More and more businesses now have CISOs - but they're increasingly taking the blame for attacks

A computer being guarded by cybersecurity.
(Image credit: iStock)

What is the role of the Chief Information Security Officer (CISO)? A new report has suggested it mainly serves as a scapegoat for all cybersecurity incidents, and then some. 

Fastly surveyed 1,500 global IT decision-makers on their opinions, and found while the number of newly appointed CISOs continues to grow, many respondents still don’t properly understand the role.

The report found the recent CISO hiring boom has consolidated, as in 2022, it was 120%, and has now fallen to 73% in 2023, meaning nearly three-quarter (73%) of UK and Irish businesses now have a CISO, and a further 15% are planning to hire one in the next two years.

Confusion 

But many still don’t understand the role. More than a quarter (27%) think CISOs are blamed too often for things out of their control - a sentiment that has persisted over the years (25% in 2021 and 30% in 2022). 

When it comes to identifying roles, responsibilities, and expectations of CISOs, IT pros are somewhat confused: 2 in 5 (39%) believe CISOs need to have an in-depth understanding of all areas of IT (down from 54% a year ago), while a quarter (23%) think they were given too much legal and operational responsibility (down from 34% a year ago).

“Our data suggests there still exists confusion over what the role of the CISO's actually entails,” said Fastly’s CISO Marshall Erwin. “This disparity of opinion highlights how the role has evolved in recent years, particularly with challenges to organisation’s security postures and growing threat landscape.”

Until this year, CISOs were confined to IT and risk management, Erwin added, saying that things changed this year. Now, CISOs are increasingly being perceived as business leaders, responsible for the strategic direction of an organization’s cybersecurity strategy. That is, he points out, where the lack of understanding about the role comes from in the first place. “Within two years, the majority of UK and Irish businesses will have filled the CISO role. For them to work effectively, there is clearly a need for organizations to develop greater understanding of the role amongst IT departments.”

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Cyber-security
Security leaders don't want to be held personally liable for attacks
Cyber-security
Dealing with the issue of CISO stress
Cartoon Phishing
Hackers use GenAI to attack more frequently and effectively
Hack The Box crisis simulation event
“Everyone will experience a hack” - how incident response can protect your organization
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
An abstract image of a lock against a digital background, denoting cybersecurity.
How cybersecurity jargon creates barriers and wastes resources
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)