Stop playing with the CISO role. Fix cybersecurity leadership
Summary
This article argues that the CISO (chief information security officer, the executive responsible for an organization's cybersecurity) role has become structurally flawed because it expects one person to handle too many responsibilities, from technical expertise to board-level strategy, while lacking direct authority to enforce decisions across the business. The author proposes creating a separate CSO (chief security officer) role positioned above traditional cybersecurity that focuses on broader organizational protection, with the mandate to bring together different departments' competing interests when security decisions affect operations, finance, legal, and business goals.
Classification
Original source: https://www.csoonline.com/article/4217607/stop-playing-with-the-ciso-role-fix-cybersecurity-leadership.html
First tracked: September 3, 2026 at 08:01 AM
Classified by LLM (prompt v3) · confidence: 95%