CEO, up from just 47% in 2023. In addition, 83% said they participate regularly in board meetings. For their part, CISOs have had to skill up in kind, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/soft-skills-every-ciso-needs-inspire-better-boardroom-relationships\">honing communications skills<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/how-cisos-communicate-boards-effectively\">learning the boardroom lingo<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> of KPIs and ROI, not to mention become more familiar with <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/what-companies-cisos-should-know-about-rising-legal-threats\">legal <\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/cisos-and-their-companies-struggle-to-comply-with-sec-disclosure-rules\">compliance<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> concerns. In other words, the scope of the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/cisos-privacy-responsibilities-keep-growing\">CISO role has expanded<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> far beyond just IT security.<\/span><\/p>\n<div readability=\"8\"><img data-recalc-dims=\"1\" decoding=\"async\" data-testid=\"content-image\" data-component=\"image\" class=\"ContentImage-Image ContentImage-Image_align_left\" data-src=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cisos-are-gaining-c-suite-swagger-but-has-it-come-with-a-cost.png\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cisos-are-gaining-c-suite-swagger-but-has-it-come-with-a-cost.png?w=640&#038;ssl=1\" loading=\"lazy\" alt=\"Chart: CISOs and boards measure success differently\" title=\"Chart: CISOs and boards measure success differently\"><\/p>\n<p class=\"ContentImage-Link\">Source: Splunk, the CISO Report 2025<\/p>\n<\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It&#8217;s a big change; for years, CISOs were relegated <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/top-infosec-execs-will-eventually-report-to-ceos-cisos-say\">further down the org chart<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, receiving mandates without any opportunity to provide context to the business. They also became the ones to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/a-cisos-guide-to-avoiding-jail-after-a-breach\">take the blame for major breaches<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, landing some in <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/joe-sullivan-former-uber-ciso-requests-new-fair-trial\">legal entanglements<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. And that status quo was leading to massive <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/cybersecurity-careers\/persistent-burnout-is-still-a-crisis-in-cybersecurity\">burnout,<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> with the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/cybersecurity-careers\/redefining-what-ciso-success-looks-like\">average CISO tenure<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> standing at just two to four years in 2020. By 2023, there was widespread consensus the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/new-ciso-rethinking-the-role\">CISO role needed a rethink<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p data-component=\"related-article\" class=\"RelatedArticle\"><span data-testid=\"related-article-title\" class=\"RelatedArticle-Title\">Related:<\/span><a class=\"RelatedArticle-RelatedContent\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/doj-multinational-dprk-it-worker-scam\" target=\"_self\" data-discover=\"true\">DoJ Busts Up Another Multinational DPRK IT Worker Scam<\/a><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Hence, more CISOs gaining a seat in the C-suite. And theoretically, putting a CISO in the middle of high-level decision making should help push the case for more cyber investment. But that hasn&#8217;t been the experience for many, who find that board buy-in is still a challenge. In fact, only 29% of the CISO survey respondents reported they have the necessary budget to keep up with the current threat environment; in contrast, 41% of non-CISO board members said they&#8217;re satisfied with cybersecurity investment levels.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In all, 53% of CISO respondents in the Splunk survey said their job has actually become &#8220;more difficult since they took the job,&#8221; seat at the table or no.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"CISOs With Board Buy-In Do Better\">CISOs With Board Buy-In Do Better<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The data also points to a clear-cut solution: Boards with members with cybersecurity backgrounds make a huge difference. Board members with CISO experience work better with cybersecurity teams on setting strategy, goal setting, and critically, budgeting.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Those results mirror the experience of Jessica Sica, CISO at software company Weave. Although she says her role reports to the chief legal officer rather than the CEO, she &#8220;regularly&#8221; meets with the whole C-team, as well as the board and audit teams. But rather than bogging her down, Sica says her relationship with leadership has made her job easier. But, she adds, Weave&#8217;s board is cybersecurity savvy.<\/span><\/p>\n<p data-component=\"related-article\" class=\"RelatedArticle\"><span data-testid=\"related-article-title\" class=\"RelatedArticle-Title\">Related:<\/span><a class=\"RelatedArticle-RelatedContent\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/war-game-pits-china-against-taiwan-cyberwar\" target=\"_self\" data-discover=\"true\">War Game Pits China Against Taiwan in All-Out Cyberwar<\/a><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;I have a very security-conscious boss, and we have a security-concerned board,&#8221; Sica says. &#8220;Having their support and voice makes it easier to get my job done.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Her experience, however, is a minority one: The survey showed only 29% of CISOs had a board with at least one cyber expert.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Progress requires CISOs to keep pushing cyber into the C-suite conversation, and boards to recognize the need to add more cybersecurity experts to their ranks, according to Michael Fanning, CISO of Splunk.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;As cybersecurity becomes increasingly central to driving business success, CISOs and their boards have more opportunities to close gaps, gain greater alignment, and better understand each other to drive digital resilience,&#8221; Fanning said in a statement. &#8220;Bringing these groups together requires educating boards on the details of cybersecurity, and for CISOs to understand the language and needs of the business while also making security a business-enabler.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/cisos-gaining-c-suite-swagger\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>After years of leaning into learning the ethos of business<\/p>\n","protected":false},"author":12,"featured_media":7075,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-7074","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cisos-are-gaining-c-suite-swagger-but-has-it-come-with-a-cost-scaled.jpg?fit=2560%2C1440&ssl=1",2560,1440,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cisos-are-gaining-c-suite-swagger-but-has-it-come-with-a-cost-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cisos-are-gaining-c-suite-swagger-but-has-it-come-with-a-cost-scaled.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cisos-are-gaining-c-suite-swagger-but-has-it-come-with-a-cost-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cisos-are-gaining-c-suite-swagger-but-has-it-come-with-a-cost-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cisos-are-gaining-c-suite-swagger-but-has-it-come-with-a-cost-scaled.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cisos-are-gaining-c-suite-swagger-but-has-it-come-with-a-cost-scaled.jpg?fit=2048%2C1152&ssl=1",2048,1152,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cisos-are-gaining-c-suite-swagger-but-has-it-come-with-a-cost-scaled.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cisos-are-gaining-c-suite-swagger-but-has-it-come-with-a-cost-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cisos-are-gaining-c-suite-swagger-but-has-it-come-with-a-cost-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/cisos-are-gaining-c-suite-swagger-but-has-it-come-with-a-cost-scaled.jpg?fit=2560%2C1440&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/7074","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=7074"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/7074\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/7075"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=7074"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=7074"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=7074"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}