The CISO Reporting Line: Why Where Security Sits in the Org Chart Matters
Dr. Abeer Alshammari · Published 7/29/2026
Where a CISO sits in the org chart is treated as an administrative detail more often than it should be. It is a governance decision with direct consequences for what risks actually get surfaced, funded, and acted on.
Governance functions are not operational functions
Dr. Abeer Alshammari's research on cybersecurity role structuring draws a specific distinction between cybersecurity governance functions, executive accountability, policy direction, risk ownership, and cybersecurity operational functions, SOC operations, identity and access management, vulnerability management, DevSecOps, incident response. Both are essential. They are not the same job, and collapsing them into one reporting line tends to let the operational function's priorities quietly set the governance agenda.
What changes when the CISO reports through IT
When security reports to the CIO, budget requests compete directly against infrastructure and delivery priorities inside the same function, and risk framing gets filtered through a lens optimized for keeping systems running rather than surfacing what's uncomfortable. This is not a claim about individual CIOs acting in bad faith. It's a structural incentive problem: the person the CISO reports to is also the person most exposed if a security finding implicates how IT has been run.
What a governance-oriented structure looks like
- A reporting line to the CEO, COO, chief risk officer, or directly to the board/audit committee, not exclusively through the CIO.
- A defined path for the CISO to escalate a disagreement with IT leadership without that disagreement being filtered before it reaches decision-makers.
- Budget and headcount decisions for security made independently of IT's own budget cycle, so security priorities aren't simply whatever's left over.
Scaling by organizational size and criticality
This research explicitly frames role structuring as something that should scale with organizational size, sector, and operational criticality, not a single fixed template. A small organization may not have the headcount for a fully independent security function, but even there, the governance/operational distinction should shape how limited resources are structured and how risk gets escalated, rather than being abandoned entirely for convenience.
The reporting line question is rarely framed as a governance decision because it looks like an HR chart detail. It is one of the highest-leverage governance decisions an organization makes about cyber risk.
Sources
- [1]Defining Cybersecurity Roles and Responsibilities Across Organizational Size and Criticality: A Governance-Oriented Framework for Public and Private Sectors — Zenodo (preprint) (2/7/2026)Accessed 7/29/2026
Try it yourself
An interactive CyberAbeer experience for this topic is in development.
Coming soonRelated reading
Cybersecurity Governance vs IT Governance: Why Confusing the Two Weakens Organizational Resilience
IT governance and cybersecurity governance are often treated as the same function under a different name. They are not, and the gap between them is where major incidents start.
Third-Party Risk Management: A GRC Practitioner's Framework for Vendor Security
A vendor security questionnaire is not a risk management program. Real third-party risk management requires ongoing ownership, not a one-time checklist at signing.