Do CISOs Want to Split Their Role

Do CISOs Want to Split Their Role

A recent report by Trellix indicated that due to growing complexity, responsibility, and regulatory accountability, a majority of CISOs believe their role should be split into separate positions.

This finding struck me as a little odd. It seems counterintuitive that CISOs really want their role split between technical aspects and cyber risk leadership?

I cannot image this tactic been successful. First, nobody wants to add more C-level execs. That just complicates leadership circles. Secondly, the risk leadership role needs direct oversight of technical protective aspects, compliance, and behavior/policy, to properly understand and manage overall cyber risks.

I do however believe that depending on the size and complexity of the environment, the technical role should be a reporting function into the CISO. This is also true of other domains like GRC, threat intelligence, risks quantification, and perhaps even privacy!

I don’t see a positive outcome if any of these roles are separated from an existing CISOs oversight. It should not be a split, rather a purposefully designed hierarchical structure under the CISO that will make leader more capable and effective in navigating and steering the risks seas.

E-mail me when people leave their comments –

CISO and Cybersecurity Strategist

You need to be a member of CISO Platform to add comments!

Join CISO Platform

CISO Platform

A global community of 5K+ Senior IT Security executives and 40K+ subscribers with the vision of meaningful collaboration, knowledge, and intelligence sharing to fight the growing cyber security threats.

Join CISO Community Share Your Knowledge (Post A Blog)
 

 

 

Fireside Chat On Top Trends In Cybersecurity 2025 & Beyond

  • Description:

    We are hosting an exclusive Fireside Chat session on "Top Trends In Cybersecurity 2025 & Beyond" featuring Ravi Subbiah (CISO Consulting and Cybersecurity Delivery Leader at TCS) &  Vijay Kumar Verma (SVP & Head Cyber Security Engineering at Jio).

    The fast-paced evolution of cybersecurity is redefining priorities and pushing organizations to stay ahead of emerging challenges. This session offers a closer look at the…

  • Created by: Biswajit Banerjee