adacom loader
Please Wait
Articles

The Modern Role of the CISO 

The Modern Role of the CISO  main image

By Panagiota Lagou, GRC Director of ADACOM, Published in IT Security Pro no95

The Modern Role of the CISO 

The role of the Chief Information Security Officer (CISO) has evolved significantly in recent years, in line with the rapid increase in cyber threats and the growing complexity of modern organizations. 

There are many challenges that CISOs must address. New technologies and the constantly evolving threat landscape create an environment of significant complexity, as they increase both the attack surface and the speed at which risks evolve. Technologies such as cloud computing, artificial intelligence, the Internet of Things (IoT), and mobile infrastructures provide greater flexibility and business value, while at the same time introducing new vulnerabilities and making it more difficult to maintain full control over systems. 

One of the main challenges is the loss of visibility. In distributed environments, data and applications are no longer located in a single central location, making them more difficult to monitor and protect. At the same time, the adoption of third-party services and cloud providers shifts part of the security responsibility, requiring the CISO to manage complex shared responsibility models. 

The threat landscape is also evolving rapidly, with ransomware attacks, highly targeted phishing campaigns, and the use of artificial intelligence techniques by attackers. Attacks are becoming more automated, faster, and more difficult to detect, reducing the time organizations have to respond. 
As a result, the need for continuous adaptation—strategic, technological, and organizational—has emerged as a major challenge in an environment where threats and technologies evolve faster than ever before. 

To address these modern challenges, the CISO can no longer rely solely on a strong technical cybersecurity background. While technical expertise remains essential, the role has evolved into a multidimensional leadership position that requires a combination of technological, business, and communication skills. Today, the CISO acts as a "translator/interpreter" between different worlds: technology, executive management, business functions, and the regulatory environment. 

One of the most critical new requirements is the ability to understand and interpret legal and regulatory obligations. Regulatory frameworks such as the GDPR, the NIS2 Directive, as well as national or sector-specific compliance requirements, are no longer considered solely the responsibility of the legal department; they have become a fundamental aspect of strategic risk management. The CISO must be able to understand these requirements and translate them into practical security measures, policies, and technological implementations. 

At the same time, communication skills have become a key success factor. The CISO must be able to explain complex cyber risks in a way that is understandable to executive management and the Board of Directors, enabling informed decisions regarding investments and acceptable levels of risk. 

In addition, the CISO must act as a coordinator among different business functions, including the IT department, the legal department, regulatory compliance, human resources, and business units. Each function has different needs and priorities, and the CISO is responsible for bringing them together within a cohesive security framework that supports both business continuity and innovation. 

These skills are not required only of the CISO but should also be shared and embedded throughout the information security team. The effectiveness of a modern cybersecurity function does not depend on a single executive but on a team that can collectively combine technical expertise, an understanding of regulatory requirements, and the ability to communicate effectively with the rest of the organization. 

Naturally, the role of the CISO cannot be separated from the technical dimension of cybersecurity. The ability to understand and interpret technological infrastructures, systems, and security mechanisms is essential for translating regulatory and business requirements into concrete technical implementations. 

In practice, this means that the CISO must have a thorough understanding of technologies such as cloud computing, artificial intelligence, networking systems, encryption, identity and access management, as well as modern security architectures such as Zero Trust. This technical expertise enables the CISO to assess whether the requirements arising from regulations or business needs can be implemented effectively and securely within the existing environment. 

Furthermore, technical knowledge enables the CISO to make better-informed decisions regarding the selection of security tools, security architecture, and risk mitigation. Without this foundation, a strategic approach risks remaining theoretical and failing to address the real challenges of the digital environment. Technical expertise therefore complements managerial and communication skills, strengthening the overall effectiveness of the role. 

A key element in the implementation of technological and organizational measures is third-party risk management, particularly due to the increasing dependence of modern organizations on third parties and the growing supply chain risk. The CISO systematically assesses partners based on cybersecurity criteria and establishes clear terms of cooperation through contracts that include security requirements, compliance clauses, and control mechanisms. 

Taking all of the above into account, the role of the CISO is evolving from a purely technical position into a strategic and cross-functional one. Today's successful CISO is not only a cybersecurity expert but also a communication leader, a manager of regulatory complexity, and a bridge between technology and business strategy. 

Read also the full article in Greek here: IT Professional Security - ΤΕΥΧΟΣ 95