One CISO or two? The role's scope problem
CISOs are juggling technical work and business strategy, and some question whether one title can hold both.
The CISO role has been rewritten repeatedly over its roughly 30-year history, reshaped by new technology and rising threats. In many organizations, CISOs now own risk reporting, information risk management, threat monitoring, cyber risk accountability and governance, and security strategy. As AI and digital dependence grow, that remit is expanding well beyond security controls.
The latest IANS State of the CISO report finds CISOs carrying increasing executive authority to shape strategy at the organizational level. That raises a question the profession keeps returning to: can one title manage the growing list of technical and executive responsibilities?
Has the role outgrown its roots?
Former CISO Todd Fitzgerald, who now runs professional leadership programs and writes about the profession, says the CISO role has passed through successive phases, from technical oversight through compliance, GRC, cloud, and privacy to what is now described as a focus on business resilience.
Increasingly, it’s been about putting a business leadership lens around the job of the CISO.
— Todd Fitzgerald, former CISO and leadership program operator
Today’s CISO is a strategic role with a remit to reduce risk and contribute to what the business needs. That is not the technical person, Fitzgerald says, noting that many CSOs grew up that way but that it is not really what the job is.
Many companies, he says, are catching up with the CISO’s true remit.
I don’t feel like this is a new transformation.
— Todd Fitzgerald, former CISO and leadership program operator
Where the reporting lines still sit
According to IANS, two-thirds of CISOs still report into IT, a sign that many organizations haven’t assigned the role strategic business importance. Fitzgerald says the profession has done a poor job of articulating what the CISO role really is, and reasons that many CISOs fall back on technical abilities because trying to change organizational processes is difficult.
They’re not addressing where the real risk may be, or they’re not doing the hard part of getting together with their business units and their stakeholders and understanding their security needs.
— Todd Fitzgerald, former CISO and leadership program operator
The result can be a mismatch between how the CISO is perceived and the role they want to play. Fitzgerald says CISOs can find themselves complaining about budgets or not being listened to. They may come into the room as the techy security person but want to be seen as something else.
Reporting lines remain a live issue. Some argue that many organizations still haven’t assigned the role strategic business importance, which shapes how much authority the CISO actually carries.
What the scopes now cover
Splunk’s 2026 CISO Report found that 79% of CISOs say their remit has become significantly more complex, with responsibilities now spanning data privacy, regulatory compliance, and third-party cyber risk — and 96% are also now responsible for AI governance and risk management.
- Two-thirds of CISOs still report into IT, according to IANS.
- 52% of CISOs believe their scope is no longer fully manageable, particularly in smaller organizations and industries with leaner security teams, per the IANS 2026 State of the CISO Report.
- 79% of CISOs say their remit has become significantly more complex, per Splunk’s 2026 CISO Report.
- 96% are now responsible for AI governance and risk management, per the same report.
Tim Brown, general partner and CISO in residence at Team 8, agrees the CISO needs to operate as a business leader to represent cyber risk to the organization.
They absolutely still need to manage the operational side and have appropriate people to be part of that, no question, but [organizations] need a measure of the real risk and the coverage in place.
— Tim Brown, general partner and CISO in residence at Team 8
Without stoking fear, Brown says the CISO’s primary task is to lead the cyber risk conversations, but that doesn’t mean relying on lists of vulnerabilities, patches, and dashboard metrics.
Nobody has unlimited budget so you’ve got to build the skills necessary to be able to communicate to appropriately spend money to get things done.
— Tim Brown, general partner and CISO in residence at Team 8
The case for redesigning the role
The problem many CISOs face is that the role has become that of a business leader who must retain every previous responsibility. As a result, many CISOs report that the expanding scope of the role is outpacing resources. The IANS 2026 State of the CISO Report found that 52% of CISOs believe their scope is no longer fully manageable, particularly in smaller organizations and industries with leaner security teams.
Several years ago, discussions focused on whether the CISO role should be split between a business CISO and a technical CISO as a way of managing the growing set of responsibilities. That debate recognized that strategic risk management had become a business imperative.
More recently, there have been suggestions that two separate types of security leaders will emerge — one focused on defenses and the other focused on risk and resilience. Fitzgerald is not in favor of splitting security off into IT.
I don’t know that I would have two CISOs. I still think one CISO who’s driving the strategy and is still responsible for that function.
— Todd Fitzgerald, former CISO and leadership program operator
Deputies, and what they actually do
Some larger enterprises opt to have a deputy CISO as a way to manage the workload. In this case, the CISO is responsible for strategic direction, engaging with the board and other executives, and risk management, while the deputy role handles more of the operations.
Brown says a deputy is important for succession planning and continuity of day-to-day operations, while also providing a way to develop people who can eventually become CISOs.
It’s important to have that depth in the organization.
— Tim Brown, general partner and CISO in residence at Team 8
Both Brown and Fitzgerald say the answer isn’t to create two CISOs. It’s one CISO with clearly defined technical, governance, and operational responsibilities.
Three functions, one owner
For Brown, the CISO’s primary function is to own the business risk associated with cyber, with governance and security operations supporting the role.
That doesn’t mean they own the remediation/resolution of the risk, but they should be the one thinking about it 100% of the time, communicating it, and helping to develop appropriate remediations.
— Tim Brown, general partner and CISO in residence at Team 8
Security operations and defenses, the primary role of the past, are the second element, and governance is the third function, but they may not all be managed personally by the CISO.
Organizations will have different reporting structures — often we see the CISO having different distinct functions underneath them. Just like accounting, where there’s a CFO responsible for finance for the organization, the CISO needs to be responsible for cyber risk for the business.
— Tim Brown, general partner and CISO in residence at Team 8
Industry reports suggest that shift is under way, with executive-level CISO titles (either VP- or director-level) now dominating across company sizes, and they’re significantly more likely to report outside of IT, according to IANS.
The liability that comes with the title
But the executive title brings added responsibilities — and risks. Executive-level CISOs need to ask whether they are covered by directors and officers (D&O) insurance, Brown says.
They need to have conversations with executive teams and boards around liability and if they’re really an officer are they covered under the directors and officers insurance?
— Tim Brown, general partner and CISO in residence at Team 8
Brown’s charges following the SolarWinds breach focused more CISOs’ attention on their personal liability and what protections were in place — or not.
The trigger point in many ways was me being charged by the SEC and it meant a lot of CISOs having that conversation.
— Tim Brown, general partner and CISO in residence at Team 8
As the role matures, Fitzgerald says, CISOs that are still largely technical will need to look to training and experience to operate as business leaders.
It’s important that we’re able to have these conversations and that we’re seen as a true partner with other executives as opposed to just a technical partner.
— Todd Fitzgerald, former CISO and leadership program operator
A younger role, still maturing
In the early days, only large enterprises were thought to need a CISO. That’s given way as more organizations have adopted a security function, even as the role has grown and changed.
Fitzgerald plots the CISO role on a similar maturity trajectory to the CIO — becoming a true executive.
It’s a younger role — 31 years since the first CISO — but if we look back at where the CIO role was at this point, we’ll see a different flavor of CISO in 10 to 15 years.
— Todd Fitzgerald, former CISO and leadership program operator
What this means for security leaders
For CISOs, the immediate practical question is not whether the title survives, but what the job actually contains — and whether the resources follow the scope. The IANS finding that 52% call their scope no longer fully manageable points to a gap that training alone may not close, especially in smaller organizations and industries with leaner security teams.
The IANS data showing two-thirds of CISOs still report into IT suggests that, in many organizations, the business-leader framing Fitzgerald and Brown describe remains aspirational rather than settled. Where the reporting line sits shapes how much authority the role carries, and how easily the CISO can get business units and stakeholders to engage on security needs.
The liability question is another area where the executive framing has concrete consequences. Brown’s point about D&O insurance coverage is one CISOs may want to raise with their boards and executive teams, particularly as more of them carry VP- or director-level titles.
For organizations, the choice is less about whether to create a second CISO and more about defining what one CISO owns, what sits beneath them, and who covers what when the workload outstrips a single person. The evidence points to scope growing faster than headcount — and to a profession still working out how to describe itself to the executives who set its budget and its mandate.
Sources
- CSO Online Original source
- today’s focus on business resilience Also reporting
- according to IANS Also reporting
- haven’t assigned the role strategic business importance Also reporting
- Splunk’s 2026 CISO Report Also reporting
- no longer fully manageable Also reporting
Continue Reading
NetScaler Zero-Day Poses Patching Puzzle
Citrix rushed out emergency updates for a SAML authentication flaw already exploited in attacks, but administrators may need to patch twice.
Apple tightens macOS full-disk access rules
Apple is changing a macOS privacy setting after an AI agent read a columnist's messages, raising questions about third-party app permissions.
MI5: MSS Front Funded 100+ Academics
The alert urges U.K. universities to review CGTRI ties, warning that continuing collaboration could lead to prosecution.