A Chief Information Security Officer, or commonly referred to as the CISO, leads the cybersecurity effort at an organization. This often includes leading the team and the associated security program. As cybersecurity itself can be a very nebulous concept, so to is the critical role that is responsible for it at an organization. Let’s take a closer look at this important organizational leader, starting with the most critical aspect of the role.
Most Important CISO Consideration
Before diving into what a Chief Information Security Officer does, it’s important to understand the most critical aspect of the role. For a CISO to be effective, regardless of what they do, their authority must be in balance with their accountability.
Their authority is the level of power they have to implement their mandate. Their mandate defines what they are accountable for delivering. I’ve seen many IT engineers handed the CISO title, but without the right authority, they’re set up to fail. Especially when the most common mandate for many of these leaders is to prevent cybersecurity breaches across the entire organization.
The root cause of a power imbalance for the CISO
This has occurred because from the beginning the role has been called a “Chief”, or executive position. While this has changed today, many remnants still remain. So regardless of anything else about the role we discuss here, please remember this when trying to make the CISO role successful.
If you are hiring for the role, make should you define the role in balance, if you are taking a CISO role make sure it is defined this way. Also, if you are training to become a CISO, understanding this concept will save you a lot of stress as you progress in cybersecurity.
Finally, the way you define the authority and accountability of the role, and ensure it is in balance is within the security program charter or security governance policy of your organizational policy set. These documents should be approved by executive mgmt or the board and be updated, relevant, and owned by the CISO. If your organization does not have a charter, an effective governance policy, or they are crappy, your CISO role does not have this crucial balance.
So with this out of the way, lets get on to what these roles commonly do.
What does a Chief Information Security Officer do?
A Chief Information Security Officer is the senior leader responsible for an organization’s cybersecurity strategy and execution. They are often referred to as a CISO for short.
CISO’s define security for an organization
The Chief Information Security Officer is accountable for defining security at an organization. Once defined, then in leading the strategy for implementing and improving this definition. This starts as mentioned above by ratifying the security program charter, or policy set within the organization. From there they will define the underlying security standards for technology, roles and processes. Next, they will lead the development of security policies and finally in the implementation of all of these things. This process never ends.
Chief Information Security Officers drive risk management and reduction
Next, once they have a definition in place, a CISO must manage security risk. They are responsible for leading the strategy of measuring this security risk for gaps in that definition. Once defined then in implementing corrective actions to reduce that risk aligned with business objectives and tolerance. Along the way, they also need to communicate these risks to the business and then implement risk mgmt decisions. These decisions can be items such as accepting, reducing or potentially transferring this risk to an insurer.
Communication inside and outside the security organization
Promoting and teaching others in the organization this definition of security, as well as risk management activities, takes a lot of communication. So an effective CISO must drive communication, awareness and decision-making throughout the organization from base employees to key stakeholders. The most important aspect to this communication is supporting effective decision making about security throughout the entire organization they serve.
To do this, a CISO will develop and implement an enterprise communication system for security. This system manages these communication flows out of the security program, inside to it, and with external partners, regulators and in the communities the organization serves. It’s all about ongoing dialogue and active listening and evangelizing cybersecurity.
Chief Information Security Officers lead the security team
An effective CISO must be a great leader. They must lead in the evangelizing of the definition of security, reducing risk, and also through managing a team of superheroes that can help with all these activities. Cybersecurity is not easy, and it takes a great team to implement a security program within an organization. So an effective CISO must do this through building, coaching and then leading the security team.
Management of the cybersecurity program
A CISO is responsible for managing an organization’s enterprise security program. A security program is the system for managing security at any organization. Aside from managing the team, a CISO must also manage the organizational cybersecurity program. This program mandates security in two ways.
First, the logical systematic nature of security. This is defining security in the organization, risk management, communication reporting and improvement activities. Next, by managing the technical security architecture at an organization. You can have the strongest logical security program, but if your technical safeguards are weak, a breach is inevitable.
CISO’s manage the technical security architecture program in the organization
So the responsibility of a Chief Information Security Officer is also to drive the technical security throughout an organization in parallel with the overall security mgmt system. The technical security architecture program includes all preventive and detective safeguards, the processes required to operate them, and the engineers who manage and maintain them.
The Chief Information Security Officer role is highly variant
The Chief Information security officer role varies widely between organizations. This is again because they are a reflection of the nebulous nature of cybersecurity.
Some CISOs have large teams and big budgets. Others are “CISOs in name only,” holding the title to meet compliance requirements—with little actual support.
So the best way to be able to understand the CISO role is to first look at their common traits, as well as misconceptions about the role to drive understanding.
Common traits and role variations of the Chief Information Security Officer
CISOs may have different backgrounds and operate in different capacities, but they usually share a few key characteristics. These are important because they can help you better understand what they do in an organization.
Chief Information Security Officer as an extra title
The number one reason that organizations hire a Chief Information Security Officer is because they need to formally say they have one. Pretty much every security regulation, from HIPAA to ISO 27001 say you need to formally define a formal security leader.
So sometimes an organization will define the CISO, but aside from that they might not do any of the other things that a best practice CISO will do.
Leadership of the organization’s cybersecurity program and team
The cybersecurity program for an organization is the system for security at an organization. This system defines security through policy and process, measures and manages risks against this definition, communicates security across an organization and drives improvement execution. The Chief Information Security Officer drives this program, as well as their team that is responsible for executing tasks within it.
Sole point of accountability for cybersecurity
Yeah so when a breach happens, everything and everyone will very quickly point to this role. The bummer too is that they might not also have the level of authority they need to align with this level of accountability when a breach or problem occurs.
This is why if you are taking a CISO role, understanding the scope of your role, and the power you have to implement that scope is so the first thing you check before you should take it.
The nebulous nature of the role is stressful
Because the definition of cybersecurity is so broad and often unclear, the role of the Chief Information Security Officer is equally nebulous—and that makes it stressful.
Perceptions, responsibilities, and expectations are constantly shifting, which only adds to the pressure and uncertainty of the job.
Cybersecurity touches everything, so the CISO role does too
Since security covers every aspect of an organization, so does the CISO role that enforces it. This is why role definition is so important, because no one person or team can do everything, but often with cybersecurity this is the perception. It is also why communication skills are so important for the role.
An effective CISO must evangelize and represent security throughout the organization, ensuring that everyone plays their role in doing it. This is a unique but essential skill of anyone in the position.
Common role types defined for the Chief Information Security Officer
The application of the Chief Information Security Officer Role generally follows a couple of different employment structures. Defined below are the most common.
Full-Time dedicated CISO
This is the traditional definition of a CISO role. An organization hires a full-time employee to serve as its Chief Information Security Officer. This is a dedicated and salaried employee that works just for this organization. Many larger organizations still follow this model.
Virtual CISO (vCISO)
A virtual CISO, or vCISO for short is a part-time security leader. They are often consultants that split their time across multiple organizations. There are also larger services, such as CISOSHARE that offer vCISO’s at contracted rates.
CxO wearing the CISO hat
This is the Chief Marketing Officer and CISO or Chief Technology Officer (CTO) and CISO. At times some organizations want to show that they have a security leader but either don’t have the resources or budget to hire for a solo position. In this instance it is common that they just add the role to another existing position at the organization. So these people have the fun of doing two jobs, generally almost never with appropriate authority and accountability.
“Named” CISO to meet regulatory requirements
To meet regulatory or best practice security requirements, many organizations designate a formal cybersecurity leader. In these cases, they may simply assign the title of CISO to another executive or even a middle manager. While this satisfies compliance on paper, it rarely succeeds in practice.
The “CornField” CISO
This is the secret play of many “get-it-done” CEOs. They bring in a full-time CISO, maybe even a big-name one. They pay them well. Then they tuck them away on side and compliance-after-the-fact projects to keep them busy and off the critical path.
Then the CEO charges ahead at full speed with their execution teams on the complex problems the companies are trying to solve. It’s more common than most people think… and if you know, you know.
The “Driving the Bus” CISO
This is the opposite of the cornfield CISO. Good security is simply good design. So some of the best Chief Information Security Officers sometimes are also directly on the critical path of an organization. They may be designing critical business products and services while they drive their security in an organization.
What are a Chief Information Security Officer responsibilities?
Defined below are many of the common responsibilities of a CISO. Again, these can vary highly from organization to organization.
Building and leading the security team
Just like any other leadership position, a CISO must create the organization chart and structure for their cybersecurity team. This will often include the definition of roles, hiring and firing of team members.
Creating and maintaining the security program charter
The security program charter defines the organization’s rulebook for security. The CISO authors the charter, sets its direction, and drives its implementation across the organization.
Implementing policies, procedures, and standards
An organization establishes its approach to security through a clear framework of policies, standards, and procedures. These documents not only define what security means for the organization but also set the expectations for how every part of the business will operate securely.
The Chief Information Security Officer leads this effort. They ensure they align with business objectives and regulatory requirements, then drive the creation of these documents. Once designed, they drive the effort to ensure consistent implementation across the organization. Beyond just drafting policies, the CISO works to embed them into daily operations by training staff, guiding leaders, and holding teams accountable. The goal is to make this definition of security become a living, active part of the organizational culture.
Managing incident mgmt. and response efforts
Preventing breaches is a top priority for most organizations, and for many executives, it’s their single most important cybersecurity concern. That’s why the CISO must actively drive incident management and response as a distinct responsibility, on top of their many other duties.
No matter how broad the role, the CISO carries one constant mandate, which is protect the organization from breaches. For many leaders, this is the ultimate measure of success and the pressure never goes away.
Overseeing risk management
The CISO drives the identification, management, reporting, and remediation of risk across the organization. They work to uncover potential threats, evaluate their impact, and prioritize responses. The CISO leads the effort to keep risk visible and managed.
They drive risk assessments, measurement, and reporting activities. Then they drive informed decision making about risk and remediation plans design and then execution. By translating complex security risks into business terms, they help executives make informed decisions and ensure the organization stays resilient against evolving threats.
Communicating with leadership and stakeholders
A Chief Information Security Officer is responsible for evangelizing cybersecurity both through communication within the security program, as well as outside of it. This also generally includes partnering with IT, legal, compliance, and other business units within an organization. They drive both the listening and voice for cybersecurity inside and outside of the organization.
Common misconceptions About CISOs
There are many misconceptions about Chief Information Security Officers that blur understanding of the role. So here are some of the most common misconceptions.
The CISO role is always powerful
As discussed above, just because there is a Chief in their title, does not mean they have a lot of authority to carry out their mandate. Most today are not senior level officials at an organization and report a couple layers down on the overall organization chart.
Chief Information Security Officers are not powerful
For CISO’s that are on the front lines of innovating at an organization, they will have a strong mandate and be very powerful. This is why the true application of the role in an organization can be so confusing.
They have large teams
While some security teams can run into the hundreds of people, many are very small. Further, there are many times that an organization will expect the CISO to perform all of the cybersecurity tasks and not have any team at all.
CISO’s are always highly technical
While it is common that a CISO will have a technical background, this is not always the case. Further, while technical security will be a big part of their job, they need other critical skills, such as master communication and leadership to be successful as well.
The Chief Information Security Officer role is always the same
Hopefully we have put this one to rest that since the definition of security varies from organization to organization, so will the definition of the CISO put in place to implement it.
Trends impacting the Chief Information Security Officer role today
As cybersecurity evolves, so does the role of the CISO. Here are the key trends shaping it today.
Increased personal liability for Chief Information Security Officers
Recently there has been a trend that CISO’s are being held personally liable for cybersecurity at an organization.
The supply of Chief Information Security Officers is being commoditized
For a while there, there was a limited amount of available qualified CISO’s. So these rockstars got rockstar salaries and attention. Qualified CISO’s are still in demand, but their experience and requirements has been lowered in most organizations. This has made more of them available at lower salaries and increased competition for the role.
“Shadow CISOs” holding the title without real responsibility
Some organizations have a CISO, but they are not truly allowed into the core of the business. They simply manage compliance activities while not hindering or slowing down innovation. Now when done right a CISO should be able to secure without slowing down a business, but some organizations do not take this chance with this trend.
The rise of the vCISO as a flexible alternative
Part time vCISO’s are growing in many cases as a result of the other trends. There are many senior CISO’s that find being a vCISO enables them to help more organizations at once while making more money. Organizations like them because they are often less expensive but with the same effect.
What’s in a Name? Chief Information Security Officer Title Variants
Depending on your industry or organization, the role may be called something else. Some common titles include:
Executive-level titles
- Chief Security Officer (CSO)
- Chief Information Assurance Officer (CIAO)
- The Chief Risk Officer (CRO)
IT/Cyber-specific
- VP of Information Security
- Head of Cybersecurity
- Director of Information Security
- Mgr of Information Security
- Information Systems Security Manager
Specialized or regulatory titles
- Data Protection Officer (DPO)
- Security Program Director
- Information Assurance Manager (IAM)
- Chief Trust Officer
Government focused Titles
- Deputy Director of Global Security
- Deputy Director of IT and Security
Common questions about Chief Information Security Officer’s
Below are some of the most common questions about the Chief Information Security Officer Role.
How do I become a CISO?
Many CISOs begin their careers as technical engineers, transition into cybersecurity roles, and then advance into leadership. In other cases, organizations simply assign the CISO title to an existing executive or manager, even if they are new to cybersecurity. What’s rare, however, is someone graduating with a cybersecurity degree and stepping directly into a CISO role without real-world experience.
How much should a Chief Information Security Officer be paid?
CISO compensation varies widely because the role itself differs so much from one organization to another. Still, here are some key metrics on CISO salaries.
Who should the CISO report to?
This is the question most often asked about the CISO role: Who should they report to? Sometimes it’s the CEO, sometimes the CTO, and sometimes somewhere in between. What truly matters is that the reporting line gives the CISO the authority to match their accountability.
What skills are critical to succeed as a CISO?
Most important is the ability to learn and teach quickly since the discipline is constantly changing. Some other top ones are technical proficiency, communication, leadership, and team mgmt skills.
Final thoughts on the Chief Information Security Officer
A Chief Information security officer is a critical role at any organization. However, it can also be highly nebulous and is changing rapidly just as technology is within all organization today. At CISOSHARE, understanding the Chief Information Security Officer role is a core aspect of our business. If you have questions on this article, or how we might be able to help your organization, please let us know.
About the author and Chief Information Security Officers
Mike Gentile is the co-author of The CISO Handbook, one of the first books to formally define the Chief Information Security Officer role. He is the founder and CEO of CISOSHARE and has served as CISO for leading organizations including UCLA Health, HireRight, and most recently Vubiquity. Connect with him here on LinkedIn.


