Although there are overlaps in the goals and responsibilities of the CIO and the CISO, there are also challenges that get in the way of a more cohesive relationship, including reporting lines, organizational structures, budgets, and risk appetites.
A panel of CIOs and CISOs identified some of the shifts that can get these two roles working better-together.
Conflict emerges when CIOs and CISOs look at the IT risks and opportunities as separate responsibilities.
This doesn't make sense to Brian Brackenborough, CISO at Channel 4, who says it is inefficient to separate the many responsibilities that CIOs and CISOs carry.
Shift #2: Overcome the tension in your reporting lines.
Consider both viewpoints of CISOs and CIOs, which is to understand the origins of tension between the roles.
Some of this friction can be attributed to reporting structures: when the CISO reports directly to the CIO there is typically less friction, but with more CISOs reporting directly to the CEO with a seat at the board room table, this dynamic changes.
Johnson Matthey's CIO, Aidan Hancock, says the CISO has always reported to him, but that reporting lines can grow and spread out.
His focus is making sure the CISO is fully on board with the rest of his IT leadership team.
Equality in reporting lines will be a dead end if CIOs and CISOs don't share responsibility for risk.
At the top of any organization, the CIO and CISO must be united and share the responsibility for leading risk.
Anuj Tewari, CISO at TMF Group, looks at collaboration between CIOs and CISOs as a key success factor.
The budget exercise was one example where Tewari said he saw CIOs and CISOs work hand in hand.
He gave the example of the traditional CIO and CISO conferences.
An information security conference is full of CISOs and information security professionals.
This way, technology leaders will know what's happening in each other's camps and help the CISO and CIO overcome the feeling that they're talking different languages.
Understanding the overlap in the roles and becoming intentional about reporting lines while aligning on risk and purpose can bring IT organizations closer together.
Modern tools break down the silos between the CISO and CIO so that convergence can take place.
CIOs and CISOs get a holistic view of what is going on in the organization they're leading.
CIOs and CISOs must clarify roles, responsibilities, and reporting structures.
This Cyber News was published on feedpress.me. Publication date: Wed, 20 Dec 2023 16:43:05 +0000