What’s the ideal reporting line to maximize a CISOs impact?
Chief Risk Officer11%
Chief Operating Officer39%
Chief Information Officer36%
Chief Executive Officer12%
374 PARTICIPANTS
Chief Risk Officer11%
Chief Operating Officer39%
Chief Information Officer36%
Chief Executive Officer12%
People44%
Process39%
Technology13%
None, these are always given equal priority and funding regardless of the situation3%
Reviewing hiring/onboarding practices29%
Instituting maternity and paternity leave48%
Setting targets or goals for diversity in leadership52%
Providing support in the form of mentors, sponsors and resource networks45%
Scheduling inclusive networking events19%
Other (please share below!)3%
No selling.
No recruiting.
No self promotion.
Rules of EngagementFAQsPrivacy
© 2025 Gartner, Inc. and/or its affiliates. All rights reserved.
I'm surprised by how low the CEO is. To maximise a CISOs impact they need to have a seat at the top table.
If they report through another role, such as the CIO, then their needs are in direct competition with all the other needs of that department, before they can be prioritized against the needs of the rest of the business.