Katie Jenkins, EVP and CISO, Liberty Mutual Insurance
Liberty Mutual InsuranceThe field is changing so rapidly, Jenkins adds, she needs to commit time to keeping up on research and connecting with other CISOs for knowledge exchange.In addition to securing infrastructure, an effective CISO focuses on securing the business, experts say. This requires understanding how security fits into the business; not just concentrating on risk management, but ensuring security helps the company move forward without creating other problems.Instead of viewing them as “tech enforcers,” it’s time to view CISOs as strategic business leaders, industry experts say. 2. Security is purely a technical function: Similarly, you can have the best tools and the best security stack in the world, but if your employees are still clicking phishing links or reusing weak passwords, that all falls by the wayside. The CISO role is evolving and today they must wear many hats, serving as psychologists, educators, and diplomats, in order to convince people that security is everyone’s job.This is because often, no one thinks much about security, until there is an issue. Additionally, leadership may not view security as part of the corporate culture. Experts say a strong CISO spends as much time working with people as they do with tools.”I’ve lost count of how many times someone assumed my day revolves around configuring firewalls or patching vulnerabilities,” says Sam Taylor, CISO of security resources firm LLC.org, adding that she runs into this all the time.”In reality, about 70% of my job is risk management, communication, and making sure security gets taken seriously at the executive level. I spend more time in boardrooms than I do in security operations centers,” she says. “Leadership teams don’t care about technical jargon; they care about risk in financial terms.”

5. CISOs can eliminate risk: There is an unrealistic expectation that a security leader should be able to stop every breach before it happens. Breaches will happen. Their real job, security experts say, is minimizing impact, keeping systems resilient, and ensuring the company bounces back fast afterwards.”People often believe CISOs can stop all attacks, but this could not be farther from the truth,” says Rafay Baloch, CEO and founder of cybersecurity consultancy RedSecLabs. “Breaches happen based on timing rather than likelihood, which challenges this perspective.”This stems from a big misconception that “cybersecurity is only done by people with a cybersecurity job title, when in fact, an entire organization serves as the first line of defense,” says Liberty Mutual’s Jenkins. “It takes every employee to ‘don their cape.’” Liberty Mutual’s Responsible Defender program requires the company’s 40,000 global employees “to use their training and instincts to help us identify and defend our company against cyberattacks,” she says.
6. CISOs are a barrier to innovation: Business leaders often view security as a roadblock and believe CISOs slow innovation with extreme risk assessments and compliance requirements. On the other hand, many CISOs maintain they actually help their businesses move faster by ensuring innovation happens securely.Security should be viewed as a company-wide function that requires buy-in from every department and CISOs not be treated as the lone defenders against cyber threats.Security leaders can often be perceived as slowing down innovation, according to Allen. Startups, for example, may resist security controls that introduce friction in user experience, while media companies may push back on digital rights management (DRM) enforcement because it complicates content distribution, he says.”A colleague of mine at a global streaming platform explained how they struggled to implement stronger API security because it was seen as an ‘unnecessary delay’ to feature releases, until API vulnerabilities were exploited, impacting millions of users,” Allen says. “In reality, CISOs are not anti-innovation; they are there to ensure sustainable growth by embedding security into digital transformation efforts rather than bolting it on later.”In many industries, CISOs must balance risk with business agility, regulatory demands with user experience, and cybersecurity with corporate innovation goals, Allen says. “Their role extends beyond technical oversight, they must be strategic partners who bridge the gap between security, product development, and business operations.”
7. CISOs don’t have mental health issues: There is a mistaken impression that CISOs can handle the stress of the job. Even though organizations are under attack 24/7/365, the thought is that by the time you get to the level of CISO you don’t have to worry about your mental health, Touhill says, calling this “a vicious myth.”He strongly encourages CISOs to not only have a plan in place to take care of the mental health of their security teams, but also have a “really, really good deputy ready to step in so you can take a vacation.” He adds, “You cannot win a marathon if it never ends. You have to take care of yourself and be constantly aware of your own mental health, not just the people you’re taking care of and leading.”
First seen on csoonline.com
Jump to article: www.csoonline.com/article/3846288/7-misconceptions-about-the-ciso-role.html