Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Indonesia integrates Indigenous data in bid to put customary lands on map

    August 25, 2026

    Let’s focus on what people with special needs can do, rather than what they can’t | Young people

    August 25, 2026

    Australia news live: PM dubbed ‘WA’s daddy’ over Blue Poles and GST promises; RBA poised to lift interest rates again if needed | Australia news

    August 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Indonesia integrates Indigenous data in bid to put customary lands on map
    • Let’s focus on what people with special needs can do, rather than what they can’t | Young people
    • Australia news live: PM dubbed ‘WA’s daddy’ over Blue Poles and GST promises; RBA poised to lift interest rates again if needed | Australia news
    • Kabinettsklausur: Altes Ritual, neue Probleme – POLITICO
    • Jeffries Defends Kushner Meeting, Vowing Tough Oversight of Trump
    • I tried Meta’s new free vibe coding app to make my own games, and it was surprisingly fun
    • Hired for One Job, Judged on Another: The CISO’s Real Problem
    • Korean Bank Taps Ripple For Payments, Pakistan Opens Crypto Licensing: Asia Express
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hired for One Job, Judged on Another: The CISO’s Real Problem

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 25, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Industry surveys have long put CISO tenure below that of other C-suite roles, and part of the reason is a double standard. During recruitment, the focus is technical depth, security experience, and leadership. But when budget season arrives and the board weighs a leader’s performance, the lens is cost, growth, customer trust, and brand protection.

    Many CISOs feel this acutely. They came up through security, or through risk and compliance, and that is where they are fluent. Their board is not. It wakes up thinking about cost, growth, and customer commitments, and a security leader who cannot connect their work to that language will be seen as important, but rarely as strategic.

    Some of this comes down to how the job has been defined. For a long time, a CISO’s success has been measured by proving a negative, by showing that nothing went wrong. That is an impossible assignment, and it frames the entire function as insurance rather than a business driver.

    The business is not wrong to expect this

    Security plays a significant role in buying decisions. In McKinsey’s early-2026 survey of more than 3,000 enterprise technology buyers, data privacy and compliance ranked as the single most important customer concern, named by over half of respondents, and providers that fall short on security and compliance were increasingly excluded from consideration regardless of price or features. The same survey found that among buyers who switched providers in the past year, cybersecurity was the number one reason they left, ahead of price, coverage, and reliability. Trust makes or breaks the deal. And yet at most companies security is still treated as the team that slows things down, buried in a review that starts only after everyone else has agreed to move forward.

    I see the same thing from the CEO seat, as a buyer and as a boss. When I talk with my own CISO, I do not ask how many alerts his team closed. I ask three things. How are you making us stronger? How are you helping us grow? And how will we recover if something goes wrong? Every CISO I know can talk about strength and recovery. Far fewer can concretely show how they enable business growth by proving trust to close deals.

    Advertisement. Scroll to continue reading.

    Why the gap is so hard to close

    So why does the daily reality still feel like overhead? Because the work underneath has not changed. Compliance keeps getting heavier. In PwC’s 2025 global compliance survey, 72% of executives said the rising complexity of compliance over the past three years had hurt their company’s profitability. Every new framework and every longer questionnaire piles on effort without obvious payoff, so teams do the only thing the calendar allows. They collect evidence once a year, answer the same questions in slightly different formats for every buyer, and move on.

    This is where being secure on paper becomes a real problem. A passed audit or a clean dashboard tells you a control worked on the day someone checked it, and nothing about the rest of the year. So when a customer’s security team asks whether that control is working right now, most vendors can only say they think so. That hesitation is where the deal stalls while everyone waits for confirmation, and it can repeat across the pipeline. Buyers are not asking these questions to be difficult, either. They ask because they have watched one weak vendor turn into their own breach.

    This is not about effort. These teams work hard. The problem is the design: a program built to survive an annual audit will always read as overhead, no matter how well it runs.

    What strategic security actually looks like

    Strategic security leaders are already positioning themselves this way. Speaking on Virtru’s Hash It Out podcast, Dave Brown (CISO of Andesite and author of “The Lean CISO”) described running security as something that should move deals rather than gate them. He sits in on sales calls. He keeps what he calls “speed dial” access to the CRO. He built an evidence library that turns security reviews that once took weeks into same-day answers. He even tells the story of a prospect whose CEO would not sign until he had spoken with the security leader directly. One conversation later, the contract was signed on the call.

    Any CISO can translate that into concrete commitments. Say the board wants 50 percent growth next year. A security leader contributing to that goal might sign up for three specific things: earn the compliance certifications the company needs to sell into Europe within four months, turn customer security questionnaires around in a day instead of twelve, and be ready to meet new contractual security terms fast enough that they never hold up a negotiation. Written that way, each one reads like a growth commitment a CFO can track alongside the sales forecast. And none of it took a bigger security budget. It took pointing the same program at the outcomes the business already cares about.

    From important player to strategic partner

    The encouraging part is that the tools and the data to work this way already exist, and buyers are already rewarding the companies that can produce proof on demand. A security leader who can show what the program made possible, the deals it helped close and the markets it opened, walks into a very different budget conversation than one still reporting on attacks fended off.

    My advice to security leaders is simple, and it is the same thing I ask of my own team. Stop letting your program be judged on the absence of bad news. Tie it to the outcomes your board already tracks, report against them transparently even when a number is ugly, and show that you are improving quarter over quarter. Do that consistently, and the business will finally see security for what it can be: one of the clearest sources of growth the leadership team has.

    [ Learn more at the CISO Forum ]

    Related: Four Risks Boards Cannot Treat as Background Noise

    Related: What CISOs Can Expect in 2026 and Beyond

    CISOs hired job Judged problem Real
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hackers target WordPress sites in miniOrange auth bypass attacks

    Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

    Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

    The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk

    Robotaxis are real now — so is the pushback

    ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Indonesia integrates Indigenous data in bid to put customary lands on map

    August 25, 2026

    Let’s focus on what people with special needs can do, rather than what they can’t | Young people

    August 25, 2026

    Australia news live: PM dubbed ‘WA’s daddy’ over Blue Poles and GST promises; RBA poised to lift interest rates again if needed | Australia news

    August 25, 2026

    Kabinettsklausur: Altes Ritual, neue Probleme – POLITICO

    August 25, 2026
    Latest Posts

    The Doctor and His Diary: What Fauci’s Innermost Musings Reveal

    July 29, 2026

    Iran Considered Retaliatory Strike on Ukrainian Seaport

    July 29, 2026

    The French presidential candidate who wants to blow up the Franco-German engine – POLITICO

    July 29, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Indonesia integrates Indigenous data in bid to put customary lands on map

    August 25, 2026

    Let’s focus on what people with special needs can do, rather than what they can’t | Young people

    August 25, 2026

    Australia news live: PM dubbed ‘WA’s daddy’ over Blue Poles and GST promises; RBA poised to lift interest rates again if needed | Australia news

    August 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.