CISOs are gaining more influence in the boardroom, and it’s about time
Closer ties between CISOs and C-suite execs offers marked benefits for enterprises


The role of the CISO is growing in status as cybersecurity becomes an increasingly pressing issue for enterprises globally, new research shows.
A recent study from Splunk shows security execs are being granted more powers to make strategic decisions for the business and are fostering closer collaborative ties with the boardroom and CEO.
More than eight-in-ten CISOs now report directly to the CEO, a huge increase from 47% in 2023. Meanwhile, 83% participate in board meetings somewhat often or most of the time.
However, while six-in-ten acknowledge that board members with cybersecurity backgrounds have a more powerful influence on security decisions, only 29% say their board includes at least one member with cybersecurity expertise.
"As cybersecurity becomes increasingly central to driving business success, CISOs and their boards have more opportunities to close gaps, gain greater alignment, and better understand each other in order to drive digital resilience,” said Michael Fanning, chief information security officer at Splunk.
“For CISOs, that means understanding the business beyond their IT environments and finding new ways to convey the ROI of security initiatives to their boards. For board members, it means committing to a security-first culture and consulting the CISO as a primary stakeholder in decisions that impact enterprise risk and governance."
CISOs on the board builds strong security practices
Splunk’s research found that board members with a security background reported stronger relationships with security teams, and felt more confident about the organization’s security posture.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
They were much less likely than other board members to express concern they weren't doing enough to protect the organization.
Working relationships where a board member had a security background were particularly good when it came to setting and aligning on strategic cybersecurity goals, with CISOs on the board delivering a three-fold improvement.
Other areas to benefit included communicating progress against milestones and security goal achievements, along with budgeting adequately to meet goals.
RELATED WHITEPAPER
There were, though, differences in priorities. More than half of CISOs thought innovating with emerging technologies was a priority, compared with just a third for board members. A similar proportion of CISOs prioritized upskilling or reskilling security employees, versus only 27% for boards.
"As the role of the CISO grows more complex and critical to organizations, CISOs must be able to balance security needs with business goals, culture, and articulate the value of security investments," commented Shefali Mookencherry, chief information security and privacy officer at the University of Illinois Chicago.
"By establishing strong relationships across various departments and stakeholders, CISOs can provide guidance and leadership to propel cybersecurity and privacy programs."
CISOs face regulatory challenges
As regulatory environments have become more complex, expansive, and punitive, CISOs are having to deliver faster incident reporting, and are facing more liability.
However, only 15% of CISOs ranked compliance status as a top performance metric, a significant contrast to 45% of boards. Nearly a quarter (21%) of CISOs said they'd been pressured not to report a compliance issue, although 59% said they would become a whistleblower if their organization was ignoring compliance requirements.
Meanwhile, cyber budgets reflect inconsistent support and misalignment, with three-in-ten CISOs saying they receive the appropriate budget for cybersecurity initiatives and accomplishing their security goals, compared with four-in-ten board members who think budgets are adequate.
Other woes included concerns that they're not doing enough, with 18% revealing they were unable to support a business initiative because of budget cuts in the last 12 months. Nearly two-thirds said that lack of support led to a cyber attack.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Geekom Mini IT13 Review
Reviews It may only be a mild update for the Mini IT13, but a more potent CPU has made a good mini PC just that little bit better
By Alun Taylor
-
Why AI researchers are turning to nature for inspiration
In-depth From ant colonies to neural networks, researchers are looking to nature to build more efficient, adaptable, and resilient systems
By David Howell
-
‘We are now a full-fledged powerhouse’: Two years on from its Series B round, Hack the Box targets further growth with AI-powered cyber training programs and new market opportunities
News Hack the Box has grown significantly in the last two years, and it shows no signs of slowing down
By Ross Kelly
-
Law enforcement needs to fight fire with fire on AI threats
News UK law enforcement agencies have been urged to employ a more proactive approach to AI-related cyber crime as threats posed by the technology accelerate.
By Emma Woollacott
-
Have I Been Pwned owner Troy Hunt’s mailing list compromised in phishing attack
Troy Hunt, the security blogger behind data-breach site Have I Been Pwned, has fallen victim to a phishing attack targeting his email subscriber list.
By Jane McCallion
-
300 days under the radar: How Volt Typhoon eluded detection in the US electric grid for nearly a year
Analysis Lengthy OT lifespans give attackers time to penetrate networks underpinning critical infrastructure and plan future disruption
By Solomon Klappholz
-
Cybersecurity teams face unparalleled pressure, but they’re stepping up to the plate
News While cybersecurity teams are contending with rising workloads and chronic staffing issues, new research shows practitioners are still charging ahead and meeting targets.
By Emma Woollacott
-
There’s a new ransomware player on the scene: the ‘BlackLock’ group has become one of the most prolific operators in the cyber crime industry – and researchers warn it’s only going to get worse for potential victims
News Security experts have warned the BlackLock group could become the most active ransomware operator in 2025
By Solomon Klappholz
-
8Base ransomware members snared in global police crackdown
News Members of the prolific 8Base ransomware gang have been snared in a joint police operation.
By Emma Woollacott
-
Developers can't get a handle on application security risks
News Research by Legit Security shows a majority of organizations have high risk applications in developer environments.
By Nicole Kobie