Heidrick & Struggles' Annual CISO Survey Reveals AI and Machine Learning Pose the Most Significant Cyber Risks, While Stress Levels Reach New Heights
46% of CISOs identified AI and machine learning as the most significant cyber risks71% of CISOs identify stress related to their roles as their most significant personal risk, up from59% in 202241% of CISOs don't have a succession plan30% of CISOs currently sit on a corporate board, a notable leap from14% in 2022
Additional research from Heidrick & Struggles revealed
"The increasing importance of cybersecurity in today's landscape is creating a significant shift in the role of the CISO as organizations face heightened professional and personal risk," said Matt Aiello, Partner at Heidrick & Struggles. "The most advanced companies are taking measures to eliminate risk within the CISO role, while strengthening their overall cyber program through robust succession planning, severance protections, D&O policies, and including cyber expertise on boards."
The importance of the role of the CISO continues to grow as digital technologies, particularly artificial intelligence, become even more prevalent and concerns about cyberattacks, specifically ransomware, rise. When it comes to organizational risk,
In addition to technological advances and more sophisticated threats, CISOs also face increasing pressure to stay ahead of the curve, leading to stress and burnout—which remain top personal concerns for CISOs year over year, as evidenced by
To address this, organizations must prioritize succession plans and/or retention strategies to prevent CISOs from exiting unnecessarily. There is room for hope, however, as
The demand for cybersecurity leadership and the specialized skills that come along with it, as well as diversity in executive positions, has become increasingly crucial within organizations, executive teams and at the board level. The survey sheds light on the fact that companies are now seeking to broaden their horizons, venturing beyond traditional industry-and IT-specific criteria when selecting CISOs. They are actively searching for the most qualified executives for the role, with a focus on diversity in terms of gender, race or ethnicity, as well as industry and functional expertise.
While the role of the CISO is increasing in importance, many organizations aren't prepared for the long run. The survey found that almost half (
Furthermore, the survey reveals that while over half of respondents expressed a belief that their corporate board possesses only partial or no knowledge and expertise required to effectively respond to cybersecurity presentations, only
"It is encouraging to see a leap in the number of CISOs sitting on corporate boards, but there is still work to be done in terms of board knowledge and expertise in cybersecurity," added Scott Thompson, Partner at Heidrick & Struggles. "And while we applaud the increase in CISOs on boards, other executives can serve as cyber experts on boards including CIOs, CTOs, GCs, Chief Risk Officers, and many others. One size does not fit all – each board can decide what kind of cyber expertise fits its needs. But this is no longer an area boards can't take seriously".
As seen in previous surveys, CISOs across regions are seeing increased compensation. From an industry perspective, CISOs in the financial services industry reported the highest average total compensation, while those in the technology and services industry received the highest average annual equity/LTI.
United States : Similar to previous years, US CISOs generally report the highest compensation. For CISOs inthe United States , reported median total cash compensation increased6% year over year, to in 2023. Median total compensation, including any annualized equity grants or long-term incentives, also increased, up to$620,000 this year.$1,100,000 Europe : The average total cash compensation for CISOs inEurope was . Average total compensation, including any annualized equity grants or long-term incentives, was$457,000 . As in$552,000 the United States andAustralia , those in the financial services industry reported the highest average total cash compensation, at . In$623,000 Europe , those in healthcare and life sciences reported the lowest. Average annual equity/LTI was highest for those in technology and services.Australia : The average total cash compensation for CISOs inAustralia was . Average total compensation, including any annualized equity grants or long-term incentives, was$368,000 . As in$586,000 the United States andEurope , those in the financial services industry reported the highest average total cash compensation, at .$501,000
The role of the CISO is continuing to evolve to meet the rapid pace of disruption and new challenges organizations face every day—and with that, leaders must recognize their unique yet important position in organizations.
About the 2023 Global Chief Information Security Officer (CISO) Survey
The annual Global Chief Information Security Officer (CISO) Survey examines both organizational structure and compensation for this increasingly critical role. For this report, Heidrick & Struggles compiled organizational and compensation data from a survey fielded in Spring 2023 of 262 CISOs around the world. Most carried the title of chief information security officer, but respondents also include chief security officers and senior information security executives. This report includes organizational data from respondents in
About Heidrick & Struggles
Heidrick & Struggles (Nasdaq: HSII) is a premier provider of global leadership advisory and on-demand talent solutions, serving the senior-level talent and consulting needs of the world's top organizations. In our role as trusted leadership advisors, we partner with our clients to develop future-ready leaders and organizations, bringing together our services and offerings in executive search, diversity and inclusion, leadership assessment and development, organization and team acceleration, culture shaping and on-demand, independent talent solutions. Heidrick & Struggles pioneered the profession of executive search more than 65 years ago. Today, the firm provides integrated talent and human capital solutions to help our clients change the world, one leadership team at a time.® www.heidrick.com
Media Contact
Bianca Wilson
Director, Public Relations,
Heidrick & Struggles
bwilson@heidrick.com
SOURCE Heidrick & Struggles