Cybersecurity officers moving up the organizational chart

Who information security professionals report to can impact investment and response.
FEB 14, 2018

Cybersecurity has moved out of the server room and into the board room. The chief information security officers at financial institutions are increasingly being thrust into the organizational spotlight as concerns with data security grow, according to a new report by the Financial Services Information Sharing and Analytics Center. The group, an organization of 7,000 chief information security officers at financial services firms, said CISOs now prioritize keeping top leadership updated on security risks and most provide boards of directors with quarterly or monthly reports. (More: This is the No. 1 cybersecurity threat to financial advisers, experts say) Most CISOs report directly to chief information officers, chief risk officers or chief operating officers and security experts say that how a CISO is placed in an organization's hierarchy impacts how firms invest in security. Greg Reber, the CEO at security consulting company AsTech, said many firms are changing this structure to avoid a conflicts in priorities. "CIOs may need to get things done quickly to realize financial goals, moving processing to the cloud environments for example — while CISOs are chiefly concerned with risk management," Mr. Reber said. Bret Fund, the founder and CEO of SecureSet, a cybersecurity academy, said CISOs who report to CIOs tend to prioritize infrastructure upgrades and breach prevention, while those who report to COOs tend to prioritize employee training. (More: Firms begin to heed cybersecurity, but have much to do) "I think that speaks to CISOs seeing first-hand how their largest risks of breach rest in the people component versus the product or process components," Mr. Fund said. "Advisers cannot underestimate the need for a robust security culture inside their organizations and the way that you achieve that is through education and training." The FS-ISAC said only 8% of CISOs report directly to firm CEOs, which could restrict information flow, decrease transparency and hamper decision making. The group recommended firms make training the top priority regardless of their organizational structure. (More: Wall Street aims to protect 401(k)s from hacking nightmare) "Advisers can no longer just 'check-the-box' when it comes to security awareness training," said Dan Lohrmann, the chief security officer at Security Mentor. "Staff must see the relevance of what they are learning, and that happens by teaching them things they don't already know. As new people, processes and technology are introduced into workflows, the corresponding actions related to the business must adjust to the increasing cyberthreats that are facing global enterprises." FS-ISAC was established in 1999 with the mission of helping the global financial services infrastructure and individual firms fight back against cybersecurity threats. Members share threat and vulnerability information, conduct coordinated contingency planning exercises, manage rapid response communications, offer education and training programs, and collaborate with government agencies.

Latest News

The 2025 InvestmentNews Awards Excellence Awardees revealed
The 2025 InvestmentNews Awards Excellence Awardees revealed

From outstanding individuals to innovative organizations, find out who made the final shortlist for top honors at the IN awards, now in its second year.

Top RIA Cresset warns of 'inevitable' recession amid tariff uncertainty
Top RIA Cresset warns of 'inevitable' recession amid tariff uncertainty

Cresset's Susie Cranston is expecting an economic recession, but says her $65 billion RIA sees "great opportunity" to keep investing in a down market.

Edward Jones joins the crowd to sell more alternative investments
Edward Jones joins the crowd to sell more alternative investments

“There’s a big pull to alternative investments right now because of volatility of the stock market,” Kevin Gannon, CEO of Robert A. Stanger & Co., said.

Record RIA M&A activity marks strong start to 2025
Record RIA M&A activity marks strong start to 2025

Sellers shift focus: It's not about succession anymore.

IB+ Data Hub offers strategic edge for U.S. wealth advisors and RIAs advising business clients
IB+ Data Hub offers strategic edge for U.S. wealth advisors and RIAs advising business clients

Platform being adopted by independent-minded advisors who see insurance as a core pillar of their business.

SPONSORED Compliance in real time: Technology's expanding role in RIA oversight

RIAs face rising regulatory pressure in 2025. Forward-looking firms are responding with embedded technology, not more paperwork.

SPONSORED Advisory firms confront crossroads amid historic wealth transfer

As inheritances are set to reshape client portfolios and next-gen heirs demand digital-first experiences, firms are retooling their wealth tech stacks and succession models in real time.