10 Key Roles a CISO Plays In an Organisation

Ajay Unni
Ajay Unni CEO,StickmanCyber
August 20, 2026 6 min read

Ask ten people what a Chief Information Security Officer does and you'll get ten different answers. Some purely technical. Some entirely about audit paperwork. A few that just say "the person who gets fired after a breach." None of them are wrong exactly, they're just partial.

The job spans strategy, budget, people management and a genuine crisis role, sometimes in the same week. And the cost of getting it wrong has gotten more personal. Under section 180 of the Corporations Act, Australian directors carry real exposure for cyber risk oversight failures. The Federal Court's 2022 finding against RI Advice, and ASIC's $2.5 million penalty against FIIG Securities in February 2026, both came down to boards that had good intentions on paper and nothing to show for them in practice. A CISO, whether that's a full-time executive or an outsourced service, is the person whose job is making sure the paper trail and the practice actually match.

Here's what that covers.

Figure What it means for a CISO's job
62% of breaches in 2026 involved the human element (Verizon DBIR)
48% of breaches involved a third party in some way, up 60% year over year (Verizon DBIR)
31% of breaches started from an unpatched, known vulnerability (Verizon DBIR)
$2.5m the penalty ASIC secured against FIIG Securities for inadequate cybersecurity governance, Feb 2026

Owns the cybersecurity program end to end

A CISO sets the direction for the whole program: what gets built, what gets bought, what gets left alone for now. That includes making sure the organisation actually meets whatever compliance obligations apply to it, ISO 27001, PCI DSS, the Essential Eight, a client contract's own security schedule, rather than treating those as a once-a-year scramble before an audit.

What this looks like: a documented security strategy reviewed at least annually, a compliance calendar nobody's surprised by, and a named owner for every control on the books.

Makes sure security decisions serve the business, not the other way round

Good security work gets judged by whether it helps the business do what it's trying to do, not by how many controls it adds. Part of the role is translating between two groups that don't naturally speak the same language: engineers who think in vulnerabilities and risk scores, and executives who think in revenue and deadlines. When a new product or project kicks off, the CISO should be in that conversation early, not called in once the architecture's already locked.

Gives the board a straight answer, not a slide of jargon

Boards don't need a rundown of every alert the SOC saw last month. They need the organisation's risk profile, what's actively being improved, what incidents happened and how big they were, and whether last year's security spend actually reduced risk. Given the exposure directors now carry under the Corporations Act, a vague update isn't just unhelpful, it's a liability. The CISO's reporting is often the only evidence a board has that oversight happened at all.

Runs the room when an incident hits

When something goes wrong, and eventually something does, the CISO decides how bad it is, who needs to know, and how fast. That means running incident response directly when the incident is serious enough, and staying close to it even when it isn't: every incident, however small, should cross the CISO's desk so a pattern gets caught before it becomes the pattern that made the news.

What this looks like: a response plan that's actually been rehearsed, not just written, and a CISO who can brief the CEO in plain language within the hour, not the week.

Keeps the business running through the aftermath

A ransomware incident doesn't end when the malware's removed, it ends when the business has its ability to operate back. Business continuity and disaster recovery plans are only useful if someone owns keeping them current and actually invokes them when needed, and that's squarely a CISO responsibility.

Makes security everyone's problem, not just IT's

Culture change doesn't happen because a CISO sends one memo. It happens because the same person keeps showing up in different rooms with the message adjusted for whoever's listening: engineers get one version, sales gets another, the exec team gets a third. A CISO who only talks to the security team never moves this needle.

Watches the risk sitting inside your supply chain

Nearly half of all breaches now involve a third party in some way, a jump of 60% on the year before. Vendors, contractors and software suppliers all carry risk into your organisation whether you've assessed them or not. Part of the CISO's job is making sure that assessment happens before a contract gets signed, not after something goes wrong with a supplier nobody vetted.

Spends the security budget where it actually cuts risk

No security budget is unlimited, so someone has to decide where the next dollar does the most good: a new detection tool, more training, another analyst, a vendor audit. That's a judgment call, and it's the CISO's to make, ideally backed by data on where the organisation's real exposure sits rather than whichever vendor pitched the loudest that quarter.

Builds and keeps the team that does the work

A CISO isn't a one-person security department. Attracting, training and retaining the people who run detection, respond to incidents and manage controls day to day is part of the role. In a market where security talent is genuinely hard to hold onto, this is often where a CISO's time disappears.

Runs training people actually remember

Cyber criminals keep finding new ways to trick employees into clicking the wrong thing, so awareness training can't be a once-a-year video nobody watches properly. Building and running a program people retain, one that keeps pace with how attackers are operating this year rather than three years ago, is the CISO's job too.

The person who has to hold all of this at once

Put those ten together and a pattern shows up: none of them get solved by buying a tool. They need someone senior enough to sit in the boardroom and technical enough to sit in the incident bridge, sometimes on the same day. That's a rare combination, and a full-time one costs accordingly, which is exactly why a lot of mid-market businesses don't hire for it at all.

StickmanCyber's CISO on-Demand gives you that person without the full-time cost: a dedicated CyberNavigator backed by StickSecure, the AI platform watching your security and compliance posture around the clock, for roughly a fifth of what an in-house CISO costs to hire. If StickmanCyber doesn't get you to the compliance mark it committed to, the team keeps working until it does, at no extra charge.

Know where your organisation stands.

  • A straight assessment of your current risk profile
  • What a CISO on-Demand would actually cost you versus an in-house hire
  • No obligation, just a clear picture

Sources

  • Verizon, 2026 Data Breach Investigations Report
  • Federal Court of Australia, ASIC v RI Advice Group Pty Ltd [2022] FCA 496
  • ASIC media release 25-035MR, ASIC sues FIIG Securities for systemic and prolonged cybersecurity failures (2025)
  • ASIC media release 26-021MR, ASIC action sees FIIG Securities ordered to pay $2.5 million over cyber security failures (Feb 2026)
  • Corporations Act 2001 (Cth) s 180
Ajay Unni

Ajay Unni

CEO,StickmanCyber Ajay Unni is CEO of StickmanCyber, leading the team in delivering cybersecurity, risk, and compliance solutions. He holds a Master of IT and a Bachelor of Computer Science, is a PCI Qualified Security Assessor and Certified Information Systems Auditor, and has served as CREST Vice Chairman and a member of the NSW Government Cyber Security Taskforce. With over 25 years in the industry, Ajay is a sought-after voice on the Australian cyber threat landscape.

Master of IT B. Computer Science PCI Qualified Security Assessor Certified Information Systems Auditor (CISA) CREST Vice Chairman NSW Gov Cyber Security Taskforce

Cybersecurity As A Service for Australian Organisations

StickmanCyber helps mid-market businesses across Australia and New Zealand reduce cyber risk, strengthen compliance, and build security maturity without the cost and complexity of managing it all internally.

Combining experienced cybersecurity specialists with AI-powered delivery, StickmanCyber provides practical, Cyber Done support across risk assessments, compliance, remediation, and ongoing protection — acting as a trusted partner from strategy through to certification and beyond.

CREST Accredited PCI-DSS ISO 27001 Essential Eight Since 2006
Book a free consultation
Risk Assessment & Essential EightUnderstand your current maturity and gaps
Compliance & CertificationISO 27001, PCI DSS, SOC 2 and more
Penetration & VAPTFind gaps, strengthen controls, build resilience
24/7 Monitoring via StickSecureContinuous visibility across your environment