Guide
Does the CISO Report to the CIO? What 22 SEC 10-K Filings Actually Say
CISO Tribune read the cybersecurity governance disclosure (Item 1C) in 22 companies' own, freshly filed Form 10-K reports. Only one named its CISO, and that filing was already out of date by the time the person left. Here is what the filings actually say about reporting lines.
TL;DR: Every U.S. public company has to describe its cybersecurity governance once a year, in Item 1C of its Form 10-K. CISO Tribune fetched the most recent Item 1C disclosure from 22 companies this week and read what each one actually says about its CISO. Only one, Meta, named its CISO, and that filing was already stale by the time the person left the job. Three filings state a specific reporting line, and the three do not agree with each other. Two large companies disclose more than one CISO. Two disclose no security-officer title at all. The rule sets a floor on what a company must say about cybersecurity governance; it does not require the company to say who runs it.
The question this answers
A 10-K is a primary source: a company's own, legally binding statement about itself, filed with the SEC under penalty of civil liability for getting it wrong. That makes Item 1C, the annual cybersecurity governance section required since fiscal year 2023, look like an obvious place to verify who holds a company's top security seat. It mostly is not, and the gap between what the rule requires and what a reader might assume it requires is the actual finding here.
Methodology
CISO Tribune built a keyless SEC EDGAR research tool this week that looks up each company's CIK from the SEC's own public ticker file, searches the EDGAR full-text search API for "Chief Information Security Officer" and "Chief Security Officer" within that company's Form 10-K filings, and fetches the most recent match. The 22 companies are drawn mostly from CISO Tribune's own roster-verification queue (large, well-known public companies whose current CISO is not yet sourced on our roster) plus a handful of additional large, well-known companies added for contrast. This is not a random sample and not a full S&P 500 census; it is a first read of a genuinely new, keyless source, with the actual filing text behind every claim below. A broader pass across more companies is the obvious next step, and CISO Tribune's growth backlog already lists it.
Two search-tool limitations surfaced while reading these filings, both worth naming so the counts below are read correctly. First, EDGAR's full-text search matches an exact phrase, so a plural-only mention, "Chief Information Security Officers," as Comcast's filing uses throughout, does not match a singular-phrase query; Comcast's disclosure was found only by reading the filing directly after the phrase search came back empty. Second, a company can satisfy Item 1C without using either phrase at all, describing cybersecurity governance entirely through teams and committees, which is exactly what two of the 22 filings below do.
Finding one: naming the person is rare, and the one example went stale fast
Of 22 Item 1C disclosures read for this piece, exactly one names the sitting CISO: Meta's Form 10-K, filed January 29, 2026, says "Meta's Chief Information Security Officer (CISO), Guy Rosen, leads our cybersecurity program." That sentence was accurate when filed. Rosen announced his departure from Meta in June 2026, and Meta named Assaf Keren as his successor in July 2026, both moves CISO Tribune's Wire recorded as they happened. A reader pulling Meta's 10-K today without checking its filing date would be citing a person who no longer holds the job. The lesson generalizes beyond Meta: a 10-K is filed once a year, on a schedule driven by the fiscal calendar, not by personnel changes, so even the rare filing that names a name carries an expiration date the filing itself never states.
Finding two: reporting lines are stated rarely, and inconsistently when they are
The conventional wisdom, covered in CISO Tribune's guide to what a CISO does, is that the CISO traditionally reported to the CIO, and increasingly does not. These 22 filings mostly do not settle the question either way, because most do not say. Three do:
- Chevron: "Chevron's Chief Information Security Officer (CISO) reports to the CIO."
- Humana: "Our Chief Information Security Officer reports to our Chief Information Officer."
- Nvidia: the filing states Nvidia has "designated a Chief Security Officer, reporting to our Senior Vice President of Software Engineering," a title that is neither CIO nor CISO, and a reporting line that runs through engineering rather than IT.
A fourth, Costco, describes its CISO as part of the Chief Information and Digital Officer's "executive team," which reads as a reporting relationship without using the words "reports to." The remaining 18 filings mention a CISO's existence, scope and sometimes tenure without stating a reporting line at all, which means a claim like "most CISOs report to the CIO" cannot be verified from these filings themselves, however common it may be in practice or in survey data from firms that ask the question directly.
Finding three: some large companies disclose more than one CISO
Two of the 22 companies do not have a single, company-wide CISO to report a line for in the first place. Berkshire Hathaway's filing describes cybersecurity governance at the level of its individual Business Groups: "Each Business Group's Chief Information Security Officer ('CISO') on at least an annual basis is to provide a report to the Business Group's senior management." Comcast's filing is explicit that it has more than one: "our primary businesses' Chief Information Security Officers ('CISOs')," naming a dedicated CISO for its Connectivity & Platforms business and another for its Content & Experiences business. Both are large, decentralized companies whose separately run operating businesses each warrant their own security leadership, which is exactly the kind of structure that makes "who is the CISO of Comcast" an unanswerable question as asked, and part of why some entries on CISO Tribune's own roster are marked unknown rather than forced into a single name.
Finding four: two filings name no security-officer title at all
Tesla's Item 1C disclosure describes incident response as overseen by "leaders from our Information Security, Product Security, Compliance and Legal teams," never naming a Chief Information Security Officer or Chief Security Officer. Valero Energy's disclosure goes further into committee structure, an "Infosec Committee," an "Infosec Oversight Committee" and an "Executive Steering Committee," run by "the heads of our information services and internal audit teams," again with no officer title anywhere in the section. Item 106 requires a description of risk management processes and oversight; it does not require that description to center on a named role, and these two filings show a company can comply without one.
What the 22 filings say, company by company
| Company | Filing read | Names the CISO? | States a reporting line? |
|---|---|---|---|
| Chevron | FY2025 10-K, filed 2026-02-24 | No | Yes, to the CIO |
| Meta Platforms | FY2025 10-K, filed 2026-01-29 | Yes (Guy Rosen, now stale) | No |
| Costco | FY2026 10-K, filed 2026-10-07 | No | Implied, under the CIDO |
| Nvidia | FY2026 10-K, filed 2026-02-25 | No (role titled CSO, not CISO) | Yes, to an SVP of Software Engineering |
| Comcast | FY2025 10-K, filed 2026-02-03 | No (multiple CISOs, by business) | No |
| Berkshire Hathaway | FY2025 10-K, filed 2026-03-02 | No (one CISO per Business Group) | No |
| Cigna | FY2025 10-K, filed 2026-02-26 | No | No |
| Cardinal Health | FY2026 10-K, filed 2026-08-11 | No | No |
| Ford | FY2025 10-K, filed 2026-02-11 | No | No |
| Elevance Health | FY2025 10-K, filed 2026-02-06 | No | No |
| Centene | FY2025 10-K, filed 2026-02-17 | No | No |
| Kroger | FY2025 10-K, filed 2026-03-31 | No | No |
| Marathon Petroleum | FY2025 10-K, filed 2026-02-26 | No | No |
| Valero Energy | FY2025 10-K, filed 2026-02-25 | No (no officer title named) | No |
| Humana | FY2025 10-K, filed 2026-02-19 | No | Yes, to the CIO |
| Morgan Stanley | FY2025 10-K, filed 2026-02-19 | No | No (overseen by a named non-CIO risk role) |
| Tesla | FY2025 10-K, filed 2026-01-29 | No (no officer title named) | No |
| Dell Technologies | FY2026 10-K, filed 2026-03-16 | No (separate CISO and CSO roles) | No |
| PepsiCo | FY2025 10-K, filed 2026-02-03 | No | No |
| UPS | FY2025 10-K, filed 2026-02-17 | No | No |
| Johnson & Johnson | FY2025 10-K, filed 2026-02-11 | No | No (works "in coordination with" the CIO) |
| FedEx | FY2026 10-K, filed 2026-07-20 | No | No |
What this means if you are trying to verify a CISO
A 10-K is still a genuine primary source, strong enough to confirm that a named person held a title as of a specific filing date, which is exactly how this piece caught Meta's filing going stale. It is a poor tool for finding out who holds a job today, since it updates once a year on the company's fiscal calendar rather than when the job changes hands, and most companies do not name the person in it at all. It is a reasonably good tool for a narrower, better question: what does the company say, in a legally binding filing, about how it governs cybersecurity and who is accountable to the board for it. That distinction, between confirming a structure and confirming a name, is the one this sample keeps landing on.
What this guide does not cover
This is a snapshot of 22 companies' most recent Form 10-K filings as read this week, not a complete or statistically representative survey of the S&P 500, and not an update every time one of these 22 companies changes CISOs or refiles. CISO Tribune's guide to the SEC's cybersecurity disclosure rules covers what Item 1C and Item 1.05 require in full; this piece is about what companies actually wrote once those rules applied to them.
Frequently asked questions
- Does the SEC require a 10-K to name the company's CISO?
- No. Item 106 of Regulation S-K, which shows up in the filing as Item 1C, requires a description of the company's cybersecurity risk management processes and the board's and management's role overseeing them. It does not require naming the individual who holds the role. Of the 22 companies' most recent Form 10-K cybersecurity disclosures CISO Tribune read for this piece, only one named its CISO.
- Does the CISO usually report to the CIO?
- When a filing states a reporting line at all in this sample, the CIO is the most common answer, but it is not the only one. Nvidia's 10-K says its Chief Security Officer reports to the Senior Vice President of Software Engineering, not to a CIO. Most of the 22 filings read for this piece describe a CISO's existence and responsibilities without stating who the CISO reports to.
- Why do some large companies disclose more than one CISO?
- Berkshire Hathaway and Comcast both disclose a CISO for each of their separately run operating businesses rather than one company-wide CISO. Berkshire's 10-K describes a CISO per Business Group; Comcast's names CISOs, plural, for its Connectivity & Platforms and Content & Experiences businesses. A single top security seat does not exist at every company structured this way.
- If a 10-K names a CISO, is that still who holds the job?
- Not necessarily. Meta's Form 10-K, filed January 29, 2026, named Guy Rosen as Chief Information Security Officer. Rosen announced his departure from Meta in June 2026, and Meta named Assaf Keren his successor in July 2026, moves CISO Tribune's Wire recorded both times. A 10-K describes governance as of its filing date, not as of whenever someone reads it.
Sources
- Chevron Corporation Form 10-K for fiscal year 2025, Item 1C · U.S. Securities and Exchange Commission (EDGAR), February 24, 2026
- Meta Platforms, Inc. Form 10-K for fiscal year 2025, Item 1C · U.S. Securities and Exchange Commission (EDGAR), January 29, 2026
- Costco Wholesale Corporation Form 10-K for fiscal year 2026, Item 1C · U.S. Securities and Exchange Commission (EDGAR), October 7, 2026
- NVIDIA Corporation Form 10-K for fiscal year 2026, Item 1C · U.S. Securities and Exchange Commission (EDGAR), February 25, 2026
- Comcast Corporation Form 10-K for fiscal year 2025, Item 1C · U.S. Securities and Exchange Commission (EDGAR), February 3, 2026
- Berkshire Hathaway Inc. Form 10-K for fiscal year 2025, Item 1C · U.S. Securities and Exchange Commission (EDGAR), March 2, 2026
- The Cigna Group Form 10-K for fiscal year 2025, Item 1C · U.S. Securities and Exchange Commission (EDGAR), February 26, 2026
- Cardinal Health, Inc. Form 10-K for fiscal year 2026, Item 1C · U.S. Securities and Exchange Commission (EDGAR), August 11, 2026
- Ford Motor Company Form 10-K for fiscal year 2025, Item 1C · U.S. Securities and Exchange Commission (EDGAR), February 11, 2026
- Elevance Health, Inc. Form 10-K for fiscal year 2025, Item 1C · U.S. Securities and Exchange Commission (EDGAR), February 6, 2026
- Centene Corporation Form 10-K for fiscal year 2025, Item 1C · U.S. Securities and Exchange Commission (EDGAR), February 17, 2026
- The Kroger Co. Form 10-K for fiscal year 2025, Item 1C · U.S. Securities and Exchange Commission (EDGAR), March 31, 2026
- Marathon Petroleum Corporation Form 10-K for fiscal year 2025, Item 1C · U.S. Securities and Exchange Commission (EDGAR), February 26, 2026
- Valero Energy Corporation Form 10-K for fiscal year 2025, Item 1C · U.S. Securities and Exchange Commission (EDGAR), February 25, 2026
- Humana Inc. Form 10-K for fiscal year 2025, Item 1C · U.S. Securities and Exchange Commission (EDGAR), February 19, 2026
- Morgan Stanley Form 10-K for fiscal year 2025, Item 1C · U.S. Securities and Exchange Commission (EDGAR), February 19, 2026
- Tesla, Inc. Form 10-K for fiscal year 2025, Item 1C · U.S. Securities and Exchange Commission (EDGAR), January 29, 2026
- Dell Technologies Inc. Form 10-K for fiscal year 2026, Item 1C · U.S. Securities and Exchange Commission (EDGAR), March 16, 2026
- PepsiCo, Inc. Form 10-K for fiscal year 2025, Item 1C · U.S. Securities and Exchange Commission (EDGAR), February 3, 2026
- United Parcel Service, Inc. Form 10-K for fiscal year 2025, Item 1C · U.S. Securities and Exchange Commission (EDGAR), February 17, 2026
- Johnson & Johnson Form 10-K for fiscal year 2025, Item 1C · U.S. Securities and Exchange Commission (EDGAR), February 11, 2026
- FedEx Corporation Form 10-K for fiscal year 2026, Item 1C · U.S. Securities and Exchange Commission (EDGAR), July 20, 2026
Hadass Liza Bitton
Writer
Hadass Liza Bitton is a writer at CISO Tribune covering security leadership: the people who take the top security seat, the ones who leave it, and what each move signals. Reach her at hadass@cisotribune.com.
The Briefing
Every verified CISO move of the week, in your inbox Friday.
Every verified CISO move and one piece of analysis, weekly.
Unsubscribe any time. See the privacy policy.