CISO - Simon
The Accountable One
"Can you get me this on one page. I need something defensible, not a guess."
Quick facts
| Title | CISO / Group CISO / VP Information Security |
| Company profile | 10,000+ employees, $1bn+ revenue |
| Budget authority | Ultimate — but rarely the sole named owner. See "Where the money actually sits" below. |
| Reports to | Varies widely — CIO (most common), CEO, CFO, COO, or CRO |
| Direct report | Harry the Head of Cyber / Chief Security Architect |
| Time in role | Shorter than most C-suite peers — see note on tenure below |
| Primary motivation | Walk into the board unable to be unpicked in the room |
Where the money actually sits
Cyber budget ownership is genuinely inconsistent across enterprises, and it's worth resisting the temptation to draw it as one clean line.
- In the majority of organizations, security spend sits inside the CIO's IT budget. Ponemon (2017) found 50% of CISOs reporting to the CIO, versus 4% to the CEO, 9% to the CTO, 9% to the CFO, and 6% to the COO (60% had a channel to the CEO without reporting there)[1]. In this structure, the CIO holds effective allocation power and can shape the CISO's agenda.
- In a large and growing minority — 45% in an ECSO CISO community survey[2] — cyber budget is independent of the CIO's budget, usually answering instead to the CFO, CEO, or a joint budget committee (typically CEO + CFO + CIO together, not one named owner).
- Either way, Simon is rarely the sole signatory. What's constant is that he is accountable for the number regardless of who controls it — he has to defend it to the board even when he doesn't fully control its allocation.
Role
Accountable for the organization's security posture and the budget that buys it. Sits in front of the board, the audit committee, and the CFO. Increasingly measured on cost discipline as much as risk reduction — asked "why do we spend $40m on security and still get breached" in the same meeting as "why is spend up 12% this year."
A day/week in his calendar
- Back-to-back exec and board-adjacent meetings; almost no unstructured time.
- Delegates almost all stack-level detail to Harry, the Head of Cyber.
- Engages personally only at decision points: budget cycle, major renewal, incident, audit, M&A.
- Reads summaries, not source data. If it's not one slide or three bullets, it doesn't get read.
Objectives
- Defend the budget number to the CFO/board without being unpicked in the room.
- Avoid being the reason for a breach and avoid being the reason spend went up with nothing to show for it.
- Convert "trust me" into evidence — frameworks, coverage %, dollars mapped to risk — because that's the language the board will actually accept.
Pain points
- Inherits a stack built by other people, over years, across departments — and is personally accountable for a picture he didn't build and can't fully verify.
- Told controls are "in place" on paper; has no reliable way to know if that's true on the ground until an incident proves otherwise.
- Budget conversations are adversarial by default: reporting line and budget ownership are split more often than the org chart implies[1][2].
- External reviews land on his desk with little runway: a PwC/KPMG portfolio-rationalisation or cost-optimisation engagement is built to demand current inventory, overlapping capabilities, unused functions, and total cost of ownership (TCO) — a picture he cannot produce from a spreadsheet. See the Problem Statement.
- A note on tenure: CISO tenure and turnover pressure are widely cited — commonly 18–26 months[3], well under general C-suite tenure. But the 2026 IANS/Artico survey of 662 CISOs reported an average self-reported total tenure of nine years[4] — a very different number, almost certainly because it measures cumulative time across employers rather than time in the current seat. Use the pressure ("job security is genuinely precarious, burnout is real, turnover is high") rather than a specific tenure figure — the underlying stat is contested.
Relationships
- Harry the Head of Cyber: primary trusted delegate. Simon expects Harry to already know the answer and bring a recommendation, not a question.
- Sasha the Security Architect: almost no direct contact. Occasionally sees her name on incident reports or consolidation wins.
- Paige the Procurement Officer: transactional, mediated through Harry — Simon signs off, doesn't negotiate.
Empathy Mapping
Says
| "Can you get me this on one page." |
| "What's our exposure if we cut this?" |
| "Show me where the dollars map to risk." |
| "I need something defensible, not a guess." |
Does
| Signs off budget, doesn't build it |
| Attends board/audit committee, rarely the tooling reviews |
| Delegates verification entirely to Harry |
| Engages only at decision points |
Thinks
| "I don't actually know what's true on the ground, and that scares me a bit." |
| "If this breaks, it's my name in the post-mortem." |
| "Every renewal is a fight I don't have the ammunition for yet." |
| "I need my people to make me look right in that room." |
Feels
| Exposed — accountable for things he can't personally verify |
| Time-poor and defensive by necessity |
| Relief when someone hands him a clean, evidenced answer |
| Skeptical of vendor claims, tired of "trust me" |
Design & marketing angle
Simon is nearly unreachable directly and doesn't want a demo — he wants a one-pager Harry can hand him before the board meeting or the consultancy readout.
Marketing to Simon is really marketing through Harry: case studies about defensibility, board-ready framework mapping, and dollar-figure overlap findings that make him look good in the room, not tools he'll personally log into. The purchase is a necessity when he cannot otherwise survive that room; see the Problem Statement.
Sources
- [1] Ponemon Institute (2017) — CISO reporting lines (50% CIO, 4% CEO)
- [2] ECSO CISO Community, Cybersecurity Budgets: Ownership, Reporting, Trends (2025) — 45% independent of the CIO
- [3] Cybersecurity Ventures — CISO tenure commonly 18–26 months
- [4] IANS Research / Artico Search, 2026 State of the CISO — nine-year average self-reported tenure (n=662)
Tools
Recommended tooling we use in the Engineering organisation, and if required, how to go about requesting licenses.
Head of Cyber - Harry
The head of cyber, or Chief Security Architect, is the head of the security team and the security architects. They are responsible for the security tooling portfolio and often the key decision maker for security investments.

