Splitting Up the CISO Role

Itwerx is a service-disabled veteran-owned managed IT and cybersecurity provider serving Seattle-area businesses, founded in 2005, and the question of who should actually own security responsibility inside a growing company comes up in almost every engagement past a certain size.

The job description for a good CISO is often, unofficially, a blend of two very different temperaments: someone with the patience for policy, training and process, and someone comfortable making fast, high-stakes calls under pressure. That is a lot to ask of one hire, and it is worth asking whether concentrating the role in a single person is even the right model.

Certifications are not the differentiator people assume

As in the rest of the cybersecurity field, industry certifications do not tell you nearly as much as their prevalence on a resume suggests, and they are a genuinely difficult thing to screen for in their absence. A credential demonstrates familiarity with a syllabus. It does not demonstrate judgment under an actual incident, which is the scarcer and more important skill. Itwerx’s own team carries very few formal security certifications, which is a deliberate reflection of the same view: the certifications are not where the security judgment on this team actually comes from.

Why splitting the role works better

The more durable answer is to split the CISO’s responsibilities across the areas of the business that already exist, rather than concentrating them in one hire who is expected to be expert in all of it at once: policy and compliance sitting with operations or legal, technical response sitting with whoever runs infrastructure, and vendor and risk oversight sitting with finance or procurement, all coordinated rather than owned by a single credentialed executive. That builds security into the way the company already runs, at every level, instead of parking it in one office and hoping that office notices everything.

None of this argues against having someone accountable for security outcomes. It argues against assuming that accountability requires one person who holds every relevant credential, when what it actually requires is a set of people, distributed across the organization, who are each responsible for the piece closest to them.

Itwerx Corp is a service-disabled veteran-owned small business providing IT services across Seattle, Bellevue, Everett and Snohomish County. This is the kind of thing our cybersecurity work deals with – talk to us about yours.