How many direct reports away from the CEO is the senior-most security executive?

Direct report10%

127%

232%

319%

48%

>52%

lock icon

Please join or sign in to view more content.

1133 PARTICIPANTS
12.6k views3 Upvotes6 Comments
Sort By:
Oldest
Group Chief Information Officer in Construction5 years ago
The answer of this question is vary depending on our industry and maturity of the corporate
2 4 Replies
Director Certifications in Education4 years ago

This is a very good question, and Ali is right depend on the industry and if the company is publicly traded. My experience is the CISO should report administratively to the CIO, but have a direct report to the CEO. The reason  is that the CEO needs to hear directly from the security guy, this prevent the CIO from sugarcoat the state of security in the organization.

Senior Director, Defense Programs in Software3 years ago

Help me understand why a CISO should report administratively to the CIO.

If a CISO should have a direct report to the CEO, why shouldn’t the CIO report to the CISO and solve this multi-reporting structure?

1
Director Certifications in Education4 years ago
The senior-most security executive is the CISO.  For most organizations, I recommend reporting directly to the CEO.
1

Content you might like

TCO19%

Pricing26%

Integrations21%

Alignment with Cloud Provider7%

Security10%

Alignment with Existing IT Skills4%

Product / Feature Set7%

Vendor Relationship / Reputation

Other (comment)

View Results
5.7k views3 Upvotes1 Comment
Head of Enterprise Architecture MERCK Group in Healthcare and Biotecha year ago
Strategy & Architecture
Read More Comments
39k views5 Upvotes34 Comments

Human Factors (fears, mental health, physical spacing)85%

Technical / IT Factors (on-premise tools, pivoting back away from remote)14%

3.7k views3 Upvotes2 Comments