What’s the ideal reporting line to maximize a CISOs impact?
Chief Risk Officer11%
Chief Operating Officer39%
Chief Information Officer37%
Chief Executive Officer12%
372 PARTICIPANTS
Chief Risk Officer11%
Chief Operating Officer39%
Chief Information Officer37%
Chief Executive Officer12%
Completely confident21%
Mostly confident71%
Not quite confident6%
Not at all confident1%
Yes68%
No31%
No selling.
No recruiting.
No self promotion.
Rules of EngagementFAQsPrivacy
© 2025 Gartner, Inc. and/or its affiliates. All rights reserved.
I'm surprised by how low the CEO is. To maximise a CISOs impact they need to have a seat at the top table.
If they report through another role, such as the CIO, then their needs are in direct competition with all the other needs of that department, before they can be prioritized against the needs of the rest of the business.