CISO Tribune

Analysis

The title upgrade: when 'Chief Trust Officer' replaces 'CISO'

HubSpot's hire of Geoff Belknap as Chief Trust Officer revives a naming debate with real stakes. What the title signals, and what it changes.

By Lla Odi · Published September 21, 2026 · 3 min read

The title 'Chief Trust Officer' is not a rebrand of CISO for optics. When a company uses it for its top security seat, it signals a deliberate scope decision with organizational consequences. HubSpot's appointment of Geoff Belknap as Chief Trust Officer this week puts the question back on the table. Belknap brings CISO experience at LinkedIn, Slack, and Palantir, and most recently served as Corporate VP and Operating CISO at Microsoft. HubSpot calling his seat something different is a choice worth reading carefully.

What does 'Chief Trust Officer' actually mean?

There is no standard definition. The title appears infrequently enough that each company using it is effectively defining it themselves. The working assumption in most cases is that the scope exceeds classic CISO territory: privacy, compliance, and customer-facing transparency are folded in alongside security engineering and operations. The word 'trust' points outward, toward customers and partners, in a way that 'information security' does not.

For a company like HubSpot, which sells software to hundreds of thousands of businesses and handles their customer data, that outward orientation is commercially legible. A prospect evaluating a CRM vendor does not think in terms of firewalls; they think in terms of whether the vendor will protect their data and tell them the truth when something goes wrong. A Chief Trust Officer title is, in part, a signal to that audience.

Does the title change the job?

Probably yes, at the margin, and in two directions. First, it broadens the mandate on paper. If the role owns privacy and transparency alongside security, the CISO equivalent is now accountable for things that in other organizations live in legal, compliance, or a separate privacy officer function. That is a larger seat, or a more fractured one, depending on how authority is allocated beneath the title.

Second, it changes the external-facing posture. A Chief Trust Officer is more likely to appear in customer conversations, regulatory engagements, and public disclosures than a CISO who runs primarily internal. Belknap's background makes him credible in that posture: CISO roles at consumer-facing platforms like LinkedIn and Slack already carry external visibility that more infrastructure-focused security roles do not.

Whether the day-to-day work differs meaningfully from a well-scoped CISO mandate is a thinner claim. The evidence from this week's records alone is insufficient to say. The pattern is suggestive, not settled.

What does this week's broader move set tell us?

Set alongside the other appointments in the record, a contrast emerges. Ruben D. Chacon joining ADM as VP and Global CISO and Frank Krieger named CISO at Swap both carry the traditional title without modification. Chacon brings a long sequence of CISO roles across food and beverage, energy, and technology companies. Krieger arrives at a fintech from a prior CISO seat at Mambu, with governance and risk roles before that. Both are straightforward title-to-title moves.

HubSpot's choice to use a different title for a hire of Belknap's seniority is therefore not industry-wide drift. It is a specific company making a specific naming decision. That makes it more informative, not less: when a company of HubSpot's size recruits an executive with Belknap's profile and then calls the job something other than CISO, it is worth asking what they are trying to accomplish.

Should other companies consider the title?

Only if the scope genuinely matches it. The risk of adopting 'Chief Trust Officer' without expanding the mandate is straightforward: it reads as marketing. Customers and practitioners will test the title against what the person actually controls. A Chief Trust Officer who does not own privacy decisions, has no customer-facing transparency function, and reports to the CIO in the same structure as a legacy CISO is just a CISO with a different badge.

The more honest use of the title is what HubSpot appears to be attempting: a deliberate signal that security, privacy, and customer accountability are unified under one executive who has the seniority and external credibility to represent those commitments publicly. Whether the structure supports that claim is something the record will show over time, not on appointment day.

Lla Odi

Editor

Lla Odi is the editor of CISO Tribune and sets the standards every record is held to: sources opened and read, titles checked against the top-seat standard, dates held to their honest precision, unknowns stated as unknowns. Contested departures, interviews and corrections cross this desk before they go live. Corrections and tips reach the editor directly at editorial@cisotribune.com.

The Briefing

Every verified CISO move of the week, in your inbox Friday.

Every verified CISO move and one piece of analysis, weekly.

Unsubscribe any time. See the privacy policy.