Ciberseguridadlatam CISO Role Faces Identity Crisis Amid Expanding Responsibilities
Article Content
- •79% of CISOs report increased complexity in their roles.
- •Two-thirds of CISOs still report to IT, indicating structural disconnect.
- •96% of CISOs now manage AI risk without a redesign of their roles.
The Chief Information Security Officer (CISO) role is undergoing a significant transformation as organizations increasingly require leaders who can manage complex cybersecurity challenges. According to the 2026 State of the CISO report, 79% of CISOs report that their responsibilities have become more complex, encompassing data privacy, regulatory compliance, third-party cyber risk, and AI governance. Despite this, two-thirds of CISOs still report directly to IT, indicating a disconnect in organizational structure. Todd Fitzgerald, an ex-CISO, notes that many organizations have yet to recognize the strategic importance of the CISO role. The report also highlights that 96% of CISOs are now responsible for AI risk management without a corresponding redesign of their authority or resources. This evolution reflects the growing need for CISOs to act as business leaders while still managing technical and operational responsibilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
What are the main responsibilities of a CISO now?
Why do two-thirds of CISOs report to IT?
How has the role of CISO evolved over time?
Continue Reading
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…