CISO Tribune

Analysis

The deputy CISO: when you need one, and how to make the role real

When a security org needs a deputy CISO, what the role should own, succession value, and the failure modes that make deputies decorative.

By CISO Tribune Editorial · Published July 22, 2026 · 2 min read

TL;DR: A deputy CISO is how a security program stops being one resignation away from leaderless. The role works when it owns a real half of the job — typically the inside (operations, delivery, incident command) while the CISO works the outside (board, regulators, customers) — and fails when it's a title glued to a staff role. Build it before the org needs it, because the need arrives without notice.

What signals say it's time?

Four, any two of which suffice. Single point of failure: if the CISO is unreachable for a week, incident command and executive escalation have no owner — a resilience gap regulators and insurers have started asking about directly. Calendar inversion: board prep, customer security reviews, and regulator relationships now consume the CISO's week, and the internal program is being led in the margins. Span of control: the org has grown past the point where one leader can develop its managers. Succession silence: if the CISO resigned tomorrow, the honest internal answer is an interim from IT and a nine-month search. Companies that wait for the resignation to discover the fourth signal pay for it twice.

How should the role be split?

The durable pattern is inside/outside, not "everything the CISO doesn't want." The deputy owns program execution: security operations and incident response (including genuine incident-command rotation — commanding, not shadowing), engineering and project delivery, team management and development, and the operational metrics. The CISO owns direction and representation: strategy, board and executive relationships, regulators, major customers, budget ownership, and the final risk-acceptance conversations. Two alternates work in specific contexts — a functional split (deputy owns GRC-and-governance in audit-heavy industries) or a regional split in global firms. The one that never works: deputy as chief-of-staff-with-a-grand-title, all exposure and no command.

What makes a deputy real rather than decorative?

Authority artifacts, in writing: standing incident-command authority with the same system-shutdown rights as the CISO; budget delegation with a real threshold; a defined risk-acceptance tier they can sign; scheduled board or committee exposure at least annually (succession value evaporates if directors have never met them); and explicit deputization — internally announced — for the CISO's absences. The test is simple: on a bad Saturday with the CISO on a plane, can the deputy take the revenue system offline and brief the CEO without anyone asking whether they're allowed to? If not, the org has a senior director and a hope.

How should companies think about the succession angle?

Honestly: a good deputy is simultaneously your continuity plan and a flight risk, because deputy CISO is the most common launchpad to a first CISO seat elsewhere. The rational response isn't to withhold development — an underdeveloped deputy is just a worse continuity plan — it's to run the race deliberately: give the deputy real scope and board visibility, pay them like the succession plan they are, and agree on a trajectory ("you're the plan; here's the timeline conversation") rather than leaving ambition to fester into a surprise resignation. Some deputies will still leave for their seat. The program they built, the bench below them, and the incident calm they normalized stay — which is most of what the role was for.

Frequently asked questions

What does a deputy CISO do?
The strongest pattern gives the deputy the inside of the program — operations, engineering delivery, incident command rotation, and much of team leadership — while the CISO faces outward to the board, regulators, executives, and customers. Two real jobs, split by direction.
When does a security team need a deputy CISO?
Reliable signals: the CISO is the single point of failure for incident command, board and customer demands consume most of the CISO's calendar, the security org has grown past what one leader can develop, or succession has no internal answer.
Is deputy CISO a stepping stone to CISO?
It is the single most common path to a first CISO seat — either by inheriting the role internally or by taking the top job at a smaller organization. For companies, that means deputies are both resilience and a retention race.

CISO Tribune Editorial

Editorial Desk

The CISO Tribune editorial desk reports on security leadership: who holds the role, who is leaving it, and what the moves mean. Every appointment entry is verified against a primary source before publication.