Does your organization use vCISOs or CISOs?

vCISO30%

CISO69%

809 PARTICIPANTS
4.7k viewscircle icon2 Upvotescircle icon5 Comments
Sort by:
VP of IT in Software6 years ago

The challenge with vCISOs or what I equate to CISO-as-a-service is the lack of accountability. It is still a consultancy service by and large.

Lightbulb on3
Director Certifications in Education6 years ago

When someone is held accountable, you tend to get better results or service. The vCISO does work for some organizations based on the type of business they do.

Senior Technology & Management Consultant in Retail6 years ago

No organization can claim that Security is not important to them. But the same argument holds good for other horizontal concerns such as performance, reliability, privacy, compliance etc. So do we have a separate role for taking care of each of them? Obviously not. All horizontal concerns are the joint responsibility of everyone in the organization and hence a virtual role is mostly preferable. I have seen organizations where the CISO has a parallel ops team, engineering team and testing team. In short he/she runs a parallel organization that is not so closely connected with engineering. I don't think that is desirable.

Having said that, there are organizations where compliance, security et all constitute a full time job. In these organizations it is good to have a full time CISO who also may have other responsibilities such as compliance, regulation, privacy etc. This person may have a band of experts. But it is important that this person is also supplemented by a virtual team of engineers who are schooled in security, privacy etc. Otherwise, they tend to get more "academic" or even worse become policy cops. No one wants that!

Lightbulb on4
VP of Global IT and Cybersecurity in Manufacturing6 years ago

Depends on the business and how its setup, for most places the CISO reports directly to CEO or board members. VCISO is an outsourced security program which interacts with an internal liaison resource.

Lightbulb on1 circle icon1 Reply
no title6 years ago

Ideally, the CISO should report to the CEO, but many organizations the CISO reports to the CIO. This reporting structure is flawed, because the CIO may control the CISO's budget.

Content you might like

Too expensive compared to local workforce18%

Security measures harder to control35%

Difficult to make that person feel part of the team29%

Less likely to keep the employee hired for a long period31%

Not enough control over the employee's compensation44%

Timezone out of sync14%

Language barriers12%

We have zero interest in hiring from other countries5%

We see no concerns about hiring from other countries4%

View Results

Board12%

CEO72%

CFO7%

COO6%

Other

View Results