Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Entering The New Age Of The CISO
Articles

Entering The New Age Of The CISO

Paul GermanBy Paul GermanNovember 26, 2018Updated:December 30, 20214 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The role of a CISO is undoubtedly changing. Not only does the role now require more responsibility than ever, but the heightened risks associated with the role has put it firmly in the spotlight of both the company Board and the industry as a whole.

And, when it comes to a data breach, the simple fact is that someone will always have to accept responsibility – whether it’s the CISO, CIO or CEO. The huge amount of data breaches that can now be recalled show that cybersecurity failures can be fatal; a major data breach will ruin not only an organisation’s bottom line, but also pose major risks to its reputation, brand and future. Once a breach has occured, customers or other stakeholders will be far more wary of engaging with the business; and dealing with the fallout of a breach often means difficult decisions need to be made. The question remains: where does the role of the CISO fit in?

CISO who?

Despite the risks that the role now has a reputation for, numerous organisations are starting to see the value of employing someone to specifically deal with the increasingly sophisticated cyber threats, either because they have the right Information Assurance (IA) mindset or because of the increasing pressures around compliance, risk and governance.

In the past few years, the role of the CISO has left behind its traditional responsibilities and core tasks of specifically developing, deploying and maintaining an information security programme, serving to protect all of the data stored and processed by a business, morphing into a much more integral role of identifying risk across the entire business and raising awareness to employees of the damage a data breach can cause. Additionally, the role now has a direct reporting line to the Board of Directors rather than a CIO or CTO, extending visibility and accountability.

The essential CISO qualities

Diligent, attentive and risk aware are just three of the main characteristics vital to the role of the CISO. Whilst the characteristics can vary from organisation to organisation, a CISO needs to be extremely aware of the risks surrounding not only their role, but the entire organisation. New threats need to be identified and new protocols put in place, all of which needs to be consistently managed and maintained to keep up with the evolving threat landscape.

Being an excellent communicator and understanding various audiences is also key; explaining the threats or solutions to a non-technical Board won’t get a CISO very far – and having the Board on side with cybersecurity efforts is essential. The Board wants to hear about the financial implications, so shying away from the possibilities won’t get a CISO very far. Removing tech jargon that really isn’t applicable is also a crucial quality because the board of directors need to be fully aware that cyber risk now has fiduciary implications and therefore needs to be given the time and attention it deserves.

Focus on the data, not the network

Technology decisions are vital for ensuring the organisation is secure; with numerous attack techniques in existence that have the ability to not only infiltrate, but destroy an organisation’s network, it is critical for organisations to think about IA, which focuses on the data, rather than security, which focuses on the network. By understanding the sensitivity and risk of data compromise the CISO is able to focus on technology decisions that protect the data itself and not just the network the data runs over as when the network is compromised it is data that is put at risk – and we all know the consequences this can have.

The need to separate roles in an organisation into discrete functions is imperative; ‘Separation of Duties’ removes the cross contamination of roles, which therefore increases accountability, reduces error potential and removes the potential for non-essential personnel to access the security configuration of network devices. This separation of duties also needs to happen within the technology itself by adopting an overlay security posture, allowing both flexibility and agility to be extended across all networks whether owned or not, whilst ensuring zero impact to the security posture when the network is changed or compromised. Every CISO should understand how fundamental this is.

Starting at the top

Whilst the correct security mindset must start at the top, in reality it also needs to be embedded across all practices within an organisation; extending beyond the security team to legal, finance and even marketing. The responsibility of securing the entire organisation’s network sits with the CISO, but the catastrophic risks of a cybersecurity failure means that it must be given consideration by the entire Board and become a top priority in meeting business objectives.

Paul German

Paul German, CEO at Certes Networks

  • Paul German
    SASE – The Risk Of Over-rationalising
  • Paul German
    Government Cloud On-Ramping
  • Paul German
    High Assurance Delivers SD-WANs For All
  • Paul German
    Harvest Now, Decrypt Later

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}