Skip to Main Content

Chief Information Security Officers

The Job

Chief information security officers work with other cyber security professionals to assess the current security infrastructure and policies at their company or organization to identify areas that need improvement. They meet with IT security vendors to learn about new products and discuss best practices. CISOs select, purchase, and oversee the installation of security software, hardware, and systems. They create and implement programs that keep data and IT systems safe, and educate executives and line-level workers about these programs. Some CISOs also oversee the physical security measures (cameras, keypads, biometric systems, etc.) that are in place to prevent unauthorized access to the facility.

When a cyberattack occurs, CISOs work with their teams to try to thwart the attack and close off any digital area that has been compromised or that serves as a point of attack. At a large company, lower-level staff typically take the lead in addressing the incident under the supervision of a CISO. If a major security breach occurs, the CISO steps in and manages the incident response.

After a cybercrime occurs, the CISO assesses the severity of the breach, determines its cause (e.g., poor security infrastructure, a mistake by an employee, deliberate misuse of data by an employee or contractor), and creates a plan to avoid the issue in the future. They act as the organization’s representative during interactions with law enforcement agencies. CISOs also write reports for top management and the board of directors that summarize the incident, who or what was responsible, and the steps that were taken to address it.

Other important duties for CISOs include staying abreast of emerging IT security concerns and educating the CEO and board members about these issues; creating or updating business continuity and disaster recovery plans; working with IT security vendors to identify security needs (as well as developing vendor management processes to mitigate information security risks); creating cybersecurity budgets; ensuring that their organization is up-to-date with evolving compliance regulations (this is especially important for global organizations that operate under regulations from multiple countries); and developing and implementing cybersecurity awareness and training programs for staff.

Related Professions
Featured Companies