Ask ten people what a Chief Information Security Officer does and you'll get ten different answers. Some purely technical. Some entirely about audit paperwork. A few that just say "the person who gets fired after a breach." None of them are wrong exactly, they're just partial.
The job spans strategy, budget, people management and a genuine crisis role, sometimes in the same week. And the cost of getting it wrong has gotten more personal. Under section 180 of the Corporations Act, Australian directors carry real exposure for cyber risk oversight failures. The Federal Court's 2022 finding against RI Advice, and ASIC's $2.5 million penalty against FIIG Securities in February 2026, both came down to boards that had good intentions on paper and nothing to show for them in practice. A CISO, whether that's a full-time executive or an outsourced service, is the person whose job is making sure the paper trail and the practice actually match.
Here's what that covers.
| Figure | What it means for a CISO's job |
|---|---|
| 62% | of breaches in 2026 involved the human element (Verizon DBIR) |
| 48% | of breaches involved a third party in some way, up 60% year over year (Verizon DBIR) |
| 31% | of breaches started from an unpatched, known vulnerability (Verizon DBIR) |
| $2.5m | the penalty ASIC secured against FIIG Securities for inadequate cybersecurity governance, Feb 2026 |
A CISO sets the direction for the whole program: what gets built, what gets bought, what gets left alone for now. That includes making sure the organisation actually meets whatever compliance obligations apply to it, ISO 27001, PCI DSS, the Essential Eight, a client contract's own security schedule, rather than treating those as a once-a-year scramble before an audit.
What this looks like: a documented security strategy reviewed at least annually, a compliance calendar nobody's surprised by, and a named owner for every control on the books.
Good security work gets judged by whether it helps the business do what it's trying to do, not by how many controls it adds. Part of the role is translating between two groups that don't naturally speak the same language: engineers who think in vulnerabilities and risk scores, and executives who think in revenue and deadlines. When a new product or project kicks off, the CISO should be in that conversation early, not called in once the architecture's already locked.
Boards don't need a rundown of every alert the SOC saw last month. They need the organisation's risk profile, what's actively being improved, what incidents happened and how big they were, and whether last year's security spend actually reduced risk. Given the exposure directors now carry under the Corporations Act, a vague update isn't just unhelpful, it's a liability. The CISO's reporting is often the only evidence a board has that oversight happened at all.
When something goes wrong, and eventually something does, the CISO decides how bad it is, who needs to know, and how fast. That means running incident response directly when the incident is serious enough, and staying close to it even when it isn't: every incident, however small, should cross the CISO's desk so a pattern gets caught before it becomes the pattern that made the news.
What this looks like: a response plan that's actually been rehearsed, not just written, and a CISO who can brief the CEO in plain language within the hour, not the week.
A ransomware incident doesn't end when the malware's removed, it ends when the business has its ability to operate back. Business continuity and disaster recovery plans are only useful if someone owns keeping them current and actually invokes them when needed, and that's squarely a CISO responsibility.
Culture change doesn't happen because a CISO sends one memo. It happens because the same person keeps showing up in different rooms with the message adjusted for whoever's listening: engineers get one version, sales gets another, the exec team gets a third. A CISO who only talks to the security team never moves this needle.
Nearly half of all breaches now involve a third party in some way, a jump of 60% on the year before. Vendors, contractors and software suppliers all carry risk into your organisation whether you've assessed them or not. Part of the CISO's job is making sure that assessment happens before a contract gets signed, not after something goes wrong with a supplier nobody vetted.
No security budget is unlimited, so someone has to decide where the next dollar does the most good: a new detection tool, more training, another analyst, a vendor audit. That's a judgment call, and it's the CISO's to make, ideally backed by data on where the organisation's real exposure sits rather than whichever vendor pitched the loudest that quarter.
A CISO isn't a one-person security department. Attracting, training and retaining the people who run detection, respond to incidents and manage controls day to day is part of the role. In a market where security talent is genuinely hard to hold onto, this is often where a CISO's time disappears.
Cyber criminals keep finding new ways to trick employees into clicking the wrong thing, so awareness training can't be a once-a-year video nobody watches properly. Building and running a program people retain, one that keeps pace with how attackers are operating this year rather than three years ago, is the CISO's job too.
Put those ten together and a pattern shows up: none of them get solved by buying a tool. They need someone senior enough to sit in the boardroom and technical enough to sit in the incident bridge, sometimes on the same day. That's a rare combination, and a full-time one costs accordingly, which is exactly why a lot of mid-market businesses don't hire for it at all.
StickmanCyber's CISO on-Demand gives you that person without the full-time cost: a dedicated CyberNavigator backed by StickSecure, the AI platform watching your security and compliance posture around the clock, for roughly a fifth of what an in-house CISO costs to hire. If StickmanCyber doesn't get you to the compliance mark it committed to, the team keeps working until it does, at no extra charge.
Know where your organisation stands.