Should the CISO role be split in two?

Wait 5 sec.

In its roughly 30-year history, the CISO role has been reshaped by waves of new technology and rising cyber threats.In many organizations, CISOs now own risk reporting, information risk management, threat monitoring, cyber risk accountability and governance, and security strategy.And as AI and digital dependence grow, the CISO’s remit is growing beyond security controls. The latest IANS State of the CISO report finds CISOs carrying increasing executive authority to shape strategy at the organizational level.Now more than ever the CISO role is being rewritten — but can one title manage the growing list of technical with executive responsibilities?Has the CISO outgrown its technical roots?Former CISO Todd Fitzgerald, who now runs professional leadership programs and writes about the profession, says the CISO role has passed through successive phases, from technical oversight through compliance, GRC, cloud, and privacy to today’s focus on business resilience.“Increasingly, it’s been about putting a business leadership lens around the job of the CISO,” Fitzgerald says.Today’s CISO is a strategic role with a remit to reduce risk and contribute to what the business needs. “That’s not the technical person. That’s how a lot of CSOs grew up, but that’s not really what the job is,” he notes.Many companies, Fitzgerald says, are catching up with the CISO’s true remit. “I don’t feel like this is a new transformation,” he tells CSO.But according to IANS, two-thirds of CISOs still report into IT — a sign that many organizations haven’t assigned the role strategic business importance. “I think we’ve done a poor job of articulating what the CISO role really is,” says Fitzgerald, who reasons that many CISOs fall back on technical abilities because trying to change organizational processes is difficult.“They’re not addressing where the real risk may be, or they’re not doing the hard part of getting together with their business units and their stakeholders and understanding their security needs,” he says.The result can be a mismatch between how the CISO is perceived and the role they want to play. Fitzgerald says CISOs can find themselves complaining about budgets or not being listened to.CISOs may come into the room as “the techy security person” but want to be seen as something else.Splunk’s 2026 CISO Report found that 79% of CISOs say their remit has become significantly more complex, with responsibilities now spanning data privacy, regulatory compliance, and third-party cyber risk — and 96% are also now responsible for AI governance and risk management.Tim Brown, general partner and CISO in residence at Team 8, agrees the CISO needs to operate as a business leader to represent cyber risk to the organization.“They absolutely still need to manage the operational side and have appropriate people to be part of that, no question, but [organizations] need a measure of the real risk and the coverage in place,” Brown says.Without stoking fear, the CISO’s primary task is to lead the cyber risk conversations, but that doesn’t mean relying on lists of vulnerabilities, patches, and dashboard metrics. “Nobody has unlimited budget so you’ve got to build the skills necessary to be able to communicate to appropriately spend money to get things done,” Brown says.The case for redesigning the CISO roleThe problem many CISOs face is that the role has become that of a business leader who must retain every previous responsibility. As a result, many CISOs report that the expanding scope of the role is outpacing resources.The IANS 2026 State of the CISO Report found that 52% of CISOs believe their scope is no longer fully manageable, particularly in smaller organizations and industries with leaner security teams.Several years ago, discussions focused on whether the CISO role should be split between a business CISO and a technical CISO as a way of managing the growing set of responsibilities. It recognized that strategic risk management had become a business imperative.More recently, there have been suggestions that two separate types of security leaders will emerge — one focused on defenses and the other focused on risk and resilience. Fitzgerald is not in favor of splitting security off into IT.“I don’t know that I would have two CISOs. I still think one CISO who’s driving the strategy and is still responsible for that function” is the right way to approach the role, he says.Some larger enterprises opt to have a deputy CISO as a way to manage the workload. In this case, the CISO is responsible for strategic direction, engaging with the board and other executives, and risk management, while the deputy role handles more of the operations.Brown says a deputy is important for succession planning and continuity of day-to-day operations, while also providing a way to develop people who can eventually become CISOs. “It’s important to have that depth in the organization,” he says.Both Brown and Fitzgerald say the answer isn’t to create two CISOs. It’s one CISO with clearly defined technical, governance, and operational responsibilities.For Brown, the CISO’s primary function is to own the business risk associated with cyber, with governance and security operations supporting the role.“That doesn’t mean they own the remediation/resolution of the risk, but they should be the one thinking about it 100% of the time, communicating it, and helping to develop appropriate remediations,” he says.Security operations and defenses, the primary role of the past, are the second element and governance is the third function, but they may not all be managed personally by the CISO.“Organizations will have different reporting structures — often we see the CISO having different distinct functions underneath them,” Brown says. “Just like accounting, where there’s a CFO responsible for finance for the organization, the CISO needs to be responsible for cyber risk for the business.”Industry reports suggest that shift is under way, with executive-level CISO titles (either VP- or director-level) now dominating across company sizes, and they’re significantly more likely to report outside of IT, according to the IANS State of the CISO report.But the executive title brings added responsibilities — and risks.Executive-level CISOs need to ask whether they are covered by directors and officers (D&O) insurance, Brown says. “They need to have conversations with executive teams and boards around liability and if they’re really an officer are they covered under the directors and officers insurance?”Brown’s charges following the SolarWinds breach focused more CISOs’ attention on their personal liability and what protections were in place — or not. “The trigger point in many ways was me being charged by the SEC and it meant a lot of CISOs having that conversation,” he says.As the role matures, Fitzgerald says, CISOs that are still largely technical will need to look to training and experience to operate as business leaders. “It’s important that we’re able to have these conversations and that we’re seen as a true partner with other executives as opposed to just a technical partner,” he tells CSO.In the early days, only large enterprises were thought to need a CISO. That’s given way as more organizations have adopted a security function, even as the role has grown and changed.Fitzgerald plots the CISO role on a similar maturity trajectory to the CIO — becoming a true executive.“It’s a younger role — 31 years since the first CISO — but if we look back at where the CIO role was at this point, we’ll see a different flavor of CISO in 10 to 15 years,” he says.