{"id":16116,"date":"2026-04-20T10:06:31","date_gmt":"2026-04-20T10:06:31","guid":{"rendered":"https:\/\/newestek.com\/?p=16116"},"modified":"2026-04-20T10:06:31","modified_gmt":"2026-04-20T10:06:31","slug":"cisos-reshape-their-roles-as-business-risk-strategists","status":"publish","type":"post","link":"https:\/\/newestek.com\/?p=16116","title":{"rendered":"CISOs reshape their roles as business risk strategists"},"content":{"rendered":"<div>\n<div id=\"remove_no_follow\">\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<section class=\"wp-block-bigbite-multi-title\">\n<div class=\"container\"><\/div>\n<\/section>\n<p><a href=\"https:\/\/www.thoughtworks.com\/en-us\/profiles\/n\/nitin-raina\">Nitin Raina<\/a>\u2019s career history resembles that of many CISOs: He worked in IT infrastructure, operations, and services before moving into security and advancing through the ranks. He\u2019s now global chief information security officer at technology consultancy Thoughtworks.<\/p>\n<p>But in a less common professional move Raina also picked up the role of global head of enterprise risk, a position he has held at Thoughtworks since 2020. He earned the job, he says, because of his ability and propensity to talk \u201cabout risk in totality.\u201d<\/p>\n<p>After taking the position, Raina established the <a href=\"https:\/\/www.csoonline.com\/article\/566417\/enterprise-risk-management-erm-putting-cybersecurity-threats-into-a-business-context.html\">enterprise risk management<\/a> function, which he now oversees. The function identifies and mitigates strategic, operational, and cybersecurity risks throughout the organization, and performs in-depth risk assessments and gap analyses to uncover vulnerabilities and inefficiencies within critical business processes, systems, and controls.<\/p>\n<p>Raina says heading enterprise risk is a natural fit for him as CISO, which is why he believes the two roles should be <a href=\"https:\/\/www.csoonline.com\/article\/2510280\/cisos-successfully-take-on-dual-titles.html\">paired more frequently<\/a>.<\/p>\n<p>\u201cThe risk conversation, as CISOs, we can lead that,\u201d Raina says. \u201cWe have the ability and the forum in which we can raise it.\u201d<\/p>\n<p>Most CISOs don\u2019t hold a risk title, as Raina does, yet researchers, executive advisers, and other security leaders say CISOs are increasingly taking on more enterprise risk management tasks.<\/p>\n<p>It\u2019s a logical expansion, these experts say. CISOs have been coached for years to identify how cyber risks pose business risks and to understand which risks represent the biggest risks to the enterprise, whether the impact of any of those exceed the organization\u2019s tolerance for risks, and if so by how much.<\/p>\n<p>That CISO work is more critical than ever, they further assert. Nearly all business operations have become digital. That fact makes any cyber risk a material risk to the business, and it makes <a href=\"https:\/\/www.csoonline.com\/article\/2111061\/cyber-resilience-a-business-imperative-cisos-must-get-right.html\">resiliency an operational imperative<\/a> today. As such, the CISO should be a key player in assessing and managing business risk.<\/p>\n<p>\u201cCISOs had once been focused on IT and cybersecurity risk. They\u2019d ask, \u2018What are the risks I have for platforms, applications, systems, the tech stack?\u2019 It was a very flat plane,\u201d says <a href=\"https:\/\/www.s-rminform.com\/our-people\/paul-caron\">Paul Caron<\/a>, global managed services lead and head of cybersecurity for the Americas at S-RM, a global corporate intelligence and cybersecurity consultancy. \u201cBut it has evolved in the past few years, and now CISOs are being pulled into new areas. They\u2019re being asked, \u2018What are the risks to the business?\u2019\u201d<\/p>\n<h2 class=\"wp-block-heading\" id=\"cisos-lead-the-way-on-risk\">CISOs lead the way on risk<\/h2>\n<p>In the <a href=\"https:\/\/www.splunk.com\/en_us\/campaigns\/ciso-report.html\">2026 CISO Report<\/a> from data platform maker Splunk, 78% of CISOs reported joint accountability with other technical C-suite leaders (CIO, CTO, etc.) for security operational business risk, 56% have that joint accountability with CEOs, and 29% have joint accountability with other C-suite roles (CFO, chief legal officer, etc.).<\/p>\n<p>The report also found that 96% of CISOs are <a href=\"https:\/\/www.csoonline.com\/article\/4073996\/the-expanding-ciso-role-from-security-operator-to-enterprise-risk-strategist.html\">now responsible for AI governance and risk management<\/a>.<\/p>\n<p>Meanwhile, the CyberRisk Alliance\u2019s <a href=\"https:\/\/files.cyberriskalliance.com\/wp-content\/uploads\/2026\/03\/Exec-Mgmt_CISO-Top-10_1Q2026_V02-1.pdf\">Q1 2026 CISO Top 10 report<\/a> found that governance, risk, and compliance is the top priority for CISOs today. The report says this reflects GRC\u2019s \u201crole as the primary mechanism through which cybersecurity earns executive and board trust.\u201d<\/p>\n<p>The report also notes that \u201corganizations are under pressure to prove that risk oversight is continuous, defensible, and integrated into enterprise decision-making. CISOs are increasingly expected to unify regulatory obligations, enterprise risk tolerance, and security controls into a coherent operating model that supports real-time governance.\u201d<\/p>\n<h2 class=\"wp-block-heading\" id=\"evolving-risks-require-a-new-ciso-leadership-profile\">Evolving risks require a new CISO leadership profile<\/h2>\n<p>The shift to CISO as a risk position, and not one limited to technical and cybersecurity alone, has been years in the making. But <a href=\"https:\/\/www.csoonline.com\/article\/4128992\/with-cisos-stretched-thin-re-envisioning-enterprise-risk-may-be-the-only-fix.html\">it has accelerated<\/a> since the arrival of ChatGPT in late 2022, as organizations embraced first generative AI and more recently agentic AI. That\u2019s because AI melds with the business process, whereas prior technologies only enabled business processes. That melding raises the stakes and makes cyber, digital, and business risk nearly synonymous.<\/p>\n<p>That evolution has pushed the CISO deeper into risk assessment and management, and it requires a different type of CISO than those of the past.<\/p>\n<p>\u201cCISOs cannot walk around and make decisions based on fear or compliance. They must now be able to talk about risk in business terms. They need to understand that risk is a business conversation,\u201d says <a href=\"https:\/\/www.emich.edu\/cet\/faculty\/l_dupree.php\">Leon DuPree<\/a>, lecturer at Eastern Michigan University\u2019s School of Information Security and Applied Computing.<\/p>\n<p>Leading CISOs do this by quantifying both risk and the ROI of their options to address those risks, DuPree says, noting that many use the Factor Analysis of Information Risk (FAIR) model to <a href=\"https:\/\/www.csoonline.com\/article\/525128\/it-risk-assessment-frameworks-real-world-experience.html\">understand and position cyber and operational risk<\/a> in financial terms.<\/p>\n<p>\u201cThat\u2019s the direction that CISOs are trying to go, so they can facilitate change and innovation working from ROIs for all the dollars being spent on security assets and risk mitigation,\u201d he adds.<\/p>\n<p>S-RM\u2019s Caron sees more CISOs taking this approach.<\/p>\n<p>For example, he says more security chiefs are being tasked with assessing and modeling risks associated with the AI uses within their organizations and reporting how those risks impact business processes \u2014 not just data integrity and IT systems.<\/p>\n<p>To perform such duties, CISOs must use more of their executive skills than their cyber acumen, Caron says. They must identify risks that come with the deployment of AI and other technologies, quantify those risks in business terms, offer mitigation strategies, quantify how each mitigation option reduces business risks, and help prioritize risk-related tasks based on expected returns and business objectives.<\/p>\n<p>\u201cIt takes more of a business leader\u2019s lens than a very technical lens. So CISOs now have to be the ones responsible for steering the conversation into directions that show they\u2019re a partner with the business to accelerate growth,\u201d he explains. \u201cThe businesses of today are demanding more and more a business CISO.\u201d<\/p>\n<p>Caron acknowledges that it\u2019s a significant demand, one that requires CISOs to expand their knowledge base beyond technical and even compliance to business operations, enterprise strategy, and market conditions.<\/p>\n<p>\u201cI think that\u2019s where CISOs needs to start going, not necessarily where they are today,\u201d he adds. \u201cMany do still struggle with the mental shift it takes.\u201d<\/p>\n<h2 class=\"wp-block-heading\" id=\"a-question-of-appetite\">A question of appetite<\/h2>\n<p><a href=\"https:\/\/www.linkedin.com\/in\/steven-martano-6263b124\/\">Steve Martano<\/a>, an IANS Research faculty member and a partner in Artico Search\u2019s cybersecurity practice, says the majority of CISOs rise through the technical and engineering ranks, so many still find enterprise risk assessment and management novel tasks.<\/p>\n<p>But, like Caron, he says it\u2019s now part of the gig.<\/p>\n<p>\u201cI think understanding how emerging tech impacts the organization\u2019s risk profile is something they must do, and I think the conversation around enterprise risk is always something security practitioners should be striving for when they communicate,\u201d he says.<\/p>\n<p>But Martano, like others, also says CISOs do not have \u2014 nor should they assume \u2014 ownership over establishing the organization\u2019s risk appetite.<\/p>\n<p>\u201cIt\u2019s not the CISOs job to revisit the risk posture itself. It\u2019s not the CISO\u2019s job to say, \u2018We\u2019re operating too loose,\u2019\u201d Martano says.<\/p>\n<p>Instead, CISOs must possess \u201ca good understanding of what the organization thinks is inbounds and out-of-bounds\u201d so they can \u201cflag how technologies, processes, and tools could have an effect on the risk posture,\u201d he says. \u201cThe CISO is the adviser.\u201d<\/p>\n<p>Boards expect CISOs to be capable of identifying and assessing current and future risks as well as advising on whether to mitigate, transfer, insure against or accept those risks, he adds.<\/p>\n<p>That may be more challenging now than ever, with technology, AI, and enterprise use of them swiftly evolving.<\/p>\n<p>\u201cThe best CISOs think about risks that are around the corner. They have to have a pulse on where things are going,\u201d Martano adds. \u201cThey don\u2019t have to be visionary; but they do need to be proactive by engaging more outside their four walls, engaging with vendors, information-sharing with their peers, having a pulse on the macro level. The more they diversify what they\u2019re hearing, the better, so they can bring nuggets of information to their boards and executive teams to discuss and how those affect their own organization\u2019s risk culture.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Nitin Raina\u2019s career history resembles that of many CISOs: He worked in IT infrastructure, operations, and services before moving into security and advancing through the ranks. He\u2019s now global chief information security officer at technology consultancy Thoughtworks. But in a less common professional move Raina also picked up the role of global head of enterprise risk, a position he has held at Thoughtworks since 2020&#8230;. <\/p>\n<p class=\"more\"><a class=\"more-link\" href=\"https:\/\/newestek.com\/?p=16116\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-16116","post","type-post","status-publish","format-standard","hentry","category-uncategorized","is-cat-link-borders-light is-cat-link-rounded"],"_links":{"self":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16116","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16116"}],"version-history":[{"count":0,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16116\/revisions"}],"wp:attachment":[{"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16116"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16116"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16116"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}