The Macrosite for News, Analysis and Opinion about the Future of the Internet
Alison Diana

The Decade of the CISO

Written by Alison Diana
1/24/2013 3 comments
no ratings
DISCUSS     Email This

With cyber-dangers lurking everywhere, more organizations are hiring chief information security officers to augment -- or even replace -- traditional CIOs, a move some see as increasingly necessary given the ongoing adoption of BYOD, mobile computing, and collaboration.

More than 55 percent of respondents to a survey of 652 IT and business professionals commissioned by IntraLinks, released today, currently have a CISO. In 2010, an SC Magazine study found 29 percent had this exec in 2008, while 44 percent did so a year later.

Now, adding another c-level executive may initially seem like an unnecessary expense, but, depending on your organization's size and complexity, this professional could actually generate enough funding -- and more -- to cover the position.

Effective CISOs with well-run information security programs can save their companies up to almost 10 percent of total revenue through reduced risk of data loss and theft, a report by SC Magazine found. In addition, organizations with CISOs are 10 times less likely to suffer expensive security breaches.

Jim Hurley, managing director of Symantec's IT Policy Compliance Group, told EC Council:

Simply put, CISOs contribute to better business results by ensuring security measures are fully implemented, standardizing and automating procedures, and by taking a strategic role with the organization to make information security a part of a business process.

CISO Transformation
For those IT professionals interested in pursuing a CISO position, there are several organizations dedicated to helping you earn the role. Of course, you need experience in IT, particularly security. Business knowledge doesn't hurt either. Additional, CISO-specific help is on-hand, too.

From formal offerings such as Carnegie Mellon University's Heinz College CISO Executive Education and Certification Program, to an array of regional forums from organizers such as the Argyle Executive Forum and Evanta Summits, security technologists have plenty of choices to support their career path.

Climbing the Security Ladder
Focusing on security can be good for your business and your career.
Focusing on security can be good for your business and your career.

The end of that educational road is promising. CISOs will hold a valued place in the boardroom, offering important insight to the rest of the c-suite, analysts such as IDC predict. While the position varies from organization to organization, on average, responsibilities have increased over the past three years, Forrester claims. According to Computerworld, they include third-party security, threat and vulnerability management, identity and access management, and fraud management.

As Andrew Rose and Nick Hayes of Forrester wrote in their report:

While one could argue this is a good thing, as it demonstrates the trust the organization has in the security function, it's also worth noting that old expectations do not go away. Therefore, CISOs have had to address an increasingly long task list with only marginally more resources, which can have several negative repercussions.

This year, CISOs will face topics such as BYOD security; social networking and customer experience, return on value, and security; siloed governance, risk management, and compliance implementations; big-data and analytics risk; enabling innovation; value of Internet of Things; enabling innovation; virtual datacenter security; cloud; "inevitable" breaches, and what IDC describes as the "Tower of Crypto Babel," the research firm said in a recent webinar.

In return, for addressing and guiding these crucial decisions, CISOs can earn salaries of between about $114,000 and $238,000, with a median pay of $168,000, according to Salary.com. SimplyHired.com shows similar, although slightly lower, salaries.

This morning, Glassdoor showed 123 open CISO positions -- and who knows? Your company may need someone with this title but not even know it.

Good luck!

— Alison Diana Visit my LinkedIn pageFollow me on TwitterCircle me on Google+, ThinkerNet Editor, Internet Evolution

Related posts:

DISCUSS     Email This
Current display:       chronological order       display newest comments first
Mitch Wagner
Thinkernetter
Thursday January 24, 2013 4:53:57 PM
no ratings

It's difficult to conceive of a CISO working outside of IT. The security and the object being secured surely should be together. 

OTOH, it's possible to imagine a single position comprising security (both cyber- and physical), as well as compliance and legal. All are different types of threats. 

DavidSilversmith
Thinkernetter
Thursday January 24, 2013 10:20:54 PM
no ratings

I was just reading another post about HR and IT being high stress due to all the secrets they need to keep - add CISO to this list.

The job reminds me of jobs like dentists.  So few like going to the dentist and so few people like hearing about security issues.  To exectives it is about defense (avoiding risk) rather than offense (making money, innovating, new product/service development).  To the regular old employee, security is one more inconvenience.

A needed job - yes!  But a stressful one.  And, if a security issue arises, I have to image the CISO is at the forefront of any necessary human sacrifice for the company to save face.

Alison Diana
Thinkernetter
Friday January 25, 2013 9:34:41 AM
no ratings

I'd think it takes a certain type of person to be a CISO, someone who certainly thrives on pressure and change, but someone who also enjoys a challenge and on accomplishing temporary victories in an ongoing battle. I'd love to delve deeper into how some CISOs earned their positions, especially at midsize organizations. Did they come from an IT position that evolved, basically from focusing on security for the majority of their job? Did the organization realize it needed a c-level security exec after a major breach or problem? Did two companies merge, making it necessary for a senior manager to oversee security integration? Something completely different? 

The ThinkerNet does not reflect the views of TechWeb. The ThinkerNet is an informal means of communication to members and visitors of the Internet Evolution site. Individual authors are chosen by Internet Evolution to blog. Neither Internet Evolution nor TechWeb assume responsibility for comments, claims, or opinions made by authors and ThinkerNet bloggers. They are no substitute for your own research and should not be relied upon for trading or any other purpose.
previous posts from IT Clan Editor's Blog
Mitch Wagner
Mitch Wagner   5/23/2013   3 comments
A pair of IBM studies show how advanced IT tools help drive value in two very different business functions: marketing and procurement.
Mitch Wagner
Mitch Wagner   5/16/2013   13 comments
Facebook and Twitter are great for posting cat pictures. But are people really using social media for life-changing communications? Like, if a hurricane comes by and blows down their house?
Kim Davis
Kim Davis   5/9/2013   18 comments
In a standout presentation at the Jefferies 2013 Global Technology, Media & Telecom Conference in New York this week, the UK government talked about becoming a "very intelligent client."
Mitch Wagner
Mitch Wagner   5/2/2013   9 comments
A consumer business would have to be crazy or desperate to change call-center software in December, the peak of the holiday season. But that was exactly Positec's position.
Mitch Wagner
Mitch Wagner   4/25/2013   10 comments
To help enterprises deploy software faster for mobile, social, big-data, and cloud applications, IBM this week acquired development tools vendor UrbanCode.
5
of
Mitch Wagner
TweetDeck Gets a Second Life

11|5|12   |   9:54   |   13 comments


A recent release of the popular TweetDeck app for Twitter power-users gives new life to software that had previously taken a wrong turn. Here's a quick walk-through of the new TweetDeck, to show you why it should be at the top of your Twitter toolkit.
Steve Saunders' Outernet
The Death of Anonymity: Part 3

Part 3 of 4   |  
See complete series
10|28|09   |   1:35   |   4 comments


What can users today do to protect their online privacy? The simplest and most obvious option is to not use the Internet – at all. However, once all digital information is consolidated over the Internet, trying to protect digital identity by simply unplugging from the Internet becomes impossible – a fact that has manifest implications for civil liberties, Saunders says.
Steve Saunders' Outernet
The Death of Anonymity: Part 2

Part 2 of 4   |  
See complete series
10|27|09   |   2:08   |   9 comments


By 2011 the number of Internet-connected sensors will exceed 1 trillion, making your chances of doing anything or going anywhere unnoticed pretty much zero. Saunders talks about how the 'sensortization' of the Internet is eliminating the traditional divide between online and offline populations.
Steve Saunders' Outernet
The Death of Anonymity: Part 1

Part 1 of 4   |  
See complete series
10|26|09   |   1:29   |   13 comments


The 20th Century Internet was characterized by the ability to interact with other people and information on the Internet largely without anyone knowing who you were. The Internet of this century, conversely, will be defined by identity. Saunders explains how Internet users are unwittingly contributing to the demise of the anonymous Internet.
The Incredible Hultquist
Social Networks & Hiring Pitfalls

10|16|09   |   2:16   |   5 comments


More companies are trolling social networks to find and vet potential job candidates. Beware the pitfalls of blurring the line between personal and professional lives.
Steve Saunders' Outernet
The Coming Internet Bubble: Part 2

Part 2 of 2   |  
See complete series
10|16|09   |   3:38   |   19 comments


How do you recognize an Internet bubble when you see one? Saunders explains how all bubbles have four symptoms in common – and takes a swipe at Google and Twitter into the bargain.
Paul J. Fleuranges
Digital Signage Keeps NYC Subway Straphangers on Track

5|6|13   |   3:51   |   No comments


New York's Metropolitan Transit Authority is conducting a pilot test of digital kiosks to guide subway users to where they want to go more efficiently and at lower cost.
Kim Davis
Fast Forward to the Future

4|23|13   |   2:29   |   20 comments


A look back at tech writing in the 90s makes us wonder where enterprise IT will be 20 years from now.
Mitch Wagner
'Digital Nomads' Work From Anywhere & Everywhere

2|14|13   |   2:35   |   20 comments


New tools like laptops, tablets, smartphone, and wireless connectivity let us work from San Diego to Katmandu, and anywhere in between. But time management remains a problem.
Second Shooter
Graphing Facebook Graph Search's Success

1|25|13   |   2:13   |   10 comments


Facebook's Graph Search may face some profound challenges and risks, first, because Facebook users haven't been thinking of their posts as product reviews; and second, because Facebook will now have to contend with the social-network equivalent of SEO "gaming" of results.
IETV: the thinkerNet on film
5
of
Kim Davis
Big-Data Can’t Always Sell Wine

5|21|13   |   2:23   |   4 comments


Whole Foods Global Wine Purchaser Doug Bell told me about some of the constraints on using analytics in the US wine market.
Paul J. Fleuranges
Digital Signage Keeps NYC Subway Straphangers on Track

5|6|13   |   3:51   |   No comments


New York's Metropolitan Transit Authority is conducting a pilot test of digital kiosks to guide subway users to where they want to go more efficiently and at lower cost.
Kim Davis
Fast Forward to the Future

4|23|13   |   2:29   |   20 comments


A look back at tech writing in the 90s makes us wonder where enterprise IT will be 20 years from now.
Mitch Wagner
Google Launches Its Most Depressing Service Yet

4|15|13   |   2:59   |   10 comments


Google's new Inactive Account Manager lets you control how Google disposes of your accounts when you die.
Second Shooter
Argument Over Top-Level Domains Is 'Stupid'

4|11|13   |   2:07   |   3 comments


The whole Amazon.reader debate is a double-stupid. It's stupid to think that there's any e-book buyer who doesn't know Amazon's URL, and it was stupider to let ICANN launch the whole free-form TLD initiative to start with.
Kim Davis
Ladies, Your Tablet Awaits

3|21|13   |   2:22   |   37 comments


ePad Femme is the world’s first tablet “made exclusively for women.”
Wisdom of the Big Chair
NFC Moves Into the Mainstream

3|20|13   |   2:16   |   No comments


While NFC's original goal was to enhance mobile commerce applications, it is finding its way into a number of other uses, which is creating both opportunity as well as challenges for IT departments.
Wisdom of the Big Chair
Integrating Security Into Your Cloud Contract

3|19|13   |   3:35   |   No comments


Enterprises would like to move to cloud computing but are hesitant because they are concerned about providers’ ability to secure company data. Here are some tips that help to ensure that if breaches occur, the business is not left holding the bag.
Brian Baron
How Edmunds.com Collects Customer Information

3|18|13   |   1:15   |   No comments


Edmunds separates customers into segments based on the info it collects on its site and from partners, and uses that to push out custom content, said Brian Baron, director of business analytics for Edmunds.com, at Predictive Analytics Innovation Summit.
Brian Baron
How Edmunds.com Uses Analytics to Customize Site

3|14|13   |   0:47   |   No comments


The automotive website uses propensity modeling to target ads and customer registration forms, said Brian Baron, director of business analytics for Edmunds.com, at Predictive Analytics Innovation Summit.
an IBM information resource
sponsored content
big blue blog
an IBM information resource
sponsored content
Expert Integrated Systems: Changing the Experience & Economics of IT
In this e-book, we take an in-depth look at these expert integrated systems -- what they are, how they work, and how they have the potential to help CIOs achieve dramatic savings while restoring IT's role as business innovator.

READ THIS eBOOK
your weekly update of news, analysis, and
opinion from Internet Evolution - FREE!

REGISTER HERE
Wanted! Site Moderators
Internet Evolution is looking for a handful of readers to help moderate the message boards on our site – as well as engaging in high-IQ conversation with the industry mavens on our thinkerNet blogosphere. The job comes with various perks, bags of kudos, and GIANT bragging rights. Interested?

Please email: moderators@internetevolution.com
Internet Evolution – not for thickies
Keep Critical Data With a Knowledge Management System
Taimoor Zubair
Fortune 500 companies lose at least
$31.5 billion a year by failing to share knowledge. A Knowledge Management System (KMS) can help companies significantly reduce these costs.

CLICK FOR MORE
M2M: Rise of the Machines? Not Yet
David Weldon
In the 1970 science fiction thriller
Colossus: The Forbin Project, two giant supercomputers from the United States and Soviet Union secretly join forces to take control of the collective nuclear might of the two countries. In the film, the two machines discover each other's existence, communicate back-and-forth, share their collective data, and cut their human creators out of the process. It is the ultimate example of machine-to-machine communications, or M2M.

CLICK FOR MORE
M2M: Rise of the Machines? Not Yet
David Weldon
In the 1970 science fiction thriller
Colossus: The Forbin Project, two giant supercomputers from the United States and Soviet Union secretly join forces to take control of the collective nuclear might of the two countries. In the film, the two machines discover each other's existence, communicate back-and-forth, share their collective data, and cut their human creators out of the process. It is the ultimate example of machine-to-machine communications, or M2M.

CLICK FOR MORE