Agentic Classroom

Who Owns Cybersecurity Across the CISO, CIO, CTO, CFO and CHRO

Cybersecurity ownership splits across five roles: the CISO runs the program, the CIO owns the infrastructure, the CTO owns the product, the CFO owns the budget, and the CHRO controls access. Here is where each boundary sits.

Cybersecurity Ownership Splits Across Five Different Company Roles

No single executive owns cybersecurity end to end. The CISO (chief information security officer) runs the security program day to day. The CIO owns the infrastructure that program runs on. The CTO owns security inside the product being built. The CFO owns the budget and breach-cost tradeoffs. The CHRO controls the human access points nobody else can touch.

Takeaways

  • The CISO owns the security program, but a 2025 survey covered by Cybersecurity Dive found only 5% of CISOs report directly to the CEO, meaning most report to the CIO whose decisions they are supposed to check.
  • Deloitte’s fourth-quarter 2025 CFO Signals survey found 58% of finance leaders expect their cybersecurity budget to grow over the next 12 to 24 months, so CFO sign-off decides which controls get built in practice.
  • A 2024 Intermedia survey reported by The Hacker News found 89% of former employees kept access to at least one corporate app after leaving, which makes offboarding a CHRO and IT problem more than a CISO one.
  • The SEC’s 2023 disclosure rule gives companies four business days to disclose a material breach after determining it is material, and that materiality call is made jointly by legal counsel and the CFO, with the CISO providing input.
  • Companies without a dedicated CISO still have someone covering each responsibility, usually the CTO or CIO by default, so it helps to name who is responsible for each piece before an incident forces the question.
Global breach cost $4.44M average (IBM, 2025)
CISO-to-CEO reporting 5% (Cybersecurity Dive, 2025)
Insider risk cost $17.4M average annual (Ponemon, 2025)
SEC disclosure window 4 business days after materiality

Who owns cybersecurity, in one table

No framework assigns cybersecurity to a single job title, which is why the same breach gets blamed on three different departments once the lawyers get involved. The table below shows what each role owns, and where the boundary blurs in practice. Treat it as a starting map, not a fixed policy. Your own org chart and your regulator will move some of these lines.

Responsibility area Primary owner Who else touches it Where it gets fuzzy
Security strategy and risk appetite CISO CEO, CIO, CTO Without a CISO, this defaults to the CIO or CTO
Security budget CFO approves, CISO proposes CIO Fuzzy when spend is buried inside the general IT budget
Cloud and network infrastructure security CIO CISO Who sets policy versus who executes patches
Product and application security CTO CISO Fuzzy at startups where the CTO absorbs the CISO role
Security awareness training CHRO enforces, CISO builds content Managers Who owns the metrics reported to the board
Incident response and containment CISO CIO, legal Who decides the incident is material enough to disclose
Access provisioning and offboarding CHRO triggers, IT executes CISO HR often doesn’t notify IT fast enough
Board and regulator reporting CISO presents, CEO and CFO sign off Legal Materiality judgment under the SEC’s four-day clock

What does the CISO own?

The CISO, or chief information security officer, owns the security program itself: the strategy, the incident response plan, the tooling and vendor choices, and the metrics that eventually reach the board. The NIST Cybersecurity Framework 2.0’s Govern function assigns this role responsibility for turning risk appetite into policy and naming who answers for what. In practice, the CISO’s authority depends heavily on who they report to. A CISO who reports to the CIO ends up grading the infrastructure decisions their own boss made, a structural conflict rather than a personality problem. A 2025 survey covered by Cybersecurity Dive found only 5% of CISOs report directly to the CEO, and Gartner’s peer research found 74% of CISOs reporting to a CIO would rather report to the board instead. The 2025 ISC2 Cybersecurity Workforce Study found 59% of security leaders cite critical or significant skills gaps on their teams, one reason the CISO role increasingly depends on other executives to cover ground the team can’t.

Where do CIO and CISO overlap?

The CIO, or chief information officer, owns the infrastructure that security runs on: the networks, the cloud environment, the servers and the identity systems. The CISO sets the security policy that infrastructure has to meet. The overlap shows up constantly in patch management and access control, where the CIO’s team executes changes the CISO’s team designed. IBM’s 2025 Cost of a Data Breach Report found the global average breach cost was $4.44 million as of 2025, while breaches in the United States averaged $10.22 million, and organizations took a mean of 241 days to identify and contain a breach. Slow patching inside CIO-owned infrastructure is one of the most common reasons that window stays open so long. When a company has no CISO, this responsibility usually becomes the CIO’s by default, workable until the CIO is asked to review their own security decisions.

Does the CTO own product security?

The CTO, or chief technology officer, owns security built into the product itself: how the codebase handles authentication and how customer data gets stored. It also covers how fast a vulnerability in a shipped feature gets patched once someone finds it. This overlaps with the CISO whenever a product vulnerability turns into a company-wide incident instead of an engineering ticket. At startups without a CISO, the CTO usually absorbs the role by default, which works while the company is small and breaks down once the company handles regulated data or gets a security questionnaire from an enterprise buyer. The pressure has grown as engineering teams ship AI-generated code faster than review processes can keep pace, a change covered in AI Agents Got Cheaper This Week, Not Safer. A CTO who owns speed and a CISO who owns risk are supposed to disagree. That friction is the system working as intended.

Why is the CFO involved?

The CFO, or chief financial officer, owns the budget for security spend and carries the financial consequence when a breach happens. Deloitte’s fourth-quarter 2025 CFO Signals survey found 58% of finance leaders expect their cybersecurity budget to grow over the next 12 to 24 months. A related Deloitte-linked report found 71% of audit committees now discuss cybersecurity at least quarterly. PwC’s 29th Global CEO Survey, published in 2026, found 31% of CEOs now name cyber risk a major threat, up from 24% the year before, with 84% planning to strengthen enterprise-wide cybersecurity as part of their response. The CFO doesn’t set security policy. They decide which of the CISO’s proposed controls get funded, making the CFO a de facto gatekeeper on how much risk the company accepts.

What can only the CHRO fix?

The CHRO, or chief human resources officer, controls two things no other executive can touch directly: who gets access on their first day, and whose access gets cut on their last. Ponemon’s 2025 Cost of Insider Risks report put the average annual cost of managing insider risk at $17.4 million, up from $16.2 million in 2023, with 55% of incidents traced to employee negligence rather than malice. A 2024 Intermedia survey reported by The Hacker News found 89% of former employees kept access to at least one corporate application after leaving. That gap sits between HR, which knows someone is leaving, and IT, which has to act on it. The CHRO also owns the culture around security training, not just the completion numbers, which is why board-level phishing click rates explain less than most boards assume, a point covered in Why Your Phishing Click Rate Tells The Board Nothing Useful and in How To Spot An AI-Written Phishing Email Before You Click.

Five ownership gaps, ranked by cost

Verizon’s 2025 Data Breach Investigations Report found the human element factored into roughly 60% of breaches, and most fixes for that live outside the CISO’s direct authority. These five places are where ownership breaks down most, ranked by the cost evidence behind each one.

  1. Offboarding access nobody revokes. With 89% of former employees keeping access to at least one app after leaving, this is the cheapest gap to close and the most commonly ignored, especially during layoffs when Security Magazine has reported revocation gets rushed or skipped.
  2. Insider risk with no clear owner. Ponemon’s $17.4 million average annual cost depends mostly on CHRO and manager behavior, not on anything the CISO’s team controls directly.
  3. Security spend buried inside the IT budget. When the CFO can’t see security as its own line item, a budget increase is hard to direct with precision, however large the total grows.
  4. Product shipped without a security review. A CTO under deadline pressure and a CISO without veto power is a recurring failure pattern, sharper now that AI-assisted coding shortens the build cycle.
  5. A CISO who reports to the person they audit. With most CISOs still sitting under the CIO, the structure itself creates tension, independent of how well either person does their job.

Who reports to the board?

The CISO usually presents incident detail to the board, but the CEO and CFO carry the legal and financial accountability for what gets disclosed. The SEC’s 2023 cybersecurity disclosure rule requires public companies to disclose a material incident within four business days of determining it is material, not four days from when the incident happened. Determining materiality is a legal call made by legal counsel and the CFO together, with the CISO providing technical input, which is why that determination can take weeks even though the disclosure clock itself is short. The World Economic Forum’s Global Cybersecurity Outlook 2026 found cyber risk has moved onto the CEO’s own list of priorities rather than staying delegated, drawing more of this reporting chain toward the CEO’s desk.

What changes without a CISO?

Most small and mid-size companies operate without a dedicated CISO. Someone is still doing each of these jobs, the title is just missing from the org chart. Security strategy usually falls to the CIO or CTO by default, security budget decisions fall to the CFO, and access control falls to whoever runs HR and IT operations. Frameworks like NIST CSF 2.0 and ISO/IEC 27001 are written to work either way, assigning governance and accountability to whichever role is doing it in that company, rather than assuming a CISO exists. An unwritten ownership gap causes more damage than a missing job title ever does. The first time anyone discovers the gap is during an incident, the worst possible moment to work out who was supposed to own what.

Prompts you can use

Paste these straight in. Change the parts in square brackets and nothing else.

Map your team’s security ownership
You are a cybersecurity governance advisor helping me build a RACI matrix (who is Responsible, Accountable, Consulted, Informed) for security ownership at my company. Ask me first: our company size, whether we have a dedicated CISO, and our current org chart for CIO, CTO, CFO and CHRO (or equivalents). Then produce a table with these responsibility areas as rows: security strategy, security budget, infrastructure security, product and application security, security awareness training, incident response, access provisioning and offboarding, and board and regulator reporting. For each row, assign Responsible, Accountable, Consulted and Informed to specific roles based on what I tell you, and flag any area where two roles both claim Accountable, since that's the gap that causes incidents. Do not assume a CISO exists unless I confirm one does.

This drafts a starting matrix, not a governance policy. Have legal or a security consultant review it before treating it as official.

Prep a board-ready incident brief
Act as a CISO advisor helping me prepare a board briefing on a security incident. Ask me first for: what happened, when we discovered it, what data or systems were affected, and where we are in determining materiality. Then draft a briefing structured as: what happened in plain language, what we know versus what's still being investigated, the current materiality assessment status, what's being done right now, and the timeline for next updates. Keep it under 400 words, avoid technical jargon the board won't understand, and do not draft any language stating materiality has been determined unless I explicitly tell you it has. Ask clarifying questions before writing if any of this is unclear.

This is a communication draft only. The materiality determination itself must come from legal counsel, not from this output.

Audit your offboarding gaps
You are a security auditor helping me find gaps in how my company revokes access when someone leaves. Ask me first how offboarding currently works: who initiates it, what triggers it, and what systems get checked. Then walk through a checklist covering SaaS applications, email and calendar, VPN and remote access, shared drives, code repositories, and any admin or privileged accounts. For each item, ask whether it's currently covered, and flag anything that depends on a manual step or a single person remembering to do it, since that's where access tends to get left open. Summarize the three biggest gaps at the end.

This produces a working checklist based on what you tell it, not a security audit. Verify any high-risk gaps it flags with your actual IT team.

Questions people actually ask

Does the CISO report to the CIO or the CEO?

Most CISOs still report to the CIO, though a 2025 survey covered by Cybersecurity Dive found only 5% report directly to the CEO. Reporting to the CIO can create a conflict, since the CISO ends up grading the infrastructure decisions their own boss made.

Who is responsible for a data breach, the CISO or the CEO?

The CISO usually owns the technical response, but the CEO and board carry the legal and financial accountability. Under the SEC’s 2023 disclosure rule, the company must disclose a material breach within four business days of determining it is material.

Does a small company need a CISO?

Not necessarily. Many small and mid-size companies never hire a dedicated CISO, and the role’s responsibilities get absorbed by the CTO or CIO instead. Frameworks like NIST CSF 2.0 are built to assign accountability to whichever role is doing the job, regardless of title.

Who owns security awareness training, IT or HR?

Usually both. The CISO’s team typically builds the training content and tracks metrics like phishing click rates, while the CHRO enforces completion and owns the broader security culture. Neither owns it alone, which is why training programs stall when the two don’t coordinate.

Who decides if a data breach has to be publicly disclosed?

Materiality is a legal determination made by legal counsel and the CFO together, with the CISO providing technical detail, then reported to the CEO and board. The SEC’s rule sets the disclosure clock at four business days after that determination, not four days after the incident itself.

Sources

  1. NIST Cybersecurity Framework 2.0’snist.gov
  2. Cybersecurity Divecybersecuritydive.com
  3. Gartner’s peer researchgartner.com
  4. 2025 ISC2 Cybersecurity Workforce Studyisc2.org
  5. IBM’s 2025 Cost of a Data Breach Reportibm.com
  6. Deloitte’s fourth-quarter 2025 CFO Signals surveydeloitte.com
  7. Deloitte-linked reportcfo.com
  8. PwC’s 29th Global CEO Surveypwc.com
  9. Ponemon’s 2025 Cost of Insider Risks reportponemon.org
  10. The Hacker Newsthehackernews.com
  11. Verizon’s 2025 Data Breach Investigations Reportverizon.com
  12. Security Magazine has reportedsecuritymagazine.com
  13. SEC’s 2023 cybersecurity disclosure rulemofo.com
  14. World Economic Forum’s Global Cybersecurity Outlook 2026weforum.org
  15. ISO/IEC 27001iso.org

What happens next

Expect more CISOs to push for reporting lines that sit outside the CIO, following the direction Gartner’s own peer research already points toward. Watch how boards respond as more companies test the SEC’s four-business-day disclosure clock in public, and whether CFOs start tracking security spend as its own budget line instead of folding it into general IT costs.

Take this further

Full resume rewrite, section by sectionBest on Claude
Act as a blunt hiring manager who has read ten thousand resumes, not a career coach. I will paste my full resume and the job description I want. Rewrite the whole resume for that role, section by section, in this order: summary, experience, skills, education. Rules: every experience line leads with impact, not duty. Use bracketed placeholders like [8 percent] for any number I did not give you, and list at the end every placeholder I need to replace with a real figure. Keep it to one page of text. Plain formatting only, no tables or columns, so screening software can parse it. After the rewrite, tell me the three weakest claims that need evidence before I send this anywhere. My resume: [paste resume]. The role: [paste job description].
Share this
About the author
Vinayak Kapoor
Vinayak Kapoor

Vinayak started at seventeen on a call centre floor and climbed every rung himself over fifteen years: millions of customer conversations for some of the world's largest brands, self-taught design, video and web work, a profitable e-commerce brand of his own, and now human cyber risk, where he has built customer success journeys for national critical infrastructure and leads business growth at HumanFirewall. Nobody groomed him. He learned every skill alone, including the AI he now builds with daily as founder of Quarry, MaaSify and HuMatrix. He writes here so your career gets the guide his never had.

Read next
Come find me

The daily thinking
lives on the feeds.

Long form here. The working notes, the arguments and the things that did not fit go out most days.

← All writing