In the event of a security breach, is the CISO ultimately at fault regardless of the business’s risk acceptance?

1.5k viewscircle icon4 Comments
Sort by:
CEO and Co-Founder in Software4 years ago

When the VP engineer says, "I got the boss to sign off on it, so what’s your problem?" the common response among the younger generation CISOs is, "Fine, you guys deal with it." But if there is a breach, it’s the CISO that will be dragged in. They all will be fine.

1 Reply
no title4 years ago

I’ll throw some of the old guard in there too, because I've had peers in fortune 500 companies that are at least as old as I am, and who've been doing it as long as I have who tell me that it's not their problem because the business accepted it. I'm like, "You better take it as your problem because if it's manifested, you're the one responsible for keeping material harm from occurring."

Board Member, Advisor, Executive Coach in Software4 years ago

When risk manifests itself, we are still responsible for detecting and responding to it to prevent material harm or impact, regardless of the business’s acceptance of risk. We are risk managers, which means we always have to be prepared for risk potential to manifest itself and ready to minimize the damage. The damage may still be large, but at least it's contained enough that it doesn't create cataclysmic, material or significant harm. I've seen so many peers who say, “Well the business accepted the risk,” and absolve themselves of any responsibility to react to it because the business accepted it.

Lightbulb on1 circle icon1 Reply
no title4 years ago

We shouldn't be doing that. And I'm seeing a lot of that in the younger generation.

Lightbulb on2

Content you might like

Proven outcomes – Documented success stories and measurable KPIs35%

Implementation confidence – Detailed plan, risk mitigation, and resource readiness48%

Total cost – Clear TCO, price protections, and exit terms39%

Innovation & future readiness – Ability to scale, adapt, and support emerging needs13%

Vendor relationship strength – Cultural fit, governance model, and executive commitment12%

View Results

Yes73%

No26%