Site navigation

Great Responsibility Does Not Come With Great Paychecks, CISOs Say

Elizabeth Greenberg

,

CISOs
“The CISO role is undergoing a seismic shift—they are no longer just security leaders but are increasingly pivotal business strategists,” noted Nick Kakolowski, senior research director at IANS.

The success of the CISO revolves around their strategic relationship with the board, research has found, as CISOs continue to expand their role.

This is based on the IANS Research and Artico research in the State of the CISO 2025 Report, which categorises executive cybersecurity leaders into three distinct segments based on their organisational influence and executive access.

While Functional CISOs, who have significant influence in the C-suite or the board but lack consistent visbility in both areas, make up half of all CISOs (50%), strategic CISOs (28%) tend to excel in influencing these arenas as they successfully align cybersecurity with broader business goals.

Tactical CISOs (22%) tend to have even less influence with the board and C-suite, and are often positioned as back-office technical practitioners.

“With CISO scope expanding and evolving, security leaders continue to be viewed as business executives rather than simply technical leaders,” said Steve Martano, IANS faculty and executive Cyber Recruiter at Artico Search.

“Effective communication with senior executives has never been more important, as alignment between business strategy and security programming is essential for long-term partnership and success.

“This report demonstrates that board engagement and C-suite access is critical in shaping the future of a security program and a CISO’s career.”

Equally, it seems just as important to gain greater job satisfaction and a higher paycheck, as Strategic CISOs earn 57% more than their functional peers, and twice as much as Tactical CISOs.

However, taking on more responsibilities does not seem to correlate to a higher salary, as only 3% of CISOs credit any salary hikes to this.

This is despite a onslaught of extra work being added onto cybersecurity leaders plates, with 1-25% of them reporting AI, change management, digital transformation, and other tasks added to their workload.


Recommended reading


It does seem that board influence may mean more than extra workloads in terms of pay and job satisfaction, though security leaders did report these extra responsibilities do correlate to at least some merit increases.

It may be difficult for CISOs to break into board influence though, as only 47% of cybersecurity leaders engage with boards on a monthly or quarterly basis, and 42% meet with their boards on an ad hoc basis, if at all.

The increasing responsibility remit of security leaders is reflected in the emergence of hybrid roles, such as dual CISO/CIO and external board seats, which are gaining traction among experienced CISOs. These positions allow security leaders to expand their influence and command a higher compensation.

“The CISO role is undergoing a seismic shift—they are no longer just security leaders but are increasingly pivotal business strategists,” noted Nick Kakolowski, senior research director at IANS.

“As their responsibilities expand into areas like business risk and IT oversight, the ability to align cybersecurity with organizational goals sets transformative leaders apart. Those who navigate these expanded responsibilities effectively are redefining the role as indispensable to business success, amplifying their influence and driving greater organizational impact.”

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data