ESProfiler Handbook
Personas

CISO - Simon

The CISO is the accountable one of the security team.

The Accountable One

"Can you get me this on one page. I need something defensible, not a guess."

Quick facts

TitleCISO / Group CISO / VP Information Security
Company profile10,000+ employees, $1bn+ revenue
Budget authorityUltimate — but rarely the sole named owner. See "Where the money actually sits" below.
Reports toVaries widely — CIO (most common), CEO, CFO, COO, or CRO
Direct reportHarry the Head of Cyber / Chief Security Architect
Time in roleShorter than most C-suite peers — see note on tenure below
Primary motivationWalk into the board unable to be unpicked in the room

Where the money actually sits

Cyber budget ownership is genuinely inconsistent across enterprises, and it's worth resisting the temptation to draw it as one clean line.

  • In the majority of organizations, security spend sits inside the CIO's IT budget. Ponemon (2017) found 50% of CISOs reporting to the CIO, versus 4% to the CEO, 9% to the CTO, 9% to the CFO, and 6% to the COO (60% had a channel to the CEO without reporting there)[1]. In this structure, the CIO holds effective allocation power and can shape the CISO's agenda.
  • In a large and growing minority — 45% in an ECSO CISO community survey[2] — cyber budget is independent of the CIO's budget, usually answering instead to the CFO, CEO, or a joint budget committee (typically CEO + CFO + CIO together, not one named owner).
  • Either way, Simon is rarely the sole signatory. What's constant is that he is accountable for the number regardless of who controls it — he has to defend it to the board even when he doesn't fully control its allocation.

Role

Accountable for the organization's security posture and the budget that buys it. Sits in front of the board, the audit committee, and the CFO. Increasingly measured on cost discipline as much as risk reduction — asked "why do we spend $40m on security and still get breached" in the same meeting as "why is spend up 12% this year."

A day/week in his calendar

  • Back-to-back exec and board-adjacent meetings; almost no unstructured time.
  • Delegates almost all stack-level detail to Harry, the Head of Cyber.
  • Engages personally only at decision points: budget cycle, major renewal, incident, audit, M&A.
  • Reads summaries, not source data. If it's not one slide or three bullets, it doesn't get read.

Objectives

  • Defend the budget number to the CFO/board without being unpicked in the room.
  • Avoid being the reason for a breach and avoid being the reason spend went up with nothing to show for it.
  • Convert "trust me" into evidence — frameworks, coverage %, dollars mapped to risk — because that's the language the board will actually accept.

Pain points

  • Inherits a stack built by other people, over years, across departments — and is personally accountable for a picture he didn't build and can't fully verify.
  • Told controls are "in place" on paper; has no reliable way to know if that's true on the ground until an incident proves otherwise.
  • Budget conversations are adversarial by default: reporting line and budget ownership are split more often than the org chart implies[1][2].
  • External reviews land on his desk with little runway: a PwC/KPMG portfolio-rationalisation or cost-optimisation engagement is built to demand current inventory, overlapping capabilities, unused functions, and total cost of ownership (TCO) — a picture he cannot produce from a spreadsheet. See the Problem Statement.
  • A note on tenure: CISO tenure and turnover pressure are widely cited — commonly 18–26 months[3], well under general C-suite tenure. But the 2026 IANS/Artico survey of 662 CISOs reported an average self-reported total tenure of nine years[4] — a very different number, almost certainly because it measures cumulative time across employers rather than time in the current seat. Use the pressure ("job security is genuinely precarious, burnout is real, turnover is high") rather than a specific tenure figure — the underlying stat is contested.

Relationships

Empathy Mapping

Says

"Can you get me this on one page."
"What's our exposure if we cut this?"
"Show me where the dollars map to risk."
"I need something defensible, not a guess."

Does

Signs off budget, doesn't build it
Attends board/audit committee, rarely the tooling reviews
Delegates verification entirely to Harry
Engages only at decision points

Thinks

"I don't actually know what's true on the ground, and that scares me a bit."
"If this breaks, it's my name in the post-mortem."
"Every renewal is a fight I don't have the ammunition for yet."
"I need my people to make me look right in that room."

Feels

Exposed — accountable for things he can't personally verify
Time-poor and defensive by necessity
Relief when someone hands him a clean, evidenced answer
Skeptical of vendor claims, tired of "trust me"

Design & marketing angle

Simon is nearly unreachable directly and doesn't want a demo — he wants a one-pager Harry can hand him before the board meeting or the consultancy readout.

Marketing to Simon is really marketing through Harry: case studies about defensibility, board-ready framework mapping, and dollar-figure overlap findings that make him look good in the room, not tools he'll personally log into. The purchase is a necessity when he cannot otherwise survive that room; see the Problem Statement.

Sources

  • [1] Ponemon Institute (2017) — CISO reporting lines (50% CIO, 4% CEO)
  • [2] ECSO CISO Community, Cybersecurity Budgets: Ownership, Reporting, Trends (2025) — 45% independent of the CIO
  • [3] Cybersecurity Ventures — CISO tenure commonly 18–26 months
  • [4] IANS Research / Artico Search, 2026 State of the CISO — nine-year average self-reported tenure (n=662)
Copyright © 2026