CISOs Are Being Handed the Business Risk Portfolio. Most Aren't Ready.
Security chiefs at Appfire, JumpCloud, and BECU describe how they're learning to own risks that finance and operations used to call their own.

Doug Kersten runs security at Appfire. He also now owns something most security leaders have never touched: accountability for how security tooling costs inside customer products erode the company's profit margins. His title is CISO. His actual mandate is creeping toward something closer to chief risk officer.
"CISOs need to provide input and remediation on the impact of security cost because these often-hidden costs have a negative impact on profitability," Kersten says. Finance teams, he argues, routinely miss these costs when calculating true cost of goods sold. If the CISO isn't in the room, nobody flags it.
Kersten isn't an anomaly. Across sectors, security chiefs are absorbing business risk functions that previously belonged to CFOs, COOs, and general counsel. Dale Hoak, CISO at RegScale, frames the shift bluntly: the line between security risk and business risk is dissolving. Today's CISO must advise on revenue exposure, supply chain integrity, customer trust, and regulatory posture — not just whether the firewall rules are clean.
Several security leaders offered concrete approaches for making that transition work.
Build a coalition. Roland Palmer, CISO at JumpCloud, says he hasn't mastered business risk yet, so he partners with those who have. His working group pulls in legal, finance, marketing, and the COO. Kersten took a parallel route — assigning business unit leaders to specific security risks, so knowledge flows in both directions.
Attach security work to business OKRs. Kersten now layers corporate objectives and key results directly into his security strategy. When the HR team identifies employee retention as a risk, his team checks whether security friction contributes to attrition. "It changed how we look at risk," he says. Richard Watson of EY recommends mapping cyber controls to specific business processes and financial outcomes — translating technical exposure into terms the CFO can act on.
Do a listening tour. Gary Hayslip, co-author of the CISO Desk Reference Guide, advocates for what he calls a "walk-about" — structured conversations with business colleagues to surface what genuinely worries them. Hoak adds that regular engagement with the CFO, COO, general counsel, and product leaders keeps security embedded in strategic planning rather than treated as a compliance afterthought.
Run tabletop exercises that force executive decisions. Most tabletops stop at technical containment, Hayslip says. He runs scenarios that push executives toward harder calls: pay a ransom or refuse, what to disclose and when, whether to invoke legal privilege, whether an operational fallback exists and who activates it. The CISO learns how peers actually reason under pressure.
Study the business formally. Sean Murphy, CISO at BECU — the fifth-largest credit union in the United States — earned a Directorship Certification from the National Association of Corporate Directors to understand how boards assess risk. Hayslip recommends a simpler starting point: read the 10-K, the investor deck, and the earnings call transcripts. That tells a CISO which business units drive revenue and what leadership is signaling to the market.
"The CISO can't prioritize protecting the business if they don't know" how it works, Murphy says. Dull reading. Necessary work.



