Skip to Main Content

Chief Information Security Officers

History

On November 2, 1988, the first malicious software program (later called a worm) was released onto the Internet by Robert Tappan Morris, a graduate student at Cornell University. The worm caused an estimated 6,000 computers (or 10 percent of all computers connected to the Internet) to stop functioning. This marked just the first of countless cyberattacks on individuals, businesses, academic institutions, government agencies and the military, and other organizations over the next several decades. The FBI’s Internet Crime Complaint Center received a record number of Internet crime complaints from the American public in 2023—880,418 complaints, with potential losses exceeding $12.5 billion.

The position of chief information security officer dates to 1994, when the financial services company Citigroup (then Citicorp) established a specialized cybersecurity office after experiencing multiple cyberattacks from Russian hackers. Steve Katz, who was overseeing information security at the financial giant JPMorgan, was hired as CISO. He served as CISO at Citicorp for six years before moving on to executive-level cybersecurity positions at Kaiser Permanente and Deloitte and then launching his own consulting firm. Katz passed away in 2023.

Today, nearly all large corporations have CISOs or professionals working in a similar position. Many smaller companies are introducing the role to help address security weaknesses and better equip their businesses in a world where cyberattacks are a regular occurrence. Government agencies and nonprofits are also hiring CISOs.

Related Professions
Featured Companies