The CISO Role Is Broken. A New Title Won't Fix It.

Security leaders are being asked to run the whole company while also running its defences. One analyst says the org chart itself is the problem, not the people in it.

ThreatVectr Newsdesk· 4 min read
Photoreal editorial-style overhead view of a large corporate boardroom table with scattered financial documents, a risk matrix printout, and a laptop displaying
Share

Key points

  • Most large organisations have a Chief Information Security Officer (CISO), the executive responsible for protecting company data and systems, but the role now carries more responsibility than one person can practically hold.
  • A growing argument in the security industry says companies should add a separate Chief Security Officer (CSO) above the CISO to own the broader business-protection agenda.
  • The CISO would keep deep technical responsibility; the CSO would have the authority to force decisions across legal, finance, operations and technology when they conflict.
  • Boards are being urged to stop treating cybersecurity as someone else's problem and to demand clear accountability at the executive level.

Every few years the security industry decides the CISO needs fixing. Better board access. A new reporting line. A bigger budget. Softer people skills. And yet, as CSO Online notes in its analysis of the problem, the gap between security teams and the rest of the business keeps reopening.

The argument gaining traction now is simpler and more uncomfortable: the job description itself is the problem.

What is a CISO actually supposed to do?

The short answer is: everything, which is exactly the issue. A CISO, or Chief Information Security Officer, is the senior executive responsible for keeping a company's information and technology safe from criminals, outages, and regulatory trouble. That was already a big job in 2005. Today the same role is also expected to advise the board, manage regulators, drive digital transformation, translate technical risk into financial terms, and somehow win arguments with business units that don't report to them.

That last part matters. The CISO is accountable for security outcomes but usually has no direct power over the engineers, product teams, or operations staff who actually make the decisions that create security risk.

The failure mode here is structural. You can hire the sharpest CISO on the market and they will still spend most of their time trying to persuade people who have no obligation to listen.

How would a Chief Security Officer actually be different?

Yes, meaningfully, if the role is designed correctly.

The proposed model works like this. The CSO, sitting above the CISO, becomes a genuine business executive first and a security expert second. Their job is to own the whole protection question: cybersecurity, data privacy, business continuity, regulatory compliance. Critically, they carry the authority to bring legal, finance, operations and technology into the same room and force a decision that the whole organisation can live with.

Consider what happens today when a serious vulnerability, meaning a flaw in a company's software that criminals could exploit, gets discovered. Security wants it fixed immediately. Operations doesn't want downtime. Finance is asking about cost. Legal is watching the regulator. The CISO can explain the danger clearly. What they often cannot do is make everyone agree on a course of action, because that requires organisational authority they don't have.

The CSO would have that authority.

Role Primary accountability Reports to
CSO (proposed) Enterprise-wide protection strategy CEO or board
CISO (retained) Technical cybersecurity delivery CSO
CIO Technology infrastructure CEO or CFO

One thing the post-mortem will say, again and again, is that everyone knew about the risk. The gap was in who had the power to resolve it.

Should ordinary people care about how companies arrange their org charts?

In practice, yes. When a hospital, a bank, or a retailer suffers a breach and your data ends up for sale online, the investigation nearly always finds the same thing: the people who spotted the warning signs couldn't get the decision-makers to act fast enough.

Clearer executive accountability means faster decisions under pressure, which means incidents get contained before your details walk out the door.

If you've recently had an account at a company that suffered a data breach, watch your email for phishing attempts, where criminals send fake messages pretending to be a trusted company to steal your passwords or payment details. Change your password at that service and, if you reused it elsewhere, change it there too.

The operational takeaway: authority and accountability need to live in the same role, or the org chart will keep manufacturing the same crisis.

© 2026 Threat Vectr