Site navigation

New CISO Report Highlights Increasing Influence and Deepening Pockets

Thom Carter

,

CISO report
A new report detailing the trends, challenges, and successes of today’s chief information security officers (CISOs) discovered that around half of CISOs are now directly reporting to their CEOs, and nearly all expect their cybersecurity budgets to increase in the next year.

To uncover the findings, Splunk, a U.S.-based software company, conducted both qualitative and quantitative research on around 350 CISOs and other executive security leaders. The experts were located internationally, working in locations across North America, Western Europe, and the Asia-Pacific region.

While, overall, 47% of CISOs are now reporting to their CEOs, Western Europe appears to be leading this trend, with 54% doing so. In comparison, 48% of CISOs based in the Asia-Pacific region report directly to their CEOs, as do 41% of those in North America. The report points to existing and incoming European legislation that places liability on CEOs for their business’ security as the reason for Western Europe’s higher percentage here.

Despite the variation, the number of CISOs reporting to CEOs can indicate a closer relationship with the C-suite and their respective governing boards, and therefore reflect the CISO’s growing influence. Speaking on this, Splunk’s CEO, Jason Lee, said: “The C-Suite and board of directors are increasingly relying on CISOs for guidance across a sophisticated threat landscape and changing market conditions.”

“These relationships provide CISOs the opportunity to become champions who strengthen an organization’s security culture and lead teams to become more cross-collaborative and resilient. By communicating key security metrics, CISOs can also guide boards on adopting emerging technologies, such as generative AI, to help improve cyber defense management and prepare for the future.”

The report also underscored that 93% of respondent CISOs believe that their cybersecurity budgets will increase either significantly or somewhat over the next year, despite 83% seeing cuts in other parts of their organisation. This could be in relation to the fact that 88% of CISOs said their governing board or body is making a concerted effort to educate themselves on cybersecurity.


Recommended reading


The research’s findings of increasing CISO influence in addition to expanding cybersecurity budgets comes at a necessary time: 90% of respondents said their organisation had experienced at least one disruptive cyber-attack within the last year, and 70% believe generative AI will provide further ammunition for adversaries.

In response to the potential threat of weaponised generative AI, 35% of respondents noted that they’re already experimenting with it for cyber-defence, including malware analysis, workflow automation, and risk scoring. Further, 61% said they’ll likely use it in the next 12 months.

“We are trying to stay ahead of generative AI,” said one CISO working for a government organisation. “We know it is a technology that is being used. Instead of blocking the technology, we are trying to put as many guardrails around it as possible.”

Thom Carter

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data