Should a CISO Report to the CIO? Exploring the Role Beyond IT and Cybersecurity

I don’t think a CISO’s role is just “tech,” and that’s exactly why I wouldn’t automatically put them under a CIO. In my previous role as Director of I.T. for a nonprofit, I was tasked with handling our cybersecurity and insurance policies. There was a lot of legal complexity that required close collaboration with lawyers to figure out how to protect our members’ data and privacy, then translate all that into IT procedures and practices.

The responsibility and risk were significant, and it involved much more than just systems and networks. When dealing with legal, compliance, and risk management at that level, it is quite different from the routine tech side.

So should the CISO report to the CIO? Considering their role includes oversight and ensuring security measures are properly implemented, it raises important questions about organizational structure.