Nearly half of firms still don't have a CISO

Hands typing on a keyboard surrounded by security icons
(Image credit: Shutterstock)

Despite cyber assaults such as ransomware rising in numbers over recent years, many organizations still don’t have a Chief Information Security Officer (CISO). What’s more, some of them are under the impression that they don’t even need one, with others saying they are struggling to find the right candidate due to the growing skills gap and the so-called “Great resignation”.

A new report published by Navisite surveying 130 security, IT, and compliance professionals found that almost half (45%) don’t employ a CISO. Of that group, just a slim majority (58%) think they should have one in the team. 

Most organizations have a cybersecurity strategy, but for the majority (60%), it was developed by teams and people other than the CISO - it was either the IT department, compliance department, or executive leadership. 

In fact, some companies (21%) don’t even have a person dedicated solely to cybersecurity, at all, while most of them (75%) experienced an increase in overall cybersecurity threat volume in the past 12 months.

Instilling confidence

Not having an executive to handle cybersecurity hurts the confidence of these companies, the report further said. Among firms with a Chief Security Officer, 70% were confident in the effectiveness of their strategies, while among those without one - 58% were confident. 

Finally, many respondents would love to see their organization spend a little more money on cybersecurity solutions, staff, and training.

“The survey results support what we’re seeing across the board: organizations prioritized their security efforts during Covid, but at the same time, they’re acutely aware of how much more they need to do to effectively defend against cyber threats,” said Aaron Boissonnault, Navisite CISO. 

“The data also points to an ongoing problem in the industry: a cybersecurity skills shortage that extends to the highest levels. Companies value and want cybersecurity leadership, but it is increasingly difficult to find and retain these individuals.”

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Cyber-security
Security leaders don't want to be held personally liable for attacks
An abstract image of digital security.
Tackling the UK's cybersecurity skills shortage
Hacker Typing
Racing against time on a menacing caldera: survey finds majority of organizations take days to tackle critical vulnerabilities, each of them a potential open goal for cybercriminals
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Cartoon Phishing
Hackers use GenAI to attack more frequently and effectively
Classroom
Many schools still don’t have basic cybersecurity measures, research reveals
Latest in Security
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Latest in News
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 9 (game #1140)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 9 (game #371)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 9 (game #637)
WhatsApp
WhatsApp just made its AI impossible to avoid – but at least you can turn it off