Should the CISO Role Be Split in Two?

As the CISO role expands from technical security oversight to encompass business risk management, governance, and strategic leadership, industry experts debate whether it should be split into separate business-focused and technical-focused positions. While some organizations have introduced deputy CISOs to manage operational tasks, the consensus among professionals like Todd Fitzgerald and Tim Brown is that a single CISO with clearly defined responsibilities is preferable, supported by appropriate teams to handle technical and governance functions. The evolving role increasingly requires CISOs to act as business leaders responsible for cyber risk at the enterprise level, raising the importance of executive authority, board engagement, and personal liability considerations.

https://www.csoonline.com/article/4230243/should-the-ciso-role-be-split-in-two.html

Scroll to Top