That creates a powerful combination.
The CSO provides the top-down, cross-functional influence. The CISO provides the technical depth and delivery capability.
Neither role has to pretend to be the other, and together, they can create something that the current model often struggles to provide: Executive ownership of the business protection agenda combined with genuine technical expertise.
The CSO should own the ‘how’ and the ‘who’
For more than two decades, the cybersecurity industry has become increasingly sophisticated at explaining what organizations should do.
We have frameworks, standards, controls, architectures, technologies and regulatory requirements. There is no shortage of advice about what needs to be done in terms of cyber protection.
Yet organizations continue to struggle with the how and the who.
- Who is going to make the decision?
- Who owns the risk?
- Who has to change?
- Who will resolve the conflict between security and business operational priorities when they emerge?
- Who ensures that transformation survives the next change in business strategy?
- Who keeps the organization moving when resistance inevitably appears?
These are leadership questions.
And they are precisely the questions a properly constituted CSO role should be equipped to answer.
The board has a role, too
There is an important consequence to this model for boards.
Boards should stop treating cybersecurity as an issue that can simply be delegated to a CISO hidden in the organization.
The board’s responsibility is to hold the leadership team accountable for protecting the business.
That means demanding clarity around roles, responsibilities and outcomes. It means asking who ultimately owns business protection. And it means ensuring that the executive structure gives that individual sufficient authority to act.
The CSO should become the executive through whom the organization’s protection strategy is coordinated and executed.
This could also free the CISO to succeed
There is an additional benefit which is rarely discussed.
Creating a genuine CSO role could make the CISO more effective.
Today, many CISOs are spending enormous amounts of time trying to operate outside their natural area of expertise.
They are navigating board politics, negotiating business priorities, managing regulatory expectations, arguing over organizational ownership and trying to build executive consensus.
All these activities matter, but they can come at the expense of the technical and operational discipline that cybersecurity still fundamentally requires.
A CSO could absorb much of the enterprise-level responsibility while allowing the CISO to regain clarity of purpose.
That does not mean returning the CISO to a narrow technical silo: It means giving the role a coherent remit.
The CISO becomes accountable for making cybersecurity work.
The CSO becomes accountable for ensuring that cybersecurity—and the wider protection agenda—works for the business.
That is a much healthier division of responsibility.
The future of cybersecurity leadership may be less about the CISO
The cybersecurity industry has become overly focused on the evolution of the CISO role.
We debate reporting lines, budgets, board access, compensation, independence, technical versus strategic skills.
All these debates have value, but perhaps we are asking the wrong question.
Perhaps the question is not: “How do we turn the CISO into a better business executive?”
Perhaps it is: “What executive structure does the business actually need to protect itself?”
Again, that leads us naturally towards the CSO. You can call it Chief Trust Officer or Chief Resilience Officer if you want, but it quickly boils down to the same thing:
A trusted senior executive, visibly part of the leadership team, with responsibility for bringing together cybersecurity and the other dimensions of business protection.
A person with sufficient authority and personal gravitas to engage the CEO, CIO, CFO, COO, General Counsel and business-unit leaders as a peer.
A person capable of translating risk into decisions, and decisions into execution.
And a person who can hold the organization accountable for delivering business protection.
Alignment is not a skill. It is a structure
You do not engineer cybersecurity and business alignment by asking the CISO to communicate better.
You engineer it by creating the right leadership structure:
- You establish clear ownership.
- You give that ownership sufficient authority.
- You separate enterprise protection from technical delivery without separating the two organizationally.
- You make the CISO responsible for the technical execution of cybersecurity.
- And you give the CSO the mandate to connect that execution to the needs of the business.
The objective is not to create another security hierarchy. It is to create a leadership and governance mechanism through which security becomes part of how the organization operates and makes decisions.
Because ultimately, cybersecurity does not exist to protect technology. It exists to protect the business.
And if we genuinely believe that, perhaps it is time for our organizational structures to reflect it.


