Your CEO has just recommended hiring a Chief Information Security Officer. The salary package is significant, the job description runs to three pages, and the CFO is nervous about headcount. Someone at the table asks: do we actually need one? Nobody has a clear answer. That is a governance problem before it is a hiring problem.
Does this apply to you?
ASX-listed: Continuous disclosure obligations and investor expectations make the question of who owns cyber risk reporting a live board issue, not a management-level detail. [1]
APRA-regulated: Prudential requirements on information security governance mean the board needs clear accountability for cyber risk. [2] Whether that sits with a CISO or another executive, the board must be able to demonstrate it.
NFP / SME: A full-time CISO is probably not the right answer, but the underlying question, who is accountable to the board for cyber risk, still needs an answer.
The question behind the question
When a board debates whether to hire a CISO, it is really debating something more fundamental: does the board currently receive accurate, independent cyber risk information, and does someone credible own the accountability for managing it? The CISO question is the surface. The governance question is what sits underneath.
A CISO is a senior executive, typically reporting to the CEO or CIO, whose job is to own the organisation's information security strategy, manage cyber risk, and give the board a clear line of sight into the threat environment. In a well-structured organisation, the CISO provides the board with a direct, expert voice on cyber risk that is not filtered through an IT department primarily motivated to protect its own operational decisions.
The board does not hire the CISO in most organisations. Management does. But the board absolutely has a role in deciding whether the structure management is proposing actually serves the board's oversight function, and whether the reporting line gives directors what they need to exercise their duty of care under the Corporations Act. [3]
What a CISO does and does not solve
Hiring a CISO solves the accountability problem. It puts a named, qualified individual in front of the board who owns cyber risk and can answer for it. That matters. Boards that receive cyber reporting from a rotating cast of IT managers, external consultants, and occasionally the CIO get inconsistent information and have no single point of accountability. A CISO fixes that.
What a CISO does not solve is the board's own cyber literacy. If the board cannot ask good questions, a CISO will fill the silence with reassuring technical language and the meeting will move on. The appointment is only useful if the board is capable of engaging with what the CISO brings to the table. The AICD, as the professional body for Australian directors, is direct on this point: cyber risk is a board-level responsibility, and directors are expected to engage with it actively, not delegate it entirely to management. [4]
A CISO also does not automatically improve cyber security outcomes. Organisations with a CISO still get breached. What the role does is ensure there is a professional accountable for minimising the likelihood and impact of a breach, and for keeping the board informed. That is a governance improvement, not a security guarantee.
The reporting line matters more than the title
Where the CISO sits in the organisation tells the board a great deal about how seriously management takes cyber risk. A CISO who reports to the CIO sits inside the technology function. That creates a structural tension: the CIO is accountable for building and running systems, and the CISO is accountable for questioning whether those systems are secure. Put one inside the other and the questioning function is subordinated to the operational function.
A CISO who reports directly to the CEO, with a dotted line to the board or its audit and risk committee, has genuine independence. That structure allows the CISO to escalate concerns without those concerns being edited by a line manager who has competing priorities. The board should ask management to explain the proposed reporting line and push back if the answer does not give the CISO real independence.
The board should also ask how the CISO will interact with the board directly. Regular reporting to the audit and risk committee, at minimum, is the standard the board should set. If management proposes that the CISO reports through the CIO and the board only hears cyber risk updates as a subset of a broader technology update, that is not a CISO structure that improves board-level governance.
When the answer is not a full-time CISO
Smaller organisations, NFPs, and businesses at an earlier stage of maturity will sometimes look at the CISO question and conclude that a full-time executive is not proportionate. That is a legitimate conclusion. It is not, however, a conclusion that removes the underlying governance obligation.
If the board decides a full-time CISO is not appropriate, it still needs to answer the same questions: who is accountable for cyber risk, how does that accountability reach the board, and is the person in that role qualified to own it? A virtual CISO arrangement, a fractional appointment, or a well-structured remit sitting with a qualified executive can all work. What does not work is leaving the question unanswered and assuming IT has it covered.
The ACS, as the professional body for Australian technology and cyber practitioners, provides frameworks for assessing what level of security leadership is appropriate for an organisation's size and risk profile. The board does not need to conduct that assessment itself, but it should ask management to demonstrate that someone has.
What the board should actually do
Governance red flags
- The board receives cyber risk updates only as a sub-item inside a broader IT or operations report, with no named executive owning the content.
- Management's recommendation to hire a CISO does not include a proposed reporting line or a description of how the role will interact with the board directly.
- No director can name who is currently accountable for the organisation's cyber risk, or explain how that accountability is structured.
- The board has approved a CISO appointment but has not set expectations for how often the CISO will report to the audit and risk committee, or on what matters.
- The organisation has concluded it does not need a CISO but has no documented alternative arrangement for cyber risk accountability at the executive level.
Questions to ask management
- Who is currently accountable for cyber risk in this organisation, and how does that accountability reach the board?
- If you are recommending a CISO, what is the proposed reporting line, and how does that structure give the CISO genuine independence from the functions they are expected to scrutinise?
- How often will the CISO report directly to the board or the audit and risk committee, and what will be covered in that reporting?
- If a full-time CISO is not proposed, what alternative arrangement provides the same level of accountable, qualified cyber risk leadership?
- What is the process for the CISO to escalate a significant cyber risk concern directly to the board, outside the normal reporting cycle?
The CISO debate is the right debate for a board to have. But the goal is not to hire a title. The goal is to ensure that someone qualified owns cyber risk, that their accountability is clear, and that the board receives direct, honest reporting from that person without it being filtered or softened on the way up. Get those three things right and the governance improves. Get the title without the structure and nothing changes except the salary cost.
Suitable for board minutes or a risk register entry
Frequently Asked Questions
Is the board legally required to appoint a CISO?
No legislation mandates the appointment of a CISO by title. What the law does require, through the duty of care and diligence under the Corporations Act, is that directors take cyber risk seriously and exercise active oversight of it. [5] A CISO is one way to structure that oversight. It is not the only way, but the board must have an answer for how cyber risk accountability is structured if the question is ever asked by a regulator or in litigation.
Should the CISO present directly to the board, or is reporting through management acceptable?
The CISO should have direct access to the board, at minimum through the audit and risk committee, without that access being conditional on management approval. Reporting that is filtered through the CIO or CEO before it reaches the board reduces the independence of the function and limits the board's ability to receive an unvarnished view of cyber risk. Direct reporting does not mean bypassing management on every matter, but the channel to the board must exist and must be used regularly.
What if we are too small to justify a full-time CISO?
Size is a legitimate factor in the decision. It is not a reason to leave cyber risk accountability unassigned. Smaller organisations can use fractional CISO arrangements, virtual CISO services, or a clearly defined executive remit, provided the person in that role has genuine cyber security expertise and a clear line of accountability to the board. The board should document whatever arrangement it settles on and review it as the organisation grows or its threat environment changes.
How does the board assess whether a CISO candidate is actually qualified?
The board does not need to conduct the technical assessment itself, but it should satisfy itself that management has used a credible process. That includes checking for recognised professional credentials, asking about the candidate's experience managing incidents and board-level reporting, and speaking with the shortlisted candidate directly before the appointment is finalised. A CISO who cannot explain cyber risk clearly to a non-technical director is not the right candidate, regardless of their technical qualifications.
If this resonates, I would welcome a conversation about the Cyber Governance Deep Review, or get in touch directly.
