To unearth their findings, the technological research and consulting firm drew from data which was collected from 2020 through 2023, as part of a benchmarking survey of 227 CISOs.
For instance, one major insight gleaned from the research is that 69% of the most successful CISOs dedicate time to professional development activities on a recurring basis, compared to the 36% of bottom-performing CISOs who do this.
The top performers scored in the highest one-third when respondents were measured on the key areas of CISO effectiveness, which include functional leadership, information security service delivery, enterprise responsiveness, and scaled governance. The bottom-performing CISOs were in the lowest one-third.
Speaking on how successful CISOs regularly direct time and effort to professional development, Chiara Girardi, senior principal of research at Gartner, said: “As the CISO role continues to rapidly evolve, it becomes even more critical for security and risk leaders to protect time for professional development.
“Developing new skills and knowledge as the role changes is essential to effectively serve as a strategic advisor to the business – the new CISO paradigm.”
The findings also outlined that 77% of the most successful CISOs initiate discussions within the enterprise on evolving security norms as to stay ahead of threats — this is compared to the 50% of bottom-performing CISOs who do this.
“No organisation can be fully protected against every cyber-threat,” noted Girardi. “The most effective CISOs stay apprised of existing and emerging risks so they can provide leadership with context around the most significant threats facing the business, to influence investments and risk decisions accordingly.”
According to the research and consulting firm, another key behaviour — shown in 67% of top-performers and 28% of bottom-performers — is engaging and collaborating with senior business decision-makers to define enterprise risk appetite.
Relatedly, 65% of top-performing CISOs build relationships with senior decision-makers outside of a project context.
Further, the most successful CISOs also regularly meet with three times as many non-IT stakeholders — for example, the heads of marketing, the heads of sales, and other business unit leaders — compared to IT stakeholders.
On this, Girardi said: “Non-IT functions are key partners that can take technology and cybersecurity decisions outside of IT.”
“By setting aside dedicated time to build relationships with senior business decision-makers across the enterprise, CISOs can cultivate an environment where decision makers understand and care about cybersecurity, as well as consider cybersecurity implications in their decision making.”
Lastly, Gartner’s research found that 63% of top-performing CISOs proactively engage in securing emerging technologies — the likes of which include artificial intelligence, machine learning, and blockchain — while just 38% of bottom-performing CISOs do so.
“As AI adoption proliferates, CISOs are already behind the curve in assessing its risk impact,” Girardi stipulated. “Threat actors are always one step ahead, so CISOs must be more proactive in understanding the security impact of technologies like generative AI and communicating those risks with senior business leadership.”
Recommended reading
- Report: 96% of CISOs Want Better Solutions for Cyber Resiliency
- The Cloud is Breaking ‘Traditional’ Security Approaches, Data Suggest
- Cybersecurity Improves as CISOs Report Drop in Material Incidents
While, as Gartner’s latest findings highlight, there may be certain behaviours which differentiate the performance of chief information security officers, the majority of CISOs in 2023 are facing the same, shared issues.
For instance, in the last few months alone DIGIT has reported on research which highlighted that 96% of CISOs want better technological solutions for cybersecurity resilience, 62% are concerned about being held personally liable for cyber-attacks at their company, and 51% see budget as the primary inhibitor of cyber strategy execution.
Earlier this year, Gartner also predicted that nearly half of cybersecurity leaders will change jobs by 2025, with 25% leaving for different roles entirely due to various work-related stressors.





