Table of Contents

Author

Former British Army officer, trained in surveillance and target acquisition, and Bain and Company engagement manager, with more than a decade of experience working in consulting, private equity and venture capital across Western Europe.

A Chief Information Security Officer sits at the intersection of technology risk and business strategy — the executive whose job is to keep an organization's data and systems secure without slowing the business down. The title is now standard at large companies, but what the role covers, who it reports to, and what it pays have all shifted meaningfully over the past two years. Here's what the job involves today, and where verified, human-led intelligence work fits alongside the monitoring tools a CISO already runs.

Key Takeaways

  • A CISO is the senior executive responsible for building and running an organization's information security program — strategy, policy, and the operational work that protects data and systems from unauthorized access, disruption, and theft.
  • Reporting lines are shifting fast toward the top of the org chart: 42% of CISOs now report directly to the CEO — roughly three times the prior year's share — while direct reporting to a CIO or CTO fell from close to half of respondents to 30% (Heidrick & Struggles, 2025/2026).
  • US CISOs' median total compensation reached $880,000 in 2025, and a separate 566-CISO benchmark recorded a 6.7% year-over-year compensation rise even as security budgets grew only 4% — the slowest pace in five years (Heidrick & Struggles; IANS Research & Artico Search, both 2025).
  • A CISO's internal monitoring tools show what's happening inside the network. They don't verify who's actually behind a vendor, a board candidate, or a name that surfaces on a leaked-credential dump — that's where investigative verification, not another dashboard, closes the gap.
  • We treat a CISO's external risk picture the same way we treat any due diligence question: verify the claim, don't just monitor for its symptoms.

What a CISO Actually Does

A Chief Information Security Officer is the senior executive responsible for building and running an organization's information security program — the strategy, policies, and operational work that protect data and systems from unauthorized access, disruption, and theft. The CISO sits in the C-suite, which means the job is only half technical. The other half is translating security posture into terms a board, a CFO, or a regulator can actually act on.

In practice, the role covers:

  • Setting security policy and choosing the frameworks — ISO 27001, NIST, SOC 2 — an organization builds its program around
  • Managing security personnel, and at larger organizations, coordinating multiple specialized teams: SOC, GRC, engineering, threat intelligence
  • Monitoring network activity and maintaining continuous visibility into where an attack is most likely to originate
  • Owning incident response and disaster recovery planning, and directing the response when a breach actually happens
  • Reporting the organization's security posture — accurately, not reassuringly — up a defined chain: CIO, CTO, CEO, or the board directly

Why this matters: the technical work is table stakes. What separates a CISO who lasts from one who doesn't is usually the second half of the job — the ability to communicate a real risk in language a non-technical executive will act on, before it becomes a headline.

The Background That Gets Someone Into the Role

CISOs typically come up through information security, IT, risk management, or computer science — though the strongest candidates increasingly pair that technical grounding with formal business or risk-management training, since the job now involves resourcing and prioritization calls that are business decisions as much as technical ones. Auditing experience isn't required, but it helps: a CISO who has sat on the other side of a compliance audit tends to build controls that actually hold up under one.

Certifications that carry real weight in hiring:

  • CISA (Certified Information Systems Auditor) or CISM (Certified Information Security Manager) — both from ISACA
  • CISSP (Certified Information Systems Security Professional) — from ISC2

None of these substitute for the harder-to-credential skill the role actually demands: staying calm and decisive while a live incident is still unfolding, with incomplete information and a board waiting for an answer.

Where the Role Came From

The role is younger than most people assume. Citicorp created the position in 1995 and hired Steve Katz to fill it — a direct response to an attempted $10 million fraud a year earlier, in which hackers moved roughly $400,000 out of the bank before the scheme was caught. That origin story still shapes the job three decades later: the CISO exists because a specific, costly failure showed that security needed a named executive owner, not a responsibility shared loosely across IT.

The foundational duties — governance, policy, monitoring — haven't gone away. What's changed is who else the CISO now has to work with. A modern CISO spends real time translating between technical teams, executives who don't share their vocabulary, and increasingly, outside investigators and auditors who need to understand what the organization actually knows about its own exposure.

Who a CISO Reports To — and Why That's Changing

Reporting lines have moved fast, and the direction is toward more executive proximity, not less. Heidrick & Struggles' 2025/2026 global CISO survey — 371 respondents across the US and Europe — found that 42% of CISOs now report directly to the CEO, roughly three times the share recorded in the prior year's survey. Reporting to a CIO or CTO, once the default path, fell from close to half of respondents to just 30%. Board access has grown alongside it: in Heidrick's earlier research, three in five CISOs already presented to the full board, and nearly four in five presented to a board committee.

Why this matters: a CISO reporting through a CIO answers, in practice, to someone whose own priorities — uptime, delivery speed, cost — can conflict with security's. A CISO reporting to the CEO or the board is being asked to own the risk conversation directly, which raises the stakes on getting the underlying facts right the first time, not the second.

What CISOs Earn, and Why Compensation Keeps Climbing

CISO pay has climbed sharply, and two independent 2025 studies show it from different angles. Heidrick & Struggles found median total compensation for US CISOs at $880,000 in 2025 (average $1.447 million), with the top quartile managing teams of 100 or more and budgets above $50 million; equity made up a growing share of total pay, especially at the top end. IANS Research and Artico Search, surveying 566 US and Canadian CISOs, recorded a 6.7% year-over-year rise in overall compensation — even as security budgets grew only 4%, the slowest rate in five years. Pay varies sharply by industry: IANS put the average in technology at $844,000 and in financial services at $744,000.

Why this matters: compensation rising faster than budget is a signal, not just a data point. Boards are paying more for the person accountable for security risk while giving that person comparatively less new money to reduce it — which puts more weight on getting real value out of every dollar already committed, including the parts of a security program that never show up on an internal dashboard at all.

CISO vs. Other C-Suite Roles

CISO vs. CIO. A CIO owns the organization's full technology stack and how it serves the business. A CISO owns one slice of that — protecting it from threats — and increasingly operates as a check on decisions the CIO's team makes for speed or cost reasons.

CISO vs. CTO. A CTO builds and evolves the technology the business runs on. A CISO decides what's safe to build on top of it, and runs the checks — audits, penetration tests, access reviews — that confirm it actually is.

CISO vs. CPO. A Chief Privacy Officer's job is regulatory: making sure data handling complies with privacy law. A CISO's job is operational: making sure the systems holding that data can't be breached in the first place. The two increasingly have to coordinate, since a privacy failure and a security failure are often the same incident described from two different angles.

CISO vs. vCISO. A virtual CISO delivers the same strategic function as a contractor rather than a full-time hire — a common route for mid-sized organizations that need the judgment without the full C-suite cost. The trade-off is availability: a vCISO typically splits time across several clients, which matters if an incident happens on a day they're not looking at your environment.

Why Organizations Actually Need a CISO

A CISO's core value is straightforward: someone senior enough to make security trade-offs stick, and technical enough to know which trade-offs matter. In practice, that means managing the organization's information assets, getting a defensible return on security spend, tracking a threat landscape that changes faster than any static policy document, and keeping the organization compliant with the standards its customers, regulators, and insurers actually check.

What the role increasingly can't do alone is verify everything it's responsible for. A CISO's internal tools — SIEM platforms, EDR, vulnerability scanners — are built to monitor an organization's own environment. They have no visibility into whether a new vendor's ownership structure hides an undisclosed conflict, whether a board candidate has an adverse-media history that hasn't surfaced yet, or whether employee credentials are already circulating on a dark web forum the organization has never looked at. That's a distinct discipline — investigative verification, not monitoring — and it's where our own work as an intelligence firm sits alongside a CISO's existing security program, not in competition with it.

What to Look for When Hiring a CISO

Organizations hiring a CISO are typically screening for depth across several dimensions at once: hands-on experience managing information assets, fluency in data governance and compliance frameworks, the ability to translate security work into business value a board will fund, and the composure to lead through an active incident rather than just plan for one on paper.

Indicators worth pressure-testing in an interview, not just a résumé:

  • A specific, verifiable incident they led — not a generalized claim of "incident response experience"
  • Direct answers about what actually failed in a past breach, not just what the team did afterward
  • Familiarity with the compliance frameworks your specific industry and regulators actually enforce
  • Evidence they've had to defend a security budget request to a CFO or board, not just spend one

One step organizations routinely skip: verifying the candidate's own background with the same rigor they'd apply to a vendor or an acquisition target. A CISO candidate's résumé claims — prior incident-response outcomes, certifications, the scope of a previous role — are exactly the kind of claims that benefit from independent pre-employment screening rather than a reference check alone, given how much authority and access the role carries from day one.

What a Security Dashboard Doesn't Tell a CISO

Internal monitoring tools answer one question well: what is happening inside our own environment right now? They answer a different, harder question much less reliably: what don't we yet know about the people, vendors, and counterparties our organization depends on?

                                                                                                                                                                                             
Internal security monitoringInvestigative verification
What it coversNetwork traffic, endpoint activity, and log data generated inside the organization's own systemsPeople, companies, and claims outside the organization's systems — vendors, executives, board candidates, counterparties
Catches an undisclosed vendor ownership conflict?No — a SIEM has no visibility into who actually controls a supplierYes — traced through corporate registries, court records, and vendor verification work
Flags a board or executive candidate's adverse-media history?NoYes — through adverse media screening across languages and jurisdictions
Detects leaked credentials or insider chatter before exploitation?Partially — depends on what's already inside the monitored perimeterYes — through dark web intelligence work outside it
Assesses cyber risk in a specific M&A target or new vendor before signing?No — internal tools have nothing to monitor until the relationship already existsYes — through cybersecurity due diligence run before the decision, not after
Best used forContinuous visibility into the organization's own systemsPoint-in-time and ongoing verification of everything outside them

Why this matters: a CISO who only monitors misses exactly the risks that never touch their own network until it's too late — an undisclosed conflict of interest, a compromised vendor, an executive hire whose background doesn't hold up. Our own risk intelligence work and broader digital risk management practice exist specifically to close that gap — verifying what a dashboard was never built to see. Where cybersecurity risk overlaps with a broader vendor relationship, we typically run it alongside third-party risk due diligence, since the two questions — is this vendor secure, and is this vendor who they claim to be — usually need answering together.

FAQ

What does a CISO do day to day?

Day to day varies with organization size, but the constants are: reviewing security posture and open incidents, managing the security team and its priorities, working with other executives on decisions that touch risk (a new vendor, an acquisition, a product launch), and reporting status up the chain — to a CIO, a CTO, the CEO, or the board, depending on the organization's structure.

Is a CISO the same as a CTO or CIO?

No. A CIO runs the organization's overall technology strategy and operations. A CTO builds and evolves the technology products and infrastructure. A CISO's mandate is narrower and specific: protecting whatever the CIO and CTO build and run from security threats, and making the trade-offs that keeps it defensible.

What's the difference between a CISO and a vCISO?

A CISO is a full-time employee; a virtual CISO (vCISO) delivers the same strategic function as an external consultant, typically split across multiple client organizations. It's a common way for mid-sized companies to get senior security judgment without a full C-suite salary, at the cost of having that judgment's full-time attention.

How much does a CISO earn?

US CISOs' median total compensation reached $880,000 in 2025, with an average of $1.447 million once equity is included (Heidrick & Struggles, 371 CISOs). A separate benchmark of 566 US and Canadian CISOs recorded a 6.7% year-over-year rise in total compensation in 2025, with average pay varying by industry — $844,000 in technology and $744,000 in financial services (IANS Research & Artico Search).

Who does a CISO report to?

Historically, most CISOs reported to a CIO or CTO. That's shifted quickly: as of Heidrick & Struggles' 2025/2026 survey, 42% now report directly to the CEO, while direct reporting to a CIO or CTO has fallen to 30% of respondents.

What certifications does a CISO need?

There's no single required credential, but CISA and CISM (both ISACA) and CISSP (ISC2) are the certifications that carry the most weight in hiring, alongside a track record of leading through real incidents rather than only holding the paper qualification.

Who was the first CISO?

Steve Katz, hired by Citicorp in 1995 after an attempted $10 million fraud the year before, in which hackers moved roughly $400,000 out of the bank before the scheme was caught. The role was created specifically because that incident showed security needed a single named executive owner.

Does every company need a full-time CISO?

Not necessarily. Smaller organizations often use a vCISO to get equivalent strategic judgment without the full-time cost. What every organization handling meaningful data or facing real regulatory exposure needs is someone with clear, senior-level ownership of security decisions — whether that person is full-time, virtual, or shared.

How does external verification fit into a CISO's work?

Alongside it, not instead of it. A CISO's internal tools monitor the organization's own environment well. They can't verify a vendor's real ownership, confirm a board candidate's background, or search the dark web for signs the organization's own credentials are already exposed. That verification work is a distinct discipline from security monitoring, and it's where an intelligence firm's investigative methodology complements a CISO's existing program rather than duplicating it.

Turn Intelligence Into Action
Order a service
Order a service
Black Plus Icon

Recent posts

View all
View all
White Plus Icon

01 September 2026

Molfar Intelligence Joins IT Ukraine Association

Molfar Intelligence has joined IT Ukraine Association, deepening its involvement in the technology community and expanding opportunities for research, knowledge exchange, and industry cooperation.

View all
View all
White Plus Icon
Gain the Clarity You Need to Move with Confidence

Let’s connect to explore how tailored intelligence can strengthen your decisions, reveal opportunities, and minimise uncertainty.