CISOs Are Being Handed the Business Risk Portfolio. Most Aren't Ready.

Security chiefs at Appfire, JumpCloud, and BECU describe how they're learning to own risks that finance and operations used to call their own.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
CISOs Are Being Handed the Business Risk Portfolio. Most Aren't Ready.
Share

Key points

  • CISOs are absorbing accountability for business risks once owned by CFOs and general counsel.
  • Embedding security into corporate OKRs changes which risks get prioritised and funded.
  • Coalition-building with legal, finance, and the COO is emerging as the fastest path to business fluency.
  • Formal governance credentials and earnings-call transcripts are both being used to close knowledge gaps.
  • Tabletop exercises that force ransom and disclosure decisions teach CISOs how executives actually reason under pressure.

Doug Kersten runs security at Appfire. He also owns something most security leaders have never touched: accountability for how security tooling costs inside customer products erode profit margins. His title is CISO; his actual mandate has crept toward something closer to chief risk officer.

"CISOs need to provide input and remediation on the impact of security cost because these often-hidden costs have a negative impact on profitability," Kersten says. Finance teams routinely miss these costs when calculating true cost of goods sold. If the CISO isn't in the room, nobody flags it.

Kersten isn't an anomaly. Security chiefs across sectors are absorbing business risk functions that previously belonged to CFOs and general counsel. Dale Hoak, CISO at RegScale, frames the shift plainly: the line between security risk and business risk is dissolving. The modern CISO must advise on revenue exposure, supply chain integrity, regulatory posture, and customer trust, not just whether the firewall rules are clean.

Our coverage of S&P 200 CISO disclosures to the SEC found the same pressure from the top down: boards are asking security leaders to speak in business outcomes, not technical metrics. Several security leaders offered concrete approaches for making the transition work.

Build a coalition. Roland Palmer, CISO at JumpCloud, partners with those who already own business risk: legal, finance, the COO. Kersten took a parallel route, assigning business unit leaders to specific security risks so knowledge flows both ways.

Attach security work to business OKRs. Kersten layers corporate objectives and key results directly into his security strategy. When HR flags employee retention as a risk, his team checks whether security friction contributes to attrition. "It changed how we look at risk," he says. Richard Watson of EY recommends mapping cyber controls to specific business processes and financial outcomes, translating technical exposure into terms the CFO can act on.

Do a listening tour. Gary Hayslip, co-author of the CISO Desk Reference Guide, advocates structured conversations with business colleagues to surface what genuinely worries them. Hoak adds that regular engagement with the CFO, COO, general counsel, and product leaders keeps security embedded in strategic planning rather than treated as a compliance afterthought.

Run tabletops that force executive decisions. Most tabletops stop at containment. Hayslip runs scenarios that push executives toward harder calls: pay a ransom or not, what to disclose and when, whether to invoke legal privilege, whether an operational fallback exists and who activates it.

Study the business formally. Sean Murphy, CISO at BECU, the fifth-largest credit union in the United States, earned a Directorship Certification from the National Association of Corporate Directors to understand how boards assess risk. Hayslip recommends a simpler start: read the 10-K and the earnings call transcripts.

"The CISO can't prioritize protecting the business if they don't know" how it works, Murphy says. Dull reading. Necessary work.

© 2026 Threat Vectr