We have spent years telling chief information security officers (CISOs) that they need to become better aligned with the business. They need to understand strategy. They need to speak the language of the board. They need to build relationships with business leaders. They need to translate cyber risk into business risk.I increasingly believe that we are asking the CISO to solve a problem that the role was never designed to solve.Business alignment is not primarily a communication problem. It is a leadership and organizational design problem.And if we are serious about fixing it, we should stop trying to turn every CISO into a chief everything officer.The CISO has become too many thingsThe modern CISO is expected to be a technologist, strategist, risk executive, regulator-facing leader, board adviser, crisis manager, transformation executive and business partner.Sometimes all at once.This is an extraordinary range of responsibilities for one role.The problem is not that all CISOs are incapable of developing broader skills. Many have done exactly that, and the best ones have become highly credible business leaders. But many have also struggled, and many are still struggling.The problem is structural.The CISO role remains fundamentally anchored in the technology and information-security domain, while increasingly being asked to influence decisions across the entire enterprise.The organization wants the CISO to be accountable for cybersecurity but also expects the CISO to influence business decisions over which they have no direct authority.That creates an inherent tension.The CSO is a different propositionI have advocated for some time that organizations should consider a more elevated chief security officer role.Not simply as a new title for the CISO. Not as another layer of management. And certainly not as an attempt to diminish the CISO’s importance.Quite the opposite.The CSO should sit above the traditional cybersecurity construct and take responsibility for the organization’s broader protection.Cybersecurity would be a major component of that business protection portfolio, but it would sit alongside areas such as data protection, business continuity, resilience and, where appropriate, regulatory protection.The crucial distinction is that the CSO must be a business leader first.The role is about protecting the organization’s ability to operate, compete and fulfil its obligations towards shareholders, customers, employees and in the case of national critical operators, society at large.That requires a very different profile from the traditional security technologist.It requires management experience, political judgement, credibility with other executives, an understanding of how the organization operates and makes money.And, above all, the authority to bring different parts of the business together when their interests inevitably collide.That is where alignment can begin to be engineered.Give the CSO the mandate to connect the organizationConsider the typical cybersecurity problem.Security identifies a significant exposure. Technology must remediate it. Operations do not want disruption. The business wants to protect revenue. Legal is concerned about regulatory consequences. Risk wants the exposure documented. Finance wants to understand the cost.Everyone is involved.But nobody necessarily has the mandate to reconcile all these perspectives.The CISO can explain the security problem. The CIO can explain the technology implications. The business executive can explain the operational consequences.But who owns the overall protection decision?This is precisely where the CSO can add value.The CSO should have the mandate to bring those perspectives together and drive a decision that reflects the interests of the whole organization.That is fundamentally different from asking the CISO to persuade everyone to adopt the security team’s position.This is not about creating another security siloThe obvious objection is that introducing a CSO above the CISO simply creates another organizational layer, and if designed badly, it could.That is why the distinction between the two roles matters.The CSO should not become the new head of cybersecurity.The CISO should retain responsibility for the technical cybersecurity capability: Architecture, engineering, security operations, identity, vulnerability management and the other disciplines required to protect the technology estate.The CSO’s role is different.It is to provide the enterprise-level leadership required to make all those capabilities work together in the context of business priorities.In the model I have advocated previously, the CISO can report to the CSO, with an appropriate relationship to the CIO where necessary.That creates a powerful combination.The CSO provides the top-down, cross-functional influence. The CISO provides the technical depth and delivery capability.Neither role has to pretend to be the other, and together, they can create something that the current model often struggles to provide: Executive ownership of the business protection agenda combined with genuine technical expertise.The CSO should own the ‘how’ and the ‘who’For more than two decades, the cybersecurity industry has become increasingly sophisticated at explaining what organizations should do.We have frameworks, standards, controls, architectures, technologies and regulatory requirements. There is no shortage of advice about what needs to be done in terms of cyber protection.Yet organizations continue to struggle with the how and the who.Who is going to make the decision?Who owns the risk?Who has to change?Who will resolve the conflict between security and business operational priorities when they emerge?Who ensures that transformation survives the next change in business strategy?Who keeps the organization moving when resistance inevitably appears?These are leadership questions.And they are precisely the questions a properly constituted CSO role should be equipped to answer.The board has a role, tooThere is an important consequence to this model for boards.Boards should stop treating cybersecurity as an issue that can simply be delegated to a CISO hidden in the organization.The board’s responsibility is to hold the leadership team accountable for protecting the business.That means demanding clarity around roles, responsibilities and outcomes. It means asking who ultimately owns business protection. And it means ensuring that the executive structure gives that individual sufficient authority to act.The CSO should become the executive through whom the organization’s protection strategy is coordinated and executed.This could also free the CISO to succeedThere is an additional benefit which is rarely discussed.Creating a genuine CSO role could make the CISO more effective.Today, many CISOs are spending enormous amounts of time trying to operate outside their natural area of expertise.They are navigating board politics, negotiating business priorities, managing regulatory expectations, arguing over organizational ownership and trying to build executive consensus.All these activities matter, but they can come at the expense of the technical and operational discipline that cybersecurity still fundamentally requires.A CSO could absorb much of the enterprise-level responsibility while allowing the CISO to regain clarity of purpose.That does not mean returning the CISO to a narrow technical silo: It means giving the role a coherent remit.The CISO becomes accountable for making cybersecurity work.The CSO becomes accountable for ensuring that cybersecurity—and the wider protection agenda—works for the business.That is a much healthier division of responsibility.The future of cybersecurity leadership may be less about the CISOThe cybersecurity industry has become overly focused on the evolution of the CISO role.We debate reporting lines, budgets, board access, compensation, independence, technical versus strategic skills.All these debates have value, but perhaps we are asking the wrong question.Perhaps the question is not: “How do we turn the CISO into a better business executive?”Perhaps it is: “What executive structure does the business actually need to protect itself?”Again, that leads us naturally towards the CSO. You can call it Chief Trust Officer or Chief Resilience Officer if you want, but it quickly boils down to the same thing:A trusted senior executive, visibly part of the leadership team, with responsibility for bringing together cybersecurity and the other dimensions of business protection.A person with sufficient authority and personal gravitas to engage the CEO, CIO, CFO, COO, General Counsel and business-unit leaders as a peer.A person capable of translating risk into decisions, and decisions into execution.And a person who can hold the organization accountable for delivering business protection.Alignment is not a skill. It is a structureYou do not engineer cybersecurity and business alignment by asking the CISO to communicate better.You engineer it by creating the right leadership structure:You establish clear ownership.You give that ownership sufficient authority.You separate enterprise protection from technical delivery without separating the two organizationally.You make the CISO responsible for the technical execution of cybersecurity.And you give the CSO the mandate to connect that execution to the needs of the business.The objective is not to create another security hierarchy. It is to create a leadership and governance mechanism through which security becomes part of how the organization operates and makes decisions.Because ultimately, cybersecurity does not exist to protect technology. It exists to protect the business.And if we genuinely believe that, perhaps it is time for our organizational structures to reflect it.