Skip to content
Log inRegister

The CISO Reporting Line: Why Where Security Sits in the Org Chart Matters

Dr. Abeer Alshammari · Published 7/29/2026

AdvancedExecutivesCISOs

Where a CISO sits in the org chart is treated as an administrative detail more often than it should be. It is a governance decision with direct consequences for what risks actually get surfaced, funded, and acted on.

Governance functions are not operational functions

Dr. Abeer Alshammari's research on cybersecurity role structuring draws a specific distinction between cybersecurity governance functions, executive accountability, policy direction, risk ownership, and cybersecurity operational functions, SOC operations, identity and access management, vulnerability management, DevSecOps, incident response. Both are essential. They are not the same job, and collapsing them into one reporting line tends to let the operational function's priorities quietly set the governance agenda.

What changes when the CISO reports through IT

When security reports to the CIO, budget requests compete directly against infrastructure and delivery priorities inside the same function, and risk framing gets filtered through a lens optimized for keeping systems running rather than surfacing what's uncomfortable. This is not a claim about individual CIOs acting in bad faith. It's a structural incentive problem: the person the CISO reports to is also the person most exposed if a security finding implicates how IT has been run.

What a governance-oriented structure looks like

  • A reporting line to the CEO, COO, chief risk officer, or directly to the board/audit committee, not exclusively through the CIO.
  • A defined path for the CISO to escalate a disagreement with IT leadership without that disagreement being filtered before it reaches decision-makers.
  • Budget and headcount decisions for security made independently of IT's own budget cycle, so security priorities aren't simply whatever's left over.

Scaling by organizational size and criticality

This research explicitly frames role structuring as something that should scale with organizational size, sector, and operational criticality, not a single fixed template. A small organization may not have the headcount for a fully independent security function, but even there, the governance/operational distinction should shape how limited resources are structured and how risk gets escalated, rather than being abandoned entirely for convenience.

The reporting line question is rarely framed as a governance decision because it looks like an HR chart detail. It is one of the highest-leverage governance decisions an organization makes about cyber risk.

Sources

  1. [1]Defining Cybersecurity Roles and Responsibilities Across Organizational Size and Criticality: A Governance-Oriented Framework for Public and Private SectorsZenodo (preprint) (2/7/2026)Accessed 7/29/2026

Try it yourself

An interactive CyberAbeer experience for this topic is in development.

Coming soon

Related reading

Back to insights