In a recent report by IANS Research, nearly 800 Chief Information Security Officers, or CISOs, revealed that their roles have expanded significantly beyond traditional cybersecurity duties to include broader business responsibilities. Despite this increase in workload, only three percent reported salary raises linked to these additional responsibilities. The research indicates that the average annual cash compensation for strategic CISOs, who interact regularly with CEOs and boards, is around five hundred forty-five thousand dollars, while functional and tactical CISOs earn approximately three hundred eighty-five thousand and two hundred ninety-one thousand dollars, respectively. Notably, those who oversee both security and IT functions, termed dual CISOs, can earn up to one million dollars, highlighting the higher compensation linked to broader oversight.
CISOs are increasingly gaining influence within boardrooms, according to new research from Splunk. The study reveals that over eighty percent of CISOs now report directly to the CEO, a significant rise from forty-seven percent in 2023. Additionally, eighty-three percent of CISOs participate in board meetings frequently. Despite this growing presence, only twenty-nine percent of boards include a member with cybersecurity expertise, even though sixty percent of CISOs acknowledge that such members wield greater influence over security decisions. The research highlights that board members with security backgrounds foster stronger relationships with security teams, leading to more effective communication and strategic alignment on cybersecurity goals. However, there remains a disconnect, as only fifteen percent of CISOs prioritize compliance status, in stark contrast to forty-five percent of board members. This misalignment in priorities and budgetary support may pose challenges as CISOs navigate an increasingly complex regulatory landscape.
The evolving role of the CISO represents both an opportunity and a challenge. While increased boardroom visibility reflects the growing importance of cybersecurity, compensation inequities and misaligned priorities risk undermining progress. For IT providers and MSPs, this moment represents a chance to partner with CISOs and boards to address gaps in strategy, compliance, and alignment, or be that role in a virtual sense for customers that are not large enough to separate that out.

