Guide
What Does a CISO Do? Responsibilities, Reporting Lines and Required Skills
A CISO owns an organization's cybersecurity risk end to end: strategy, the security program, incident response and the board conversation. Sourced to NIST, CISA, Okta, Splunk and IANS Research.
TL;DR: A Chief Information Security Officer owns an organization's cybersecurity risk end to end: setting the strategy, running the security program day to day, handling incidents, and answering for all of it in the boardroom. The technical work increasingly sits with the team the CISO builds; the CISO's own, undelegable job is turning that work into a business and risk story the rest of the executive suite and the board can act on, a skill boards say they are not yet getting well (IANS Research, March 2026).
What is a CISO, exactly?
A CISO is the executive accountable for an organization's information and cybersecurity risk. Okta's breakdown of the role describes the CISO as responsible for protecting intellectual property, data and information assets across technical, informational and physical domains, and for establishing, implementing and maintaining everything related to data security and IT risk. Splunk's explainer frames it the same way: developing and implementing security policy, managing the security organization, and coordinating the response when something goes wrong.
The title sits in the C-suite, which is the point. A CISO is not the most senior security engineer; it is the executive whose job is to decide what the organization's security posture should be, fund it, staff it, and defend that judgment to people who do not read packet captures. CISO Tribune's own record of appointments and departures, which tracks only this top security seat and excludes deputy, assistant and associate titles, exists because that distinction (who actually holds final accountability for the seat) is easy to get wrong from a press release alone.
CISO and Chief Security Officer (CSO) are often the same job under different titles. Where a company has both, the CSO role sometimes extends to physical security and the CISO stays scoped to information and cyber risk, but there is no universal rule; read the reporting line and the mandate, not the title.
What does a CISO actually do, day to day?
Strip away the vendor pitches and the job maps closely onto a public framework the industry already uses to describe cybersecurity work. NIST's Cybersecurity Framework organizes that work into functions, and NIST's own description of the original five is a reasonable outline of what a CISO's program has to cover:
- Identify: developing the organization's understanding of its cybersecurity risk across systems, people, assets, data and capabilities.
- Protect: the safeguards that keep critical services running.
- Detect: the activities that surface a cybersecurity event when it happens.
- Respond: the actions taken once an incident is detected.
- Recover: restoring capabilities and services an incident impaired, and building resilience for next time.
NIST updated the framework to version 2.0 in February 2024, adding a sixth function, Govern, covering how the organization's cybersecurity risk strategy, roles and policy are set, communicated and monitored, which is explicitly the CISO's own layer of the work: the other five functions describe the security program; Govern describes the CISO's job of running it as a program with real authority, not a side project. In a job description, this usually shows up as: set the security strategy and policy; own the budget and staffing for the security organization; run or oversee the security operations center, vulnerability management and incident response; manage third-party and supply-chain risk; carry regulatory and compliance obligations; and report the resulting risk picture to the CEO and the board.
The NICE Workforce Framework for Cybersecurity, maintained by CISA, defines a matching work role it calls Executive Cybersecurity Leadership: establishing vision and direction for an organization's cybersecurity operations and resources, with the authority to make and execute decisions that affect the organization broadly, including policy approval and stakeholder engagement. That authority, not any specific technical task, is what separates the CISO from the engineers and analysts who report into the program.
Who does a CISO report to?
There is no single answer, and the answer has been moving. Historically the CISO reported to the CIO, nesting security inside the IT organization. Splunk's research on the role found that has changed enough that 61% of CISOs no longer report to the CIO; instead they report to the CTO, the COO, or directly to the CEO. The shift reflects a long-running argument that a function with a mandate to say no to the rest of IT should not report through IT's own budget holder.
A growing minority report into the board or a board risk committee, especially at public companies where directors want an unfiltered view rather than one shaped by whoever the CISO's manager happens to be. Reporting line is a useful proxy for how seriously a company treats the function: a CISO who reports to the CEO or the board, and presents to the board directly on a standing schedule, has a different mandate than one who reports two levels down inside engineering.
Whoever the formal reporting line runs to, the board relationship is the part under the most pressure right now. IANS Research's board-relationships study, published in March 2026, found only 29% of board directors rate the cybersecurity updates they get from their CISO as very effective, while 53% call them only somewhat effective. Boards gave their best marks to reporting on regulatory trends affecting risk (82% rated it good or better) and their worst to reporting on the impact of fast-moving threats, where 53% said quality needs to improve and only 6% called it excellent. Read plainly: boards trust their CISO to explain what the rules require, and trust them far less to say, credibly, what is coming next.
What skills and background does the job need?
Both Okta and Splunk describe a similar mix: deep grounding in security, IT risk or a related technical discipline, paired with skills that have nothing to do with a keyboard. Okta's summary puts it directly: the aptitude to explain technical and IT security issues in terms a non-technical executive can understand is essential to the role, not a nice-to-have. Splunk adds business and risk-management literacy, financial planning (the CISO owns and defends a budget), incident management under pressure, and people leadership, since a CISO typically runs a department rather than a desk.
Certifications such as CISSP are common on a CISO's résumé and signal baseline technical credibility, but neither source treats a certificate as the qualifying credential. The actual bar is track record: has this person run a security program before, through an incident, in front of a board, and lived with the budget tradeoffs that come with the job.
Compensation and career path
Pay varies enormously by industry, company size and geography, but Splunk's research put a number on the center of the range: as of January 2024, CISOs had a median annual total salary of $386,000, with total compensation reaching $585,000 before bonuses at the high end, and banking and financial-services roles often landing between $180,000 and $400,000 before incentive pay. Treat any single figure as a snapshot rather than a current market rate; compensation in security leadership has moved quickly in both directions as the role's visibility and liability have grown.
The path into the seat rarely runs through one track. People arrive from security engineering and architecture, from IT risk and compliance, from consulting, and increasingly from adjacent executive roles where they already carried board-level accountability. What the job increasingly selects for, per both sources above, is less "deepest technical expertise" and more "can run a function, own its risk, and be believed by the people who are not in security."
How the job is changing in 2026
Two forces are reshaping the role beyond the day-to-day list above. The first is regulation: disclosure rules now put a named executive's judgment about what counts as a "material" cybersecurity incident on the record, which raises the cost of getting the board conversation wrong and is its own guide (coming to CISO Tribune's guides section). The second is the board-trust gap IANS documented: boards increasingly want a forward-looking risk narrative, not a status report, and that is a different skill than running the program itself.
CISO Tribune's own record reflects the consequence: a steady flow of appointments and departures at named companies, and a running list of seats currently open where a verified departure has no verified successor yet. That is CISO Tribune's own count of what our record shows, not an industry-wide statistic; it is a byproduct of boards and CEOs replacing people in this seat often enough that tracking it, company by company, is worth doing. If you are trying to understand a specific move rather than the role in the abstract, the Wire is the place to start, and company pages show the succession history behind any single appointment.
Frequently asked questions
- What does CISO stand for?
- Chief Information Security Officer: the senior executive responsible for an organization's information and cybersecurity risk, strategy and program.
- Is a CISO the same as a CSO?
- Often, but not always. At most companies the titles are used interchangeably for the top security seat. Where both exist, the CSO sometimes also covers physical security and the CISO stays focused on information and cyber risk; CISO Tribune's own record tracks the top security seat under either title.
- Does a CISO need to be technical?
- A technical background helps the CISO evaluate the program credibly, but the job itself is executive: translating technical risk into business decisions, running a budget, and briefing the board. Okta's and Splunk's role breakdowns both describe the communication and business skills as being as important as the technical ones.
- Who does a CISO report to?
- It varies by company. Traditionally CISOs reported to the CIO; Splunk's research on the role found 61% no longer do, reporting instead to the CTO, the COO or directly to the CEO. A smaller group reports to the board or a risk committee directly.
- What is the hardest part of the CISO job right now?
- Board communication under harder scrutiny. IANS Research's March 2026 study found only 29% of board directors rate their CISO's updates as very effective, and reporting on how fast-moving threats and AI affect the business is the area boards rate worst.
Sources
- NICE Workforce Framework for Cybersecurity: Executive Cybersecurity Leadership · CISA (NICCS), October 7, 2026
- The Five Functions (NIST Cybersecurity Framework) · NIST, October 7, 2026
- Cybersecurity Framework · NIST, October 7, 2026
- What Does a CISO (Chief Information Security Officer) Do? · Okta, October 7, 2026
- The CISO Role: What Does a Chief Information Security Officer Do? · Splunk, October 7, 2026
- Boards Give CISO Cybersecurity Reporting a Mixed Grade · IANS Research, March 24, 2026
Hadass Liza Bitton
Writer
Hadass Liza Bitton is a writer at CISO Tribune covering security leadership: the people who take the top security seat, the ones who leave it, and what each move signals. Reach her at hadass@cisotribune.com.
The Briefing
Every verified CISO move of the week, in your inbox Friday.
Every verified CISO move and one piece of analysis, weekly.
Unsubscribe any time. See the privacy policy.