{"id":9862,"date":"2026-10-05T08:25:00","date_gmt":"2026-10-05T08:25:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9862"},"modified":"2026-10-05T08:25:00","modified_gmt":"2026-10-05T08:25:00","slug":"should-the-ciso-role-be-split-in-two","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9862","title":{"rendered":"Should the CISO role be split in two?"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">In its roughly 30-year history, the CISO role has been reshaped by waves of new technology and rising cyber threats.<\/p>\n<p class=\"wp-block-paragraph\">In many organizations, CISOs now own risk reporting, information risk management, threat monitoring, cyber risk accountability and governance, and security strategy.<\/p>\n<p class=\"wp-block-paragraph\">And as AI and digital dependence grow, the CISO\u2019s remit is growing beyond security controls. The latest <a href=\"https:\/\/www.ians.com\/insights\/ciso-leadership\/the-ciso-in-2030-build-skills-now-to-lead-as-the-role-evolves\">IANS State of the CISO report<\/a> finds CISOs carrying increasing executive authority to shape strategy at the organizational level.<\/p>\n<p class=\"wp-block-paragraph\">Now more than ever the CISO role is being rewritten \u2014 but can one title manage the growing list of technical with executive responsibilities?<\/p>\n<h2 class=\"wp-block-heading\">Has the CISO outgrown its technical roots?<\/h2>\n<p class=\"wp-block-paragraph\">Former CISO <a href=\"https:\/\/www.linkedin.com\/in\/toddfitzgerald\">Todd Fitzgerald<\/a>, who now runs professional leadership programs and writes about the profession, says the CISO role has passed through successive phases, from technical oversight through compliance, GRC, cloud, and privacy to <a href=\"https:\/\/www.csoonline.com\/article\/4200382\/how-cisos-can-rise-to-the-business-resilience-challenge.html\">today\u2019s focus on business resilience<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIncreasingly, it\u2019s been about putting a business leadership lens around the job of the CISO,\u201d Fitzgerald says.<\/p>\n<p class=\"wp-block-paragraph\">Today\u2019s CISO is a strategic role with a remit to reduce risk and contribute to what the business needs. \u201cThat\u2019s not the technical person. That\u2019s how a lot of CSOs grew up, but that\u2019s not really what the job is,\u201d he notes.<\/p>\n<p class=\"wp-block-paragraph\">Many companies, Fitzgerald says, are catching up with the CISO\u2019s true remit. \u201cI don\u2019t feel like this is a new transformation,\u201d he tells CSO.<\/p>\n<p class=\"wp-block-paragraph\">But <a href=\"https:\/\/www.ians.com\/press\/2026-report-finds-executive-level-ciso-titles-more-prevalent-than-ever\">according to IANS<\/a>, two-thirds of CISOs still report into IT \u2014 a sign that many organizations <a href=\"https:\/\/www.csoonline.com\/article\/4136293\/its-time-to-rethink-ciso-reporting-lines.html\">haven\u2019t assigned the role strategic business importance<\/a>. \u201cI think we\u2019ve done a poor job of articulating what the CISO role really is,\u201d says Fitzgerald, who reasons that many CISOs fall back on technical abilities because trying to change organizational processes is difficult.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThey\u2019re not addressing where the real risk may be, or they\u2019re not doing the hard part of getting together with their business units and their stakeholders and understanding their security needs,\u201d he says.<\/p>\n<p class=\"wp-block-paragraph\">The result can be a mismatch between how the CISO is perceived and the role they want to play. Fitzgerald says CISOs can find themselves complaining about budgets or not being listened to.<\/p>\n<p class=\"wp-block-paragraph\">CISOs may come into the room as \u201cthe techy security person\u201d but want to be seen as something else.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.splunk.com\/en_us\/form\/ciso-report.html\">Splunk\u2019s 2026 CISO Report<\/a> found that 79% of CISOs say their remit has become significantly more complex, with responsibilities now spanning data privacy, regulatory compliance, and third-party cyber risk \u2014 and 96% are also now responsible for AI governance and risk management.<\/p>\n<p class=\"wp-block-paragraph\">Tim Brown, general partner and CISO in residence at Team 8, agrees the CISO needs to operate as a business leader to represent cyber risk to the organization.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThey absolutely still need to manage the operational side and have appropriate people to be part of that, no question, but [organizations] need a measure of the real risk and the coverage in place,\u201d Brown says.<\/p>\n<p class=\"wp-block-paragraph\">Without stoking fear, the CISO\u2019s primary task is to lead the cyber risk conversations, but that doesn\u2019t mean relying on lists of vulnerabilities, patches, and dashboard metrics. \u201cNobody has unlimited budget so you\u2019ve got to build the skills necessary to be able to communicate to appropriately spend money to get things done,\u201d Brown says.<\/p>\n<h2 class=\"wp-block-heading\">The case for redesigning the CISO role<\/h2>\n<p class=\"wp-block-paragraph\">The problem many CISOs face is that the role has become that of a business leader who must retain every previous responsibility. As a result, many CISOs report that the expanding scope of the role is outpacing resources.<\/p>\n<p class=\"wp-block-paragraph\">The IANS 2026 State of the CISO Report found that 52% of CISOs believe their scope is <a href=\"https:\/\/www.csoonline.com\/article\/4128992\/with-cisos-stretched-thin-re-envisioning-enterprise-risk-may-be-the-only-fix.html\">no longer fully manageable<\/a>, particularly in smaller organizations and industries with leaner security teams.<\/p>\n<p class=\"wp-block-paragraph\">Several years ago, discussions focused on whether the CISO role should be split between a business CISO and a technical CISO as a way of managing the growing set of responsibilities. It recognized that strategic risk management had become a business imperative.<\/p>\n<p class=\"wp-block-paragraph\">More recently, there have been suggestions that two separate types of security leaders will emerge \u2014 one focused on defenses and the other focused on risk and resilience. Fitzgerald is not in favor of splitting security off into IT.<\/p>\n<p class=\"wp-block-paragraph\">\u201cI don\u2019t know that I would have two CISOs. I still think one CISO who\u2019s driving the strategy and is still responsible for that function\u201d is the right way to approach the role, he says.<\/p>\n<p class=\"wp-block-paragraph\">Some larger enterprises opt to have a deputy CISO as a way to manage the workload. In this case, the CISO is responsible for strategic direction, engaging with the board and other executives, and risk management, while the deputy role handles more of the operations.<\/p>\n<p class=\"wp-block-paragraph\">Brown says a deputy is important for succession planning and continuity of day-to-day operations, while also providing a way to develop people who can eventually become CISOs. \u201cIt\u2019s important to have that depth in the organization,\u201d he says.<\/p>\n<p class=\"wp-block-paragraph\">Both Brown and Fitzgerald say the answer isn\u2019t to create two CISOs. It\u2019s one CISO with clearly defined technical, governance, and operational responsibilities.<\/p>\n<p class=\"wp-block-paragraph\">For Brown, the CISO\u2019s primary function is to own the business risk associated with cyber, with governance and security operations supporting the role.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThat doesn\u2019t mean they own the remediation\/resolution of the risk, but they should be the one thinking about it 100% of the time, communicating it, and helping to develop appropriate remediations,\u201d he says.<\/p>\n<p class=\"wp-block-paragraph\">Security operations and defenses, the primary role of the past, are the second element and governance is the third function, but they may not all be managed personally by the CISO.<\/p>\n<p class=\"wp-block-paragraph\">\u201cOrganizations will have different reporting structures \u2014 often we see the CISO having different distinct functions underneath them,\u201d Brown says. \u201cJust like accounting, where there\u2019s a CFO responsible for finance for the organization, the CISO needs to be responsible for cyber risk for the business.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Industry reports suggest that shift is under way, with executive-level CISO titles (either VP- or director-level) now dominating across company sizes, and they\u2019re significantly more likely to report outside of IT, according to the IANS State of the CISO report.<\/p>\n<p class=\"wp-block-paragraph\">But the executive title brings added responsibilities \u2014 and risks.<\/p>\n<p class=\"wp-block-paragraph\">Executive-level CISOs need to ask whether they are <a href=\"https:\/\/www.csoonline.com\/article\/2512968\/if-youre-a-ciso-without-do-insurance-you-may-need-to-fight-for-it.html\">covered by directors and officers (D&amp;O) insurance<\/a>, Brown says. \u201cThey need to have conversations with executive teams and boards around liability and if they\u2019re really an officer are they covered under the directors and officers insurance?\u201d<\/p>\n<p class=\"wp-block-paragraph\">Brown\u2019s charges following the SolarWinds breach focused more CISOs\u2019 attention on their personal liability and what protections were in place \u2014 or not. \u201cThe trigger point in many ways was me being charged by the SEC and it meant a lot of CISOs having that conversation,\u201d he says.<\/p>\n<p class=\"wp-block-paragraph\">As the role matures, Fitzgerald says, CISOs that are still largely technical will need to look to training and experience to operate as business leaders. \u201cIt\u2019s important that we\u2019re able to have these conversations and that we\u2019re seen as a true partner with other executives as opposed to just a technical partner,\u201d he tells CSO.<\/p>\n<p class=\"wp-block-paragraph\">In the early days, only large enterprises were thought to need a CISO. That\u2019s given way as more organizations have adopted a security function, even as the role has grown and changed.<\/p>\n<p class=\"wp-block-paragraph\">Fitzgerald plots the CISO role on a similar maturity trajectory to the CIO \u2014 becoming a true executive.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIt\u2019s a younger role \u2014 31 years since the first CISO \u2014 but if we look back at where the CIO role was at this point, we\u2019ll see a different flavor of CISO in 10 to 15 years,\u201d he says.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>In its roughly 30-year history, the CISO role has been reshaped by waves of new technology and rising cyber threats. In many organizations, CISOs now own risk reporting, information risk management, threat monitoring, cyber risk accountability and governance, and security strategy. And as AI and digital dependence grow, the CISO\u2019s remit is growing beyond security [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9863,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9862","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9862"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9862"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9862\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9863"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9862"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9862"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9862"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}