Cybersecurity is an intense race that never lets up, an endless back-and-forth with threat actors looking for a way in.
Not surprisingly, CISO are continually on edge, feeling increased stress and pressure: In fact, 75% are open to change, according to a new report from IANS Research and Artico Search.
The State of the CISO 2023-2024 Report also found that many security leaders are left out of board conversations, have trouble being heard and don’t have the authority they need to take action — despite the fact that they are being held up to new standards and are increasingly responsible for their organization’s security posture.
“At the outset of 2024, the state of the CISO reflects a duality of both anxiety and opportunity,” IANS and Artico researchers write. “CISOs are having to do more with less and risk legal exposure, professionally.”
Current CISO situation vs. expectationsThis year’s report analyzing CISO’ job level and satisfaction, compensation, board engagement and budget dynamics collected data from hundreds of CISO and other security leaders in the U.S. and Canada. Participants work for finance, technology and healthcare companies with annual revenues ranging from less than $1 billion to those with more than $10 billion.
Research indicates that CISO are in a precarious position due to volatile financial markets and inflation (resulting in budget cutbacks), increasing breaches and ransomware and the sheer explosion in genAI tools that can both defend and attack an organization.
Amidst all this, expectations are rising — yet they do not reflect the current state of affairs. For starters, organizations see their CISO as a business risk function with high business acumen, but in reality 76% of security leaders come from a technical background where risk management is often secondary. And, only 2% say their formative training years broadened beyond cyber.
Secondly, security leaders are expected to bring clear voices to executive leadership and have a direct line of communication with the CEO, C-suite and board. However, just 20% hold C-level positions (that’s even lower, as 15%, at public companies), 63% are at a VP or director-level position and 90% are at least two levels removed from the CEO. Furthermore, only half engage with their company’s boards on a quarterly basis.
“Essentially, the expectations for the CISO role have been elevated to the C-suite level,” researchers write. “Yet, we find many CISOs continue to struggle to be viewed as such and/or have not been elevated to that level.”
Impact of securities exchange commission (SEC) actions on CISONew SEC rules have gone into effect requiring public companies to disclose ‘material’ cybersecurity events within four days, document their risk and mitigation measures and detail the board’s involvement and line of communication around security.
Furthermore, the agency recently filed fraud charges against SolarWinds and its CISO Timothy G. Brown for misleading investors about the company’s security practices and risk.
This presents new legal and liability exposure for CISO, with regulatory bodies holding them directly responsible in instances of fraud within their companies. But, just 36% say they are offered clear risk guidance and details on risk tolerance from their company’s boards.
“The situation has arisen in which the CISO is responsible for reporting requirements, similar to that of a chief financial officer, but often without the signature authority and general influence of a CFO,” researchers write.
The updated SEC rules demand strong collaboration between CISO and company leadership, including the board. However, researchers report, “our analysis found there is a disconnect at most companies.”
Security leaders that do have regular engagement with the C-suite and boards are overall more satisfied, according to the survey and are also more optimistic about budget and risk alignment. On the contrary, just 28% without board involvement report satisfaction with their roles.
“We see CISO satisfaction positively correlated with access and influence at the board level,” said Steve Martano, a partner in Artico Search’s cybersecurity practice and IANS faculty member. “CISOs with a strong rapport with their boards feel more valued and generally report they are ‘heard,’ even when there are disagreements on budgeting.”
Compensation and professional development for security leadersIANS’s research on declining job satisfaction reflects that of other recent reports. Notably, security company BlackFog found that nearly one-third (32%) of cybersecurity leaders in the U.S. and UK were considering quitting their jobs. Another study found that a staggering nine out of 10 security leaders are “moderately” to “tremendously” stressed, and that the average CISO tenure is just a little over two years.
Others in the industry highlight the impact high-pressure environments and alert fatigue have on security leaders and their teams’ mental health.
So what can CISO do to improve their satisfaction levels, standing and influence within a company and broaden their non-technical expertise?
For starters, advocate, IANS advises. With traditional characteristics no longer meeting the needs of the new security landscape, CISO have an “unprecedented opportunity” to argue for their role at the C-suite level and call for enhanced interaction with boards.
Additionally, just 20% of security leaders receive internal mentoring from non-technical colleagues. In light of this, they should be proactive when it comes to formal leadership training.
This is important because, to properly interact with the C-suite and the board, CISO need to have business acumen and speak their language, researchers emphasize. They must have a solid understanding of corporate and go-to-market strategy, the ability to frame risk in economic impact terms and the “financial literacy” to read — and most importantly understand — financial statements.
Also critical is executive presence, IANS says. CISO must be persuasive, direct and decisive. This ability “hinges on skills like storytelling, situational awareness and understanding the roles and responsibilities of the members of the board,” researchers write.
As an added bonus, CISO that enhance their leadership skills through external training have higher salaries. Security leaders who don’t participate in professional development make an average of $369,000 a year, while those with executive coaching take in roughly $550,000 — a difference of nearly $200,000.
Ultimately, says advisory CISO and IANS faculty member Wolfgang Goerlich: “CISOs who manage relationships are more satisfied and successful than CISOs who manage technology.”
Comments