I wrote a short post last week about the CISO role being accountable for everything and in control of almost nothing. It got more attention than I expected, and the comments were better than the post.
The most common response was some version of “CISOs aren’t powerless.” I want to start there, because it’s fair.
The part that’s on us
Plenty of security leaders walk into a budget conversation with a list of control gaps and a vulnerability count. That’s a status report with an implied ask attached, not a business decision.
The people who get funded are the ones who show up with a decision: here is the exposure, here are two or three ways to reduce it, here’s what each costs, here’s what we accept if we do nothing. Then they let the business choose.
That’s a real skill and a lot of us are mediocre at it. If you’re waiting for authority to be handed to you because you’re technically correct, you will wait a long time.
So yes. Some of this is ours to fix.
Where that stops working
Influence and authority are not the same thing. That’s what the “earn your influence” argument misses.
Influence gets you into the room and gets you heard. It gets your risk framing taken seriously by people who could have ignored it.
What it doesn’t get you is sign-off on a vendor contract, or a risk acceptance with someone else’s name on it. And it doesn’t stop a business unit from buying a platform in November that you find out about in March.
I have watched security leaders who were genuinely excellent at business framing get overruled on procurement anyway. Not because they explained it badly. Because nothing in writing said they had a vote.
Earned influence and written authority are two different things, and organizations that give you the first one often use it as a reason not to give you the second.
The org chart is not the fix
The conversation always turns to reporting lines. Should the CISO report to the CEO. To the board. Not to the CIO. There’s a whole cottage industry of opinions on this.
Over the course of my career I’ve reported through IT, through legal, through operations, through compliance. Different box, same job, same accountability. Nothing structural changed based on which line I was drawn to.
What changed things was something else entirely: whether the reporting path ran through the person whose budget I was challenging.
That’s the actual variable. If security escalates through the executive whose project you’re trying to slow down, the escalation dies at that desk. It doesn’t matter what the title is. The conflict is baked into the path.
The second conflict, which is worse
There’s a version of this that shows up constantly in the mid-market, and it’s more dangerous because it looks responsible.
The CISO owns governance. So the CISO writes the policy, builds the control, operates the control, and then signs the assessment saying the control works.
That’s not a second line of defense. That’s one person grading their own homework and filing the report with the regulator.
The reason nobody catches it is that it never looks like a conflict when things are going well. It looks like efficiency. Who better to assess the controls than the person who built them? They know the environment. They know where the gaps are. Consolidating it saves money and headcount.
The conflict only surfaces the first time the honest answer is expensive. And by then, the structure that would have protected the assessment doesn’t exist.
But we’re not big enough to separate everything
This is the objection I get from every community bank and mid-market fintech I work with, and it’s legitimate. A $2B bank is not staffing an independent risk function for cyber. There is no second line to move the work to. Knowing what good looks like doesn’t conjure headcount.
Someone in the comments pointed me to a regulation I didn’t know, and it handles this better than anything in financial services.
EASA Part-IS is the EU’s information security regulation for aviation. The personnel clause puts both the authority and the responsibility on a named Accountable Manager. Same clause. Same person. And delegating the work to a competent appointee does not delegate the accountability. That stays put.
The part I found most useful is the proportionality guidance. It says outright that multiple responsibilities may be assigned to one person, as long as the independence of the compliance monitoring is preserved.
That’s a regulator acknowledging that small shops cannot separate every line, and then protecting the one separation that actually matters.
It doesn’t transplant cleanly. Aviation has a competent authority that reviews and accepts nominated persons, and banking examiners don’t do that for cyber. But the principle holds: you don’t need every line separated. You need the assessment independent from the thing being assessed. Everything else can stack.
What to actually put in writing
If you’re hiring a CISO, or you’re a CISO negotiating one, this is the short list. It’s shorter than people expect.
Sign-off on third-party contracts that touch regulated data. Not consultation. Not a seat at the table. Signature or documented objection.
A risk acceptance process where the business owner signs their own name. If security is the only signature on the form, security owns the outcome.
A reporting path that doesn’t run through the budget being challenged. Wherever the role sits, the escalation route has to bypass the person with the conflict.
Independent assessment. Whoever signs the assessment cannot be the person who built and runs the control. In a small shop this might mean an outside party once a year. That’s fine. It just can’t be the same signature.
A standing board slot. This is the cheapest one and the most overlooked. It’s separable from the reporting line and it’s a far easier yes than a new executive pillar. Fifteen minutes, unfiltered, on the calendar.
D&O coverage and an indemnification agreement, in writing. Most security leaders assume they’re covered because the executives are covered. Read the policy’s definition of “officer” and find out whether it includes you, because it frequently doesn’t. The indemnification should advance defense costs as they’re incurred rather than reimburse you afterward, and it has to survive your departure. The claim usually shows up after you’re gone.
None of that requires a reorg. Most of it fits in an offer letter or an engagement scope.
The version nobody says out loud
Formal accountability sits with the board. Actual consequence lands on the CISO. The authority to prevent the incident sits with whoever owns the budget.
That’s three things in three places, and every incident happens in the space between them.
A well-maintained risk register looks like a program working. Often it’s a record of everything the security leader couldn’t get funded, written by the person who will be gone ninety days after it matters.
Documentation protects you from being wrong. It does not protect you from being blamed. Those are different problems, and the second one is why the indemnification matters.
Fix the authority, or stop being surprised by the tenure numbers.
If you’re building a security program in a regulated environment and want to talk through what this looks like on paper, book a call.


