InfoBrief | The Evolving Role of the CISO

InfoBrief | The Evolving Role of the CISO

IDC’s survey of 847 decision-makers across 17 countries reveals that the CISO role is evolving, balancing both strategic and tactical responsibilities in today’s digitally transformed organizations. Key findings highlight challenges like alignment with CIOs and the need for continuous skill development to address emerging cybersecurity priorities. Download now to learn more.

InfoBrief | The Evolving Role of the CISO

The Changing Role of the CISO Today’s Chief Information Security Officer (CISO) is an architect and business leader.

InfoBrief, sponsored by Check Point Software | March 2024

Frank Dickson Program Vice President, Cybersecurity Products, IDC

2InfoBrief, sponsored by Check Point Software March 2024 | IDC #US51875024

The Changing Role of the CISO

Table of Contents CLICK BELOW TO NAVIGATE TO EACH SECTION IN THIS DOCUMENT

In This InfoBrief . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .3

The Reality of a CISO’s Role is Different than Most Think . . . . . . . . . . . .4

CISOs Hold Themselves to a High Standard . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .5

Despite Being in a Strategic Role, CISOs Have Tactical Concerns . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .6

CIO and CISO Priorities Are Not Aligned . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7

CIOs and CISOs Each See the Other as a Source of Friction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .8

More Tenured CISOs Focus on Customer Support and Business Strategy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .9

The Security Mindset Transitions from Fear to Hypergrowth Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10

Security Executives Are Looking to Drive Business Initiatives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11

Key Takeaway . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12

Appendix: Supplemental Data . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13

About the IDC Analysts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16

Message from the Sponsor . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .17

3Table of Contents

The Changing Role of the CISO

InfoBrief, sponsored by Check Point Software March 2024 | IDC #US51875024

IDC sought to understand the CISO’s role in today’s digitally transformed organizations.

⊲ What are their top priorities when working with IT?

⊲ What are their key challenges?

⊲ How do they spend their time?

⊲ How has the role evolved?

In This InfoBrief Research Overview

• IDC conducted a survey of 847 decision makers in 17 countries on tech and cybersecurity products.

• Respondents were director level and above and worked at organizations with 500 or more employees.

• IDC focused on CIOs and CISOs.

• IDC also conducted several in-depth interviews to gather qualitative insights.

Key Findings • The CISO’s role is different to what most think.

• CISOs are concerned with both strategy and tactics.

• CIOs and CISOs aren’t always aligned.

• CISOs need to continuously evolve their skills to meet the strategic nature of their role.

4Table of Contents

The Changing Role of the CISO

InfoBrief, sponsored by Check Point Software March 2024 | IDC #US51875024

CIOs and CISOs have different views on the role of the CISO

n = 61 (CISOs), n = 62 (CIOs), n = 847; Source: IDC’s CIO/CISO Thought Leadership Survey, November 2023

18% CISO

The Reality of a CISO’s Role is Different than Most Think Everyone agrees that a CISO is more than just a cybersecurity person. The role also needs a mix of IT architecture, people, business, and communication skills.

Awareness and understanding of the latest cybersecurity threats . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

IT architecture and engineering skills . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Cybersecurity architecture and engineering skills . . . . . . . . . . . . . . . . . . . . .

Cybersecurity policy formulation and application . . . . . . . . . . . . . . . . . . . . . .

Leadership and team-building skills . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Business management skills . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Technical knowledge . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Broad understanding of the security field . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Project management skills . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Compliance and legal knowledge . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Communication skills with upper management/boards . . . . . . . . . . . . .

12%

12%

10%

10%

10%

8%

7%

7%

6%

5%

5%

Thinking about strengths and skills that a CISO should possess, which of the following are most important?

CIOs think of the CISO’s role as more tactical.

CISOs are focused on strategic architecture.

8% CIO

5% CISO

13% CIO

5Table of Contents

The Changing Role of the CISO

InfoBrief, sponsored by Check Point Software March 2024 | IDC #US51875024

75% CIO

CISOs Hold Themselves to a High Standard Organizations have more confidence in their CISOs than CISOs do of themselves.

How satisfied are you with your CISO’s response to the recent breach?

Overall, how satisfied are you with how your current CISO meets and achieves their role functions?

CIO

Overall, how satisfied are you with your ability to achieve the role functions of CISO?

CISO

94%

85% 67%9% 8%

How satisfied are you with your response as CISO to the recent breach?

n = 61 (CISOs), n = 62 (CIOs); Source: IDC’s CIO/CISO Thought Leadership Survey, November 2023

CISO

6Table of Contents

The Changing Role of the CISO

InfoBrief, sponsored by Check Point Software March 2024 | IDC #US51875024

23%

Despite Being in a Strategic Role, CISOs Have Tactical Concerns CISOs are most concerned with inflation’s impact on budget and the impact of recession on expected business revenue, while CIOs are most concerned with staffing shortages.

Which of the following risk factors related to your organization’s tech spending for the next 12 months concern you the most?

■ CIO  ■ CISO

Inflation driving up vendor pricing beyond budget expectations . . . . . . . . . . . . . . . . . . . . . . 16%

Potential geopolitical turmoil forcing changes in a tech provider . . . . . . . . . . . . . . . . . . . . . . 7% 3%

Staffing/labor shortages preventing effective use of technology . . . . . . . . . . . . . . . . . . . . . . 18%8% Energy shortages affecting overall business activity . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13%8%

Managing demand for cloud subscriptions in line with budgeting plans . . . . . . . . . . . . . . 10%8%

Ability to attain cyberinsurance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8% 13%

Not being able to get access to IT hardware due to supply chain constraints . . . . . . . . 10% 15%

Impact of recession on expected business revenue . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15% 18%

n = 61 (CISOs), n = 62 (CIOs); Source: IDC’s CIO/CISO Thought Leadership Survey, November 2023 | For an accessible version of the data in these figures, see Supplemental Data in the Appendix.

7Table of Contents

The Changing Role of the CISO

InfoBrief, sponsored by Check Point Software March 2024 | IDC #US51875024

CIO and CISO Priorities Are Not Aligned Competing expectations about the CISO’s role in business resiliency may hamper their effectiveness.

What are the CIO’s areas of top priority in working with cybersecurity? What are the CISO’s areas of top priority in working with IT?

CIO CISO

n = 61 (CISOs), n = 62 (CIOs); Source: IDC’s CIO/CISO Thought Leadership Survey, November 2023 | For an accessible version of the data in these figures, see Supplemental Data in the Appendix.

Ensuring cybersecurity requirements are met before technology investments are made . . . . . . . . . . . .

Analyzing security vulnerabilities requiring IT remediation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Ensuring network security through firewall management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Ensuring integration between IT and security projects . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

27

16

7

3

46

18

10

8

Seeking faster response times from IT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 0

Coordinating and planning resources, including budgets and staff . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5 5

Formulating a cloud security strategy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 2

Providing architecture for delivering business change . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5 2

Delivering a secure digital workplace for onsite and remote staff . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 2

Protecting business assets from data loss . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2 3

Securing software development life cycle . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7 5

Ensuring business continuity and resilience, minimizing disruption. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 0

CISOs are most focused on cybersecurity and vulnerabilities. CIOs are focused on seeking faster response times from IT and ensuring business continuity and resilience, minimizing disruption, which aren’t on CISOs’ radar.

8Table of Contents

The Changing Role of the CISO

InfoBrief, sponsored by Check Point Software March 2024 | IDC #US51875024

CIOs and CISOs Each See the Other as a Source of Friction

Which area of focus has proven most challenging in working with security?

Security activities are frequently causing disruptions, impacting IT operations. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Security is challenged in integrating technology requirements to broader enterprise applications. . . . . . . . . . . . . . . . . . . . . . . . . .

No difficult challenges in working with security . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Security makes too many unilateral technology choices . . . . . . . . . . . . .

21%

16%

13%

10%

Security is challenged in adhering to IT standards for its technology implementations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10%

Security’s risk management requirements are not clearly articulated or planned . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Security requirements demand too much of IT resources, including budget and staff . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Difficulty in understanding one another’s business language and operations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

8%

8%

8%

IT activities are frequently causing disruptions, impacting security operations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

IT is challenged in adhering to security’s standards for its implementations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

No difficult challenges in working with IT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

IT makes too many unilateral technology choices . . . . . . . . . . . . . . . . . . . . . . . .

20%

20%

18%

13%

IT is challenged in integrating security requirements to broader enterprise applications . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10%

IT requirements demand too much of security’s resources, including budget and staff . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

IT’s technology requirements are not clearly articulated or planned . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Difficulty in allocating shared computing and storage resources to security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

7%

3%

3%

n = 61 (CISOs), n = 62 (CIOs); Source: IDC’s CIO/CISO Thought Leadership Survey, November 2023

CIO CISO

CIO’s cite security activities frequently causing disruptions, impacting IT operations as the top challenge, while CISOs say the same about IT activities.

9Table of Contents

The Changing Role of the CISO

InfoBrief, sponsored by Check Point Software March 2024 | IDC #US51875024

“A CISO has to be able to articulate technical risk in a business-friendly manner. Any executive is trying to understand what threats mean to the business.”

FORTUNE 500 INSURANCE CIO

“There is growing need for customer support as the customer’s compliance requirements grow, and so the CISO has to help. The CISO also has to be involved in new sales. Any new customer wants to meet with the CISO and understand your security measures. So as you look at that, you can clearly see security is part of their mantra.”

CIO OF MIDSIZE BANK

Customer support

More Tenured CISOs Focus on Customer Support and Business Strategy How CISOs Spend Their Time

Cybersecurity tactics and procedures

Compliance

Leadership and risk management

C IS

O M

A T

U R

IT Y

Executive/business strategy and architecture

10Table of Contents

The Changing Role of the CISO

InfoBrief, sponsored by Check Point Software March 2024 | IDC #US51875024

99% of CEOs lead or support

digital initiatives.

Investing in emerging technology areas

(e.g, generative AI, predictive AI, machine learning, blockchain) is the most common technology priority.

Security leaders coming from a place of fear over

numerous risk concerns is a huge internal challenge to accomplishing digital

initiatives.

Delays in security teams adopting a growth mindset

prompts business leaders to pinpoint security holding back

key growth initiatives.

The Security Mindset Transitions from Fear to Hypergrowth Mode CISOs must balance the real fears of sophisticated cyberattacks and an economic downturn with supporting growth initiatives to create new revenue streams and boost efficiency.

n = 847; Source: IDC’s CIO/CISO Thought Leadership Survey, November 2023

11Table of Contents

The Changing Role of the CISO

InfoBrief, sponsored by Check Point Software March 2024 | IDC #US51875024

Security Executives Are Looking to Drive Business Initiatives What is the most important way you see your role evolving over the next 12–24 months?

39% Continue to focus on traditional

security responsibilities

5% Move into a more business-focused role in the C-suite (e.g., COO, CMO)

33% Broaden role to be a business leader in the area of trust (including security, risk, and compliance)

16% Develop into a broader CIO role

7% Take on a different technology

leadership role (e.g., CTO, CDO)

n = 89; Source: IDC’s Worldwide C-Suite Tech Survey, August 2023 | For an accessible version of the data in these figures, see Supplemental Data in the Appendix.

12Table of Contents

The Changing Role of the CISO

InfoBrief, sponsored by Check Point Software March 2024 | IDC #US51875024

Key Takeaway

As security practioners move higher up in the organization, their skills and knowledge must evolve. CISOs must develop their executive abilities to have an impact across the most senior leadership to improve business outcomes.

CISOs should consult and coordinate with the following stakeholders:

• Compliance: to assist in achieving and reporting compliance

• Risk management: to aid in understanding the company’s risk posture and to make necessary policy and technology changes

• Line of business or other functional areas: to coach and improve security and impact ongoing strategy

• Overall leadership: to develop cybersecurity function across the entire organization and not just IT

• Customers: to consult with customers to help them achieve compliance and understand customer pain points in order to best address

CISOs need to build their skills to become more strategic.

Executive/business strategy and architecture

Cybersecurity techniques, tactics, and procedures

Customer support

Leadership and collaboration

Compliance and risk management

13Table of Contents

The Changing Role of the CISO

InfoBrief, sponsored by Check Point Software March 2024 | IDC #US51875024

Appendix: Supplemental Data The table in this appendix provides an accessible version of the data for the complex figures in this document. Click “Return to original figure” below this table to get back to the original data figure.

SUPPLEMENTAL DATA FROM PAGE 6

Which of the following risk factors related to your organization’s tech spending for the next 12 months concern you the most?

CISO CIO

Inflation driving up vendor pricing beyond budget expectations 23% 16%

Impact of recession on expected business revenue 18% 15%

Not being able to get access to IT hardware (e.g., PCs, peripherals, datacenter infrastructure) due to supply chain constraints 15% 10%

Ability to attain cyber insurance 13% 8%

Managing demand for cloud subscriptions in line with budgeting plans 8% 10%

Energy shortages affecting overall business activity 8% 13%

Staffing/labor shortages preventing effective use of technology 8% 18%

Potential geopolitical turmoil forcing changes in a tech provider 3% 6%

n = 61 (CISOs), n = 62 (CIOs); Source: IDC’s CIO/CISO Thought Leadership Survey, November 2023

Return to original figure

14Table of Contents

The Changing Role of the CISO

InfoBrief, sponsored by Check Point Software March 2024 | IDC #US51875024

Appendix: Supplemental Data (continued) SUPPLEMENTAL DATA FROM PAGE 7

What are the CISO’s areas of top priority in working with IT? What are the CIO’s areas of top priority in working with cybersecurity?

CISO CIO

Ensuring cybersecurity requirements are met before technology investments are made 46% 27%

Analyzing security vulnerabilities requiring IT remediation 18% 16%

Ensuring network security through firewall management 10% 7%

Ensuring integration between IT and security projects 8% 3%

Seeking faster response times from IT 0% 7%

Coordinating and planning resources, including budgets and staff 5% 5%

Formulating a cloud security strategy 2% 7%

Providing architecture for delivering business change 2% 5%

Delivering a secure digital workplace for onsite and remote staff 2% 7%

Protecting business assets from data loss 3% 2%

Securing software development life cycle 5% 7%

Ensuring business continuity and resilience, minimizing disruption 0% 10%

n = 61 (CISOs), n = 62 (CIOs); Source: IDC’s CIO/CISO Thought Leadership Survey, November 2023

Return to original figure

15Table of Contents

The Changing Role of the CISO

InfoBrief, sponsored by Check Point Software March 2024 | IDC #US51875024

Appendix: Supplemental Data (continued) SUPPLEMENTAL DATA FROM PAGE 10

What is the most important way you see your role evolving over the next 12–24 months?

Percentage

Continue to focus on traditional security responsibilities 39%

Move into a more business-focused role in the C-suite (e.g., COO, CMO)

5%

Take on a different technology leadership role (e.g., CTO, CDO) 7%

Develop into a broader CIO role 16%

Broaden role to be a business leader in the area of trust (including security, risk, and compliance)

33%

n = 89; Source: IDC’s Worldwide C-Suite Tech Survey, August 2023

Return to original figure

16Table of Contents

The Changing Role of the CISO

InfoBrief, sponsored by Check Point Software March 2024 | IDC #US51875024

Frank leads the team that delivers compelling research in the areas of Network Security; Endpoint Security; Cybersecurity Analytics, Intelligence, Response, and Orchestration (AIRO); Identity & Digital Trust; Legal, Risk & Compliance; Data Security; IoT Security; and Cloud Security. Topically, he provides thought leadership and guidance for clients on a wide range of security products including endpoint security, identity and access management, authentication, threat analytics, and emerging products designed to protect transforming architectures and business models.

More about Frank Dickson

Frank Dickson Program Vice President, Cybersecurity Products, IDC

About the IDC Analysts

17

The Changing Role of the CISO

Table of Contents InfoBrief, sponsored by Check Point Software March 2024 | IDC #US51875024

Message from the Sponsor

Learn more about how Check Point can protect your organization at www.checkpoint.com

Founded over 30 years ago, Check Point has secured the digital world for everyone, everywhere.

From the first stateful firewall to dynamic security innovations to the emergence of the Check Point Infinity Platform, AI-powered, cloud-delivered cybersecurity with 99.8% prevention rates. More than 50 AI engines deliver collaborative security across an organization’s entire security architecture, comprised of the network, the cloud, and the workspace. Add to this Infinity Core Services comprehensive technical services to ensure we address customers’ evolving cybersecurity needs.

This publication was produced by IDC Custom Solutions. The opinion, analysis, and research results presented herein are drawn from more detailed research and analysis independently conducted and published by IDC, unless specific vendor sponsorship is noted. IDC Custom Solutions makes IDC content available in a wide range of formats for distribution by various companies. This IDC material is licensed for external use and in no way does the use or publication of IDC research indicate IDC’s endorsement of the sponsor’s or licensee’s products or strategies.

IDC Research, Inc. 140 Kendrick Street, Building B, Needham, MA 02494, USA T +1 508 872 8200

International Data Corporation (IDC) is the premier global provider of market intelligence, advisory services, and events for the information technology, telecommunications, and consumer technology markets. With more than 1,300 analysts worldwide, IDC offers global, regional, and local expertise on technology and industry opportunities and trends in over 110 countries. IDC’s analysis and insight helps IT professionals, business executives, and the investment community to make fact-based technology decisions and to achieve their key business objectives.

©2024 IDC. Reproduction is forbidden unless authorized. All rights reserved. CCPA

idc.com @idc @idc

In This InfoBrief The Reality of a CISO’s Role is Different than Most Think CISOs Hold Themselves to a High Standard Despite Being in a Strategic Role, CISOs Have Tactical Concerns CIO and CISO Priorities Are Not Aligned CIOs and CISOs Each See the Other as a Source of Friction More Tenured CISOs Focus on Customer Support and Business Strategy The Security Mindset Transitions from Fear to Hypergrowth Mode Security Executives Are Looking to Drive Business Initiatives Key Takeaway Appendix: Supplemental Data About the IDC Analysts Message from the Sponsor


Item Type: pdf