TESTIMONIALS

โ€œReceived the latest edition of Professional Security Magazine, once again a very enjoyable magazine to read, interesting content keeps me reading from front to back. Keep up the good work on such an informative magazine.โ€

Graham Penn
ALL TESTIMONIALS
FIND A BUSINESS

Would you like your business to be added to this list?

ADD LISTING
FEATURED COMPANY
Cyber

CISO view

by Mark Rowe
Amy Lemberger, founder of The CISO Hub, argues that the real corporate cyber security issue is basic: no one senior is clearly owning the decisions that matter.

In many businesses, cyber security still sits under IT, compliance, or procurement. Itโ€™s still seen as a โ€˜nice to haveโ€™ and not a โ€˜must haveโ€™. That structural choice shapes how risk is handled. Security becomes operational rather than strategic. Decisions are pushed down the organisation, while accountability remains unclear. When incidents occur, leadership is often caught off guard, despite months or years of warning signs.ย Lemberger is a former FTSE-250 Chief Information Security Officer (CISO) who has spent over 17 years working in cyber security. She says this misunderstanding is widespread.

โ€œAccountability for cyber risk never leaves the CEO,โ€ she says. โ€œYou can delegate responsibility, but you canโ€™t outsource accountability.โ€

Lemberger argues that hiring a CISO is often misunderstood as a solution in itself. In reality, it changes the quality of information available to leadership, not the level of risk.

โ€œHiring a CISO doesnโ€™t make risk disappear,โ€ she says. โ€œIt makes risk visible. What matters is what the business chooses to do with that visibility.โ€

Cyber risk, she explains, is not a technical problem that can be solved once and moved on from. It is a continuous series of trade-offs between security, speed, cost, and growth. Those trade-offs sit squarely at leadership level.

When security is buried too far down the organisation, the people closest to the risk often lack the authority to influence outcomes. At the same time, senior leaders may not have a clear or honest picture of the risks they are accepting. The result is a gap that no amount of tooling or policy can close.

Debates about where the CISO should report are common. Should the role sit under the CIO, the CFO, or directly with the CEO. Lemberger believes the reporting line matters less than access and influence.

A security leader who cannot speak directly and plainly to senior decision-makers ends up producing reports that circulate without changing behaviour.
About the CISO Hub
It offers a virtual or fractional CISO – a Chief Information Security Officer who works with an organisation on a part-time or flexible basis; such as for a tech start-up that isn’t yet able to pay for a full-time CISO. Visit https://ciso-hub.co.uk/.

Related News

  • Cyber

    US National Cyber Strategy

    by Mark Rowe

    President Trumpโ€™s leadership has created a new era in cyberspace, a White House cyber security strategy document has hailed. The United States…

  • Cyber

    AI in the SOC

    by Mark Rowe

    Dan Petrillo, VP of Product at the cyber firm BlueVoyant, discusses why complete autonomy is the wrong goal. As artificial intelligence (AI)…

  • Cyber

    Principles for AI use in OT

    by Mark Rowe

    The United States federal Cybersecurity and Infrastructure Security Agency (CISA) and the equivalent Australian Signals Directorateโ€™s Australian Cyber Security Centre (ASDโ€™s ACSC),…