CCCS 453 - Security Risk Management and Governance
Assignment #1: A CISO’s responsibilities and reporting
Mitchell Hughes – ID #########
Raul Felix Barbosa – ID 261251846
Although the traditional model still establishes the CISO under the CIO, or Head of IT, data finds that
about one-third of CISOs (about 33%) still follow this reporting structure. This reporting structure is
helpful for aligning responsibilities with the organization's IT functions, but may create potential conflicts
of interest because a CIO is typically focused on efficiency and innovation when it comes to the IT
function, and the CISO desires to enforce controls and restrictions when protecting the organization.
More organizations, particularly those that recognize security as a strategic issue, are establishing the
CISO as a direct report to the CEO. Although only about 20% of CISOs currently report to the CEO, this
shift is becoming more common and will give the CISO role greater visibility and decision-making
power, but will also require the CEO to address technical and risk-related issues. In more regulated, or
risk-mature, industries, it's also common for CISOs to report to other C-suite leaders. About 39% of
CISOs are in this group, working under titles such as CFO, CRO, COO, or General Counsel. In these
scenarios, security is often seen less as a technical concern and primarily as an enterprise risk,
compliance, or financial matter.
While it is rare for CISOs to report directly to the board of directors, many are now giving the board
regular briefings. This makes cybersecurity a governance issue at the C-level and ensures security is
integrated with overall risk governance.
References:
Hitch Partners. 2025 CISO Security Leadership Survey Results. San Francisco: Hitch Partners,
2025. [Link]
The National CIO Review. “The CISO’s Tightrope: Balancing Security, Business, and Legal
Risks in 2024.” The National CIO Review, March 14, 2024.
[Link]
balancing-security-business-and-legal-risks-in-2024/.