Skip to content
The Cyber Security Place

Governance

The accountability arrived before the authority

The job acquired personal exposure, artificial intelligence and a standing invitation to the boardroom. It did not acquire the right to stop anything.

Last reviewed August 30, 2026

Concern about personal liability among security chiefs rose from about 56% to 78% in a single year, and some 96% now own artificial intelligence governance, usually without extra budget or people. Yet roughly 64% still report into technology and only about 11% to the chief executive. Boards are unconvinced: just 29% of directors call the updates very effective, and what fails is future risk rather than current state — unsurprisingly, since more than half of organisations have never written down how much risk they will carry. Spending is not the constraint. It stands near $248.9bn and growing 12.7%, after a year that managed only 4%, and security runs near 13.2% of technology spending. What is scarce is not funding but decision rights: who may stop a release, who accepts an exception, and for how long. Those cost nothing and take a year to obtain.

You have twenty minutes. What do you say?

8 sentences, all of them true, none of them wrong. What differs is what the room takes away and the question that follows — and only 3 of the 8 survive being asked it.

We are 94% patched across the estate.

Heard as: Six per cent of the company is unprotected, and nobody has said which six.

Next question: Which systems are in the six per cent?

A percentage of a denominator nobody has agreed on. It sounds like reassurance and invites the one question it cannot answer, because the unpatched remainder is exactly where the old and forgotten machines live.

We blocked 4.2 million attacks last quarter.

Heard as: Something enormous is happening that I cannot evaluate, and the number will be bigger next time.

Next question: Is that good?

Volume of blocked noise measures the internet, not the organisation. It cannot go down for a good reason, which makes it useless as a trend and slightly alarming as a headline.

Our maturity score rose from 2.4 to 3.1.

Heard as: A number I did not choose moved in a direction I am told is good.

Next question: What would 4.0 cost, and would we be safe then?

Maturity models are useful internally and hopeless externally. The scale has no units, no relationship to loss, and the obvious follow-up leads somewhere nobody wants to go.

If the payroll system were encrypted on a Friday, nobody gets paid until the following Thursday.

Heard as: A specific bad thing, with a duration I can picture and a decision attached.

Next question: What would shorten that, and what does it cost?

A consequence in the units the room already uses — days, people, money. It survives the follow-up because the follow-up is the conversation the speaker wanted.

Three suppliers can reach our customer data, and one of them will not tell us who their subcontractors are.

Heard as: We have a contractual problem with a named owner, not a technical one.

Next question: What happens if we insist and they refuse?

It converts a security finding into a commercial decision the board is actually equipped to take, which is the only kind it can take.

We passed the audit with no major findings.

Heard as: This is handled. Next item.

Next question: None asked.

The most dangerous sentence available, because it closes the discussion. Passing an audit describes the audit, and organisations are breached in the space between what was tested and what exists.

Our insurance would cover about a third of the loss we modelled.

Heard as: Somebody has modelled a loss, and the number is bigger than the cover.

Next question: What is the other two thirds, and are we choosing to carry it?

It states an accepted exposure out loud. Boards are constituted to decide exactly this and are rarely given the chance in this subject.

We need more headcount to keep up with the threat landscape.

Heard as: The department wants to grow, like every department.

Next question: What stops if we say no?

A request without a consequence competes with every other request without a consequence, and loses to the ones that came with a number.

The three that hold have nothing in common technically. What they share is grammar: each names a consequence in units the room already uses, and each ends somewhere a decision can be taken. The five that fail are not lies or even exaggerations. They are answers to questions nobody in that room asked, which is the most expensive habit in this discipline and the hardest to notice from inside it.

Why has liability moved faster than authority?

Two changes happened in the same decade and only one of them completed. The first was accountability: a handful of enforcement actions and prosecutions established that when an organisation misleads people about a breach, the answer to who is responsible can be an individual with a name and a job title. The number of such cases remains small. Their effect on the profession has been enormous, and the 22-point jump in a single year is what that effect looks like measured.

The second change was supposed to be authority, and it stalled. Roughly 64% of security chiefs still sit inside the technology function, reporting to the person whose objectives include delivering projects on time. That arrangement asks one executive to slow another executive's programme while depending on them for budget, headcount and an annual review. Most of the time it produces exactly what you would expect, which is a security function that raises concerns and does not stop anything.

The consequence is a role carrying personal exposure for outcomes it cannot determine. That is an unstable arrangement in any profession, and the people in it have started behaving accordingly: negotiating indemnities before accepting the job, insisting that risk acceptances are signed by whoever benefits from taking them, and keeping records in a form that survives a subsequent disagreement about what was known and when.

None of that is cynicism, and treating it as such misses what it produces. An organisation where the person who wants the deadline signs for the risk of meeting it is better governed than one where a security team objects informally and gets overruled in a corridor. The paperwork is not defensive posturing. It is the only mechanism that puts a decision in front of the person entitled to take it.

The sentence almost nobody has written

Board reporting fails in a specific and diagnosable place. Directors rate updates on the current state as adequate and updates on future risk as poor, and the usual explanation — that boards lack technical background — is comfortable and wrong. Future risk can only be reported against a threshold. More than 50% of organisations have never defined one.

Without it, every forward-looking slide becomes a list of things that might happen, each individually alarming and none of them comparable to anything. A director cannot tell whether the organisation is above or below where it intends to be, because no such intention exists to be above or below. What arrives instead is weather: a description of conditions, delivered by somebody who evidently finds them worrying, with no proposition attached.

The remedy is a paragraph and a signature, not a framework. A statement of what the organisation is prepared to lose — how long it can be unable to serve customers, how much money it will absorb without extraordinary measures, what kinds of data exposure would be considered unacceptable regardless of cost — converts the entire conversation. Reporting becomes a comparison against a line. Prioritisation becomes arithmetic. The argument about the delayed release becomes a question with an owner.

It is avoided because writing it forces an admission that some losses are acceptable, and nobody wants that sentence attributed to them. Which is precisely why it belongs at board level rather than in a security function, and why the preparation time — commonly 10 hours or more per report — is being spent in the wrong place. Assembling numbers is cheap work that feels productive. Obtaining the sentence is expensive work that removes the need for most of the numbers.

An argument being won, slowly

611 entries here concern leadership, boards, budgets or governance. 95 name the security chief, 123 the board or the executive floor, and 49 discuss budgets.

10201478201574201687201712420181272019642020352021

The pale column is the whole subject and the solid part names the role. Both grow, and the growth is the record of an argument being won in public: that this is a business problem rather than a technical one, that somebody senior must own it, and that the owner should be in the room where money is allocated. The earliest piece here naming the role, Can your ciso answer these three questions, is already making that case.

What the chart cannot show is the half that did not follow. Standing arrived. Personal exposure arrived. Artificial intelligence arrived, at 96% and mostly without funding. The right to stop a release did not, and the distance between those two facts is where most of the frustration in this profession actually lives.

Is the money the problem?

Usually not, and saying so is unpopular in a profession that has spent twenty years asking for more. Global spending stands near $248.9bn and is growing about 12.7% after a year in which it grew only 4% — a slowdown that panicked people at the time and turned out to be a pause rather than a trend. Security typically consumes something like 13.2% of technology spending, which is not a starved function.

Where the money goes is more revealing than how much of it there is. Roughly 40% goes to software and platforms, 30% to people, 15% to hardware and 15% to outside services. A function that spends more on tools than on the people operating them tends to accumulate products nobody has time to tune, which is the most common finding in any honest review of a well-funded security programme.

The genuine constraints are not purchasable. Who is permitted to stop a release. Who may accept an exception and for how long. Whether an inherited system with no maintenance path can be retired, and who pays. Whether the annual objectives of the engineering leadership include anything that a security failure would jeopardise. Each of those is free, each takes a year to change — and each is also why experienced people leave — and none appear in a budget request.

There is also a quieter waste that no budget line captures. Tooling bought in successive waves overlaps: three products alert on the same behaviour, two agents compete for the same processor, and nobody has retired anything because retirement requires proving a replacement covers the gap. Inventories of licensed but unconfigured software are commonplace, and consolidating them typically frees more capacity than the next purchase would add. The obstacle is rarely analytical. Nobody is promoted for switching something off, and the person who does it owns every subsequent outage whether or not the two are related. Removing that penalty is a management decision, available immediately, and free. It requires somebody senior to say out loud that the person who retires a redundant product will not be held responsible for the next unrelated failure, and then to mean it the first time one happens.

Which is why the more useful request to a board is rarely for funding. It is for a decision: this is the exposure, here is what removing it costs, here is what carrying it costs, and we need somebody to choose. Boards are constituted to do precisely that, and much of the time nobody has ever asked them to.

What the job turns out to consist of

Job descriptions for this role describe strategy, architecture and threat. The calendar of somebody doing it describes something else entirely: contract clauses, supplier questionnaires, audit evidence, exception requests, and a standing argument about whether a project can proceed. Very little of the week is spent on anything a technical candidate would recognise as security work, which is the single largest surprise reported by people moving into it from engineering.

A substantial share of the load is answering other organisations' questions. Every significant customer now sends a security questionnaire, each different, most asking for the same assurances in incompatible formats, and none of them read carefully by the recipient. The industry has produced standard frameworks precisely to end this, and the frameworks have been added to the questionnaires rather than replacing them. The cost is real and falls hardest on smaller suppliers, who answer proportionally more of them with proportionally fewer people.

Underneath the paperwork is a genuine function that nothing else in the organisation performs: translation between people who understand what a system does and people who decide what the company will risk. Engineering knows the failure modes and cannot price them. The board can price things and cannot see them. Somebody has to carry meaning across that gap in both directions, and the reason the role has survived every prediction of its obsolescence is that the gap has not closed.

Which suggests a hiring test rarely applied. The useful question for a candidate is not how they would architect something. It is to describe a time they persuaded somebody with more authority to accept a delay, and what it cost them. People who cannot answer have generally not done the job, whatever their title said.

What should a board actually ask?

Directors are routinely handed lists of questions to put to their security leadership, and most of those lists produce a recital. Asking whether the organisation is compliant, whether it has a framework, or how many incidents occurred invites answers that are true, reassuring and uninformative. The questions that work share a property: the answer is either specific or visibly absent, and both outcomes are useful.

What could stop us trading tomorrow, and for how long? This forces a named system, a named consequence and a duration, and it cannot be answered with a percentage. If nobody can answer it, that is the finding, and it is a more valuable one than any report the meeting was going to receive instead.

What did we decide to leave undone this year, and who signed for it? Every organisation carries accepted risk. A leadership that cannot produce the list is not carrying less; it is carrying the same amount without anybody having chosen. The follow-up matters as much: were those signatures given by people who benefit from the decision, or by the security function on their behalf?

And the awkward one: what would you do differently if this were your own money? Asked seriously, it separates the requests that exist because a control framework lists them from the requests somebody genuinely believes in. It also gives an honest professional permission to say that a much-discussed initiative is not worth doing, which the incentives in this field almost never allow.

The exception that quietly became the policy

Every organisation has a policy and every organisation breaks it, which is neither scandalous nor avoidable. Systems predate rules, acquisitions arrive with their own arrangements, and a business occasionally needs to do something the standard forbids in order to make money. The exception process exists for this, and it is the most neglected mechanism in the entire field.

Neglected because it is dull, and consequential because it is where the real security posture is decided. A policy describes what an organisation intends. The exception register describes what it actually does. In most places that register is a spreadsheet, incomplete, with entries that have no expiry, no compensating measure, and an owner who left two years ago. Those entries are not deviations from the security programme; collectively they are the security programme.

A functioning version has four properties and none of them require software. Every exception expires, with a date, and the default on expiry is that it stops rather than renews. Every exception names a person senior enough to be uncomfortable signing it. Every exception states what is being done instead, even if that is nothing, because writing "nothing" is itself informative. And the whole register is reviewed by somebody outside the function that requested them.

The same neglect shows up in the one rehearsal that matters. An incident is a governance event before it is a technical one: counsel arrives, an insurer must be notified, a regulator's clock starts running in every jurisdiction where customers live, and somebody has to speak publicly within hours while the forensic picture is still incomplete. Organisations that have practised this discover the awkward questions in a conference room — who authorises paying an extortionist, who signs the customer letter, whether the chief executive or the general counsel fronts the announcement — and organisations that have not discover them at two in the morning with a journalist already holding the story.

A rehearsal worth the afternoon has a specific shape. No slides, a scenario nobody in the room helped write, the communications and legal people present rather than represented, and one deliberate complication introduced halfway through: the backups are encrypted too, or the person with the authority is on a flight. What it produces is not a plan. It is a list of decisions nobody had realised were unassigned, which is the same output as the exception register arrived at from a different direction.

Get that working and a surprising amount of the rest becomes easier. Board reporting acquires content that is genuinely about the future. Prioritisation stops being an argument about severity scores and becomes a queue ordered by what the organisation has already admitted it is uncomfortable with. And the person carrying the personal exposure discussed above has, for the first time, a record showing which decisions were theirs and which were somebody else's.

Common questions

Who does the security chief usually report to?

Still into technology. Around 64% report to a chief information or technology officer and only about 11% to the chief executive. That arrangement asks somebody to contest the delivery priorities of the person who writes their appraisal, which works exactly as well as it sounds.

Is personal liability a real concern now?

It is the fastest-moving sentiment in the role: roughly 78% report worrying about personal liability, up from about 56% a year earlier. The prosecutions and enforcement actions behind that jump are few in number and enormous in effect, because they established that the answer to "who is accountable" can be a named individual.

Does that make the job unattractive?

It changes what a candidate negotiates for. Indemnification, directors-and-officers cover that explicitly includes the role, a written statement of decision rights, and evidence that risk acceptances are recorded and signed elsewhere have all moved from unusual requests to standard ones.

How much are organisations spending?

Global information security spending is around $248.9bn and growing about 12.7% year on year, a marked acceleration after a year that grew only 4%. Security typically runs near 13.2% of the technology budget, split roughly 40% software, 30% people, 15% hardware and 15% outside services.

Do boards think they are being informed well?

Not really. About 29% of directors call the updates they receive very effective and roughly 53% say only somewhat. The interesting detail is where it breaks: reporting on the current state works reasonably, and reporting on future risk does not.

Why does future-risk reporting fail?

Because more than half of organisations have never defined how much risk they are willing to carry. Future risk can only be reported against a threshold, and where no threshold exists the report becomes a list of frightening possibilities with no way to say whether any of them is unacceptable.

What does a good board update look like?

Short, in the units the room already uses, and ending in a decision somebody has to take. Consequence rather than activity, exposure that is being accepted rather than eliminated, and a named question the board is being asked to answer. Almost everything else is throat-clearing.

How long should preparing one take?

Far less than it does. Ten hours or more per report is common, and most of that is assembling numbers into shapes nobody asked for. A standing set of three or four measures the board has agreed to care about turns preparation into updating a page.

Should the security chief sit on the board?

Rarely, and the demand is usually a proxy for something else. What the role actually needs is a route to the audit or risk committee that does not pass through the person whose project is being delayed, plus minutes that record who accepted what. Both are achievable without a seat.

Who owns artificial intelligence risk?

The security chief, almost everywhere: some 96% now hold it, up from a minority two years ago. It arrived the way responsibilities usually arrive in this role — by default, because nobody else claimed it, and generally without matching budget or headcount.

Is a bigger budget the answer to most problems?

Less often than requested. Spending is rising faster than headcount can absorb, and the constraint in most organisations is decision-making rather than money: who may stop a release, who accepts an exception, how long an exception lives. Those cost nothing and are harder to obtain than funding.

What is the single most useful change?

Writing down what the organisation is prepared to lose, and having somebody senior sign it. Everything downstream — prioritisation, reporting, the argument about the delayed release — becomes tractable once that sentence exists, and stays a matter of opinion until it does.

Leadership and governance in the archive

611 entries, peaking in 2019 with 127.