shield_person Andrew Roberts Advisory

Briefing No. 029

Does the board need to hire a CISO?

·9 min read·1,758 words

Your CEO has just recommended hiring a Chief Information Security Officer. The salary package is significant, the job description runs to three pages, and the CFO is nervous about headcount. Someone at the table asks: do we actually need one? Nobody has a clear answer. That is a governance problem before it is a hiring problem.

Does this apply to you?

ASX-listed: Continuous disclosure obligations and investor expectations make the question of who owns cyber risk reporting a live board issue, not a management-level detail. [1]

APRA-regulated: Prudential requirements on information security governance mean the board needs clear accountability for cyber risk. [2] Whether that sits with a CISO or another executive, the board must be able to demonstrate it.

NFP / SME: A full-time CISO is probably not the right answer, but the underlying question, who is accountable to the board for cyber risk, still needs an answer.

The question behind the question

When a board debates whether to hire a CISO, it is really debating something more fundamental: does the board currently receive accurate, independent cyber risk information, and does someone credible own the accountability for managing it? The CISO question is the surface. The governance question is what sits underneath.

A CISO is a senior executive, typically reporting to the CEO or CIO, whose job is to own the organisation's information security strategy, manage cyber risk, and give the board a clear line of sight into the threat environment. In a well-structured organisation, the CISO provides the board with a direct, expert voice on cyber risk that is not filtered through an IT department primarily motivated to protect its own operational decisions.

The board does not hire the CISO in most organisations. Management does. But the board absolutely has a role in deciding whether the structure management is proposing actually serves the board's oversight function, and whether the reporting line gives directors what they need to exercise their duty of care under the Corporations Act. [3]

What a CISO does and does not solve

Hiring a CISO solves the accountability problem. It puts a named, qualified individual in front of the board who owns cyber risk and can answer for it. That matters. Boards that receive cyber reporting from a rotating cast of IT managers, external consultants, and occasionally the CIO get inconsistent information and have no single point of accountability. A CISO fixes that.

What a CISO does not solve is the board's own cyber literacy. If the board cannot ask good questions, a CISO will fill the silence with reassuring technical language and the meeting will move on. The appointment is only useful if the board is capable of engaging with what the CISO brings to the table. The AICD, as the professional body for Australian directors, is direct on this point: cyber risk is a board-level responsibility, and directors are expected to engage with it actively, not delegate it entirely to management. [4]

A CISO also does not automatically improve cyber security outcomes. Organisations with a CISO still get breached. What the role does is ensure there is a professional accountable for minimising the likelihood and impact of a breach, and for keeping the board informed. That is a governance improvement, not a security guarantee.

The reporting line matters more than the title

Where the CISO sits in the organisation tells the board a great deal about how seriously management takes cyber risk. A CISO who reports to the CIO sits inside the technology function. That creates a structural tension: the CIO is accountable for building and running systems, and the CISO is accountable for questioning whether those systems are secure. Put one inside the other and the questioning function is subordinated to the operational function.

A CISO who reports directly to the CEO, with a dotted line to the board or its audit and risk committee, has genuine independence. That structure allows the CISO to escalate concerns without those concerns being edited by a line manager who has competing priorities. The board should ask management to explain the proposed reporting line and push back if the answer does not give the CISO real independence.

The board should also ask how the CISO will interact with the board directly. Regular reporting to the audit and risk committee, at minimum, is the standard the board should set. If management proposes that the CISO reports through the CIO and the board only hears cyber risk updates as a subset of a broader technology update, that is not a CISO structure that improves board-level governance.

When the answer is not a full-time CISO

Smaller organisations, NFPs, and businesses at an earlier stage of maturity will sometimes look at the CISO question and conclude that a full-time executive is not proportionate. That is a legitimate conclusion. It is not, however, a conclusion that removes the underlying governance obligation.

If the board decides a full-time CISO is not appropriate, it still needs to answer the same questions: who is accountable for cyber risk, how does that accountability reach the board, and is the person in that role qualified to own it? A virtual CISO arrangement, a fractional appointment, or a well-structured remit sitting with a qualified executive can all work. What does not work is leaving the question unanswered and assuming IT has it covered.

The ACS, as the professional body for Australian technology and cyber practitioners, provides frameworks for assessing what level of security leadership is appropriate for an organisation's size and risk profile. The board does not need to conduct that assessment itself, but it should ask management to demonstrate that someone has.

What the board should actually do

Governance red flags

  • The board receives cyber risk updates only as a sub-item inside a broader IT or operations report, with no named executive owning the content.
  • Management's recommendation to hire a CISO does not include a proposed reporting line or a description of how the role will interact with the board directly.
  • No director can name who is currently accountable for the organisation's cyber risk, or explain how that accountability is structured.
  • The board has approved a CISO appointment but has not set expectations for how often the CISO will report to the audit and risk committee, or on what matters.
  • The organisation has concluded it does not need a CISO but has no documented alternative arrangement for cyber risk accountability at the executive level.

Questions to ask management

  1. Who is currently accountable for cyber risk in this organisation, and how does that accountability reach the board?
  2. If you are recommending a CISO, what is the proposed reporting line, and how does that structure give the CISO genuine independence from the functions they are expected to scrutinise?
  3. How often will the CISO report directly to the board or the audit and risk committee, and what will be covered in that reporting?
  4. If a full-time CISO is not proposed, what alternative arrangement provides the same level of accountable, qualified cyber risk leadership?
  5. What is the process for the CISO to escalate a significant cyber risk concern directly to the board, outside the normal reporting cycle?

The CISO debate is the right debate for a board to have. But the goal is not to hire a title. The goal is to ensure that someone qualified owns cyber risk, that their accountability is clear, and that the board receives direct, honest reporting from that person without it being filtered or softened on the way up. Get those three things right and the governance improves. Get the title without the structure and nothing changes except the salary cost.

"The board reviewed the organisation's current cyber risk accountability structure, considered the proposed CISO appointment and reporting line, and resolved that management provide a formal proposal specifying the CISO reporting relationship to the board, the cadence of direct board reporting, and the escalation pathway for material cyber risk concerns outside the normal reporting cycle."

Suitable for board minutes or a risk register entry

Frequently Asked Questions

Is the board legally required to appoint a CISO?

No legislation mandates the appointment of a CISO by title. What the law does require, through the duty of care and diligence under the Corporations Act, is that directors take cyber risk seriously and exercise active oversight of it. [5] A CISO is one way to structure that oversight. It is not the only way, but the board must have an answer for how cyber risk accountability is structured if the question is ever asked by a regulator or in litigation.

Should the CISO present directly to the board, or is reporting through management acceptable?

The CISO should have direct access to the board, at minimum through the audit and risk committee, without that access being conditional on management approval. Reporting that is filtered through the CIO or CEO before it reaches the board reduces the independence of the function and limits the board's ability to receive an unvarnished view of cyber risk. Direct reporting does not mean bypassing management on every matter, but the channel to the board must exist and must be used regularly.

What if we are too small to justify a full-time CISO?

Size is a legitimate factor in the decision. It is not a reason to leave cyber risk accountability unassigned. Smaller organisations can use fractional CISO arrangements, virtual CISO services, or a clearly defined executive remit, provided the person in that role has genuine cyber security expertise and a clear line of accountability to the board. The board should document whatever arrangement it settles on and review it as the organisation grows or its threat environment changes.

How does the board assess whether a CISO candidate is actually qualified?

The board does not need to conduct the technical assessment itself, but it should satisfy itself that management has used a credible process. That includes checking for recognised professional credentials, asking about the candidate's experience managing incidents and board-level reporting, and speaking with the shortlisted candidate directly before the appointment is finalised. A CISO who cannot explain cyber risk clearly to a non-technical director is not the right candidate, regardless of their technical qualifications.

If this resonates, I would welcome a conversation about the Cyber Governance Deep Review, or get in touch directly.

Andrew Roberts

Briefing by

Andrew Roberts

Founder and Principal Advisor at Andrew Roberts Advisory. I help Australian boards translate cyber and AI governance obligations into clear, defensible oversight. Former ASX-listed Group CEO, AICD and ACS member, ACS MACS (Snr) CP (Cyber).

Sources

Related briefings

More Briefings

Cyber Governance & Oversight

Cyber Governance for Boards Australia: Moving Beyond Technical Metrics to Defensible Oversight

Apr 29, 2026
Cyber Governance & Oversight

What is a Technology Consultant? A Director’s Guide to Strategic Advisory in 2026

Apr 30, 2026
Governance Strategy & Advisory

Digital Strategy Consulting: A Board-Level Governance Template for 2026

May 01, 2026
Cyber Governance & Oversight

Defensible Oversight: A Cyber Security Audit Checklist for Australian Boards

May 04, 2026
Governance Strategy & Advisory

Tech Consulting for Australian Boards: Bridging the Governance Gap in 2026

May 06, 2026
AI Governance

AI Ethics Governance for Australian Boards: A Director's Framework

May 08, 2026
Board Reporting & Disclosure

Cyber Risk Reporting to the Board Australia: Establishing Defensible Oversight in 2026

May 11, 2026
AI Governance

AI Risk Management Framework for Directors: A Defensible 2026 Guide for Australian Boards

May 13, 2026
Regulation & Compliance

Regulatory Settlement Agreements: A Director’s Guide to Defensible Governance

May 15, 2026
Cyber Governance & Oversight

Cyber Security for Australian Boards: Moving from Technical Metrics to Defensible Oversight

May 18, 2026
Regulation & Compliance

Privacy Act Obligations and the Crimes Act: A Director’s Guide to Defensible Oversight

May 20, 2026
Third-Party & Supply Chain Risk

Third Party Cyber Risk Governance Australia: A Director’s Guide to Defensible Oversight

May 22, 2026
Cyber Governance & Oversight

Board Cyber Governance Strategy Australia: A 2026 Reference for Directors

May 25, 2026
Cyber Governance & Oversight

How to Challenge a CISO Report: A Director’s Guide to Defensible Oversight

May 27, 2026
AI Governance

Board Oversight of Generative AI Risks: A Defensible Governance Framework for 2026

May 29, 2026
AI Governance

AI Governance Reporting for Boards: A Guide to Defensible Oversight

Jun 01, 2026
AI Governance

Questions for Boards to Ask About Corporate AI Strategy: A 2026 Director’s Checklist

Jun 05, 2026
AI Governance

Director's Guide to Artificial Intelligence Risks: Defensible Oversight in 2026

Jun 08, 2026
Board Reporting & Disclosure

Linking Cyber Risk to Financial Impact: A Director’s Guide to Defensible Board Reporting

Jun 10, 2026
Regulation & Compliance

APRA CPS 234: Board Obligations Checklist for Directors

Jun 03, 2026
Board Reporting & Disclosure

Investor Expectations for Board Cyber Oversight in 2026

Jun 10, 2026
Cyber Governance & Oversight

Essential Eight Board Oversight for Australian Directors

Jun 12, 2026
Regulation & Compliance

Cyber Security Act 2024: Australian Director Obligations

Jun 05, 2026
Cyber Governance & Oversight

Board Cybersecurity Duties: A Director's Guide to Defensible Oversight in Australia

Jun 15, 2026
Cyber Governance & Oversight

AICD Cyber Security Governance Principles Version 2: What Australian Directors Need to Know

Jun 16, 2026
Third-Party & Supply Chain Risk

Third-Party Cyber Risk: A Director's Guide to Defensible Board Oversight in Australia

Jun 17, 2026
AI Governance

What an Independent AI Governance Review Actually Involves for Australian Boards

Aug 02, 2026
Cyber Governance & Oversight

The Origin Hack: What Directors Need to Do NowNew

Aug 09, 2026