Blog

10 Key Roles a CISO Plays In an Organisation

Written by Ajay Unni | Aug 20, 2026, 5:31:15 AM

Ask ten people what a Chief Information Security Officer does and you'll get ten different answers. Some purely technical. Some entirely about audit paperwork. A few that just say "the person who gets fired after a breach." None of them are wrong exactly, they're just partial.

The job spans strategy, budget, people management and a genuine crisis role, sometimes in the same week. And the cost of getting it wrong has gotten more personal. Under section 180 of the Corporations Act, Australian directors carry real exposure for cyber risk oversight failures. The Federal Court's 2022 finding against RI Advice, and ASIC's $2.5 million penalty against FIIG Securities in February 2026, both came down to boards that had good intentions on paper and nothing to show for them in practice. A CISO, whether that's a full-time executive or an outsourced service, is the person whose job is making sure the paper trail and the practice actually match.

Here's what that covers.

Figure What it means for a CISO's job
62% of breaches in 2026 involved the human element (Verizon DBIR)
48% of breaches involved a third party in some way, up 60% year over year (Verizon DBIR)
31% of breaches started from an unpatched, known vulnerability (Verizon DBIR)
$2.5m the penalty ASIC secured against FIIG Securities for inadequate cybersecurity governance, Feb 2026

Owns the cybersecurity program end to end

A CISO sets the direction for the whole program: what gets built, what gets bought, what gets left alone for now. That includes making sure the organisation actually meets whatever compliance obligations apply to it, ISO 27001, PCI DSS, the Essential Eight, a client contract's own security schedule, rather than treating those as a once-a-year scramble before an audit.

What this looks like: a documented security strategy reviewed at least annually, a compliance calendar nobody's surprised by, and a named owner for every control on the books.

Makes sure security decisions serve the business, not the other way round

Good security work gets judged by whether it helps the business do what it's trying to do, not by how many controls it adds. Part of the role is translating between two groups that don't naturally speak the same language: engineers who think in vulnerabilities and risk scores, and executives who think in revenue and deadlines. When a new product or project kicks off, the CISO should be in that conversation early, not called in once the architecture's already locked.

Gives the board a straight answer, not a slide of jargon

Boards don't need a rundown of every alert the SOC saw last month. They need the organisation's risk profile, what's actively being improved, what incidents happened and how big they were, and whether last year's security spend actually reduced risk. Given the exposure directors now carry under the Corporations Act, a vague update isn't just unhelpful, it's a liability. The CISO's reporting is often the only evidence a board has that oversight happened at all.

Runs the room when an incident hits

When something goes wrong, and eventually something does, the CISO decides how bad it is, who needs to know, and how fast. That means running incident response directly when the incident is serious enough, and staying close to it even when it isn't: every incident, however small, should cross the CISO's desk so a pattern gets caught before it becomes the pattern that made the news.

What this looks like: a response plan that's actually been rehearsed, not just written, and a CISO who can brief the CEO in plain language within the hour, not the week.

Keeps the business running through the aftermath

A ransomware incident doesn't end when the malware's removed, it ends when the business has its ability to operate back. Business continuity and disaster recovery plans are only useful if someone owns keeping them current and actually invokes them when needed, and that's squarely a CISO responsibility.

Makes security everyone's problem, not just IT's

Culture change doesn't happen because a CISO sends one memo. It happens because the same person keeps showing up in different rooms with the message adjusted for whoever's listening: engineers get one version, sales gets another, the exec team gets a third. A CISO who only talks to the security team never moves this needle.

Watches the risk sitting inside your supply chain

Nearly half of all breaches now involve a third party in some way, a jump of 60% on the year before. Vendors, contractors and software suppliers all carry risk into your organisation whether you've assessed them or not. Part of the CISO's job is making sure that assessment happens before a contract gets signed, not after something goes wrong with a supplier nobody vetted.

Spends the security budget where it actually cuts risk

No security budget is unlimited, so someone has to decide where the next dollar does the most good: a new detection tool, more training, another analyst, a vendor audit. That's a judgment call, and it's the CISO's to make, ideally backed by data on where the organisation's real exposure sits rather than whichever vendor pitched the loudest that quarter.

Builds and keeps the team that does the work

A CISO isn't a one-person security department. Attracting, training and retaining the people who run detection, respond to incidents and manage controls day to day is part of the role. In a market where security talent is genuinely hard to hold onto, this is often where a CISO's time disappears.

Runs training people actually remember

Cyber criminals keep finding new ways to trick employees into clicking the wrong thing, so awareness training can't be a once-a-year video nobody watches properly. Building and running a program people retain, one that keeps pace with how attackers are operating this year rather than three years ago, is the CISO's job too.

The person who has to hold all of this at once

Put those ten together and a pattern shows up: none of them get solved by buying a tool. They need someone senior enough to sit in the boardroom and technical enough to sit in the incident bridge, sometimes on the same day. That's a rare combination, and a full-time one costs accordingly, which is exactly why a lot of mid-market businesses don't hire for it at all.

StickmanCyber's CISO on-Demand gives you that person without the full-time cost: a dedicated CyberNavigator backed by StickSecure, the AI platform watching your security and compliance posture around the clock, for roughly a fifth of what an in-house CISO costs to hire. If StickmanCyber doesn't get you to the compliance mark it committed to, the team keeps working until it does, at no extra charge.

Know where your organisation stands.

  • A straight assessment of your current risk profile
  • What a CISO on-Demand would actually cost you versus an in-house hire
  • No obligation, just a clear picture

Sources

  • Verizon, 2026 Data Breach Investigations Report
  • Federal Court of Australia, ASIC v RI Advice Group Pty Ltd [2022] FCA 496
  • ASIC media release 25-035MR, ASIC sues FIIG Securities for systemic and prolonged cybersecurity failures (2025)
  • ASIC media release 26-021MR, ASIC action sees FIIG Securities ordered to pay $2.5 million over cyber security failures (Feb 2026)
  • Corporations Act 2001 (Cth) s 180