I am often asked: “What is the biggest challenge facing CISOs today?”
Most people asking the question expect a technical answer: Shadow AI, non-human identities, the agentic transformation of the enterprise… Indeed, it is tempting to assume that the biggest challenge facing today’s CISO is the rapidly evolving threat landscape.
I believe that conclusion is simplistic and possibly misleading.
For years, the cybersecurity industry has been asking the wrong questions.
We have debated security budgets, reporting lines, skills shortages, artificial intelligence, ransomware, cloud security and, more recently, post-quantum cryptography. Every year brings a new set of priorities and pushy vendors, and every year organizations invest billions of dollars collectively in new technologies designed to stay ahead of increasingly sophisticated attackers.
Yet despite that investment, major breaches continue to dominate the headlines. CISO tenure remains remarkably short, boards remain frustrated with the lack of measurable progress, and many organizations still find themselves reacting to incidents rather than preventing them.
The biggest challenge facing today’s CISO is not cybersecurity itself. It is leading enterprise-wide transformation in organizations whose structures, incentives and culture often work against long-term cybersecurity success.
That distinction matters because it fundamentally changes where leaders should focus their attention.
The Challenge Has Never Been Knowing What To Do
The overwhelming majority of large organizations already know what good cybersecurity looks like. International standards, regulatory frameworks and industry best practices have existed for decades. The question is rarely what needs to be done.
The real challenge has always been how to make it happen—and who can drive lasting change across a complex enterprise.
Too many organizations still treat cybersecurity as a technical discipline. When an incident occurs, the instinctive response is to increase spending, buy another security platform or launch another transformation program. Those actions may be necessary, but they rarely address the underlying problem.
Technology is seldom the limiting factor. Leadership is.
Why Organizations Keep Repeating The Same Mistakes
Over the years, I have described what I call the Cybersecurity Spiral of Failure. Organizations underestimate cyber threats until an incident, regulatory investigation or damaging audit forces action. Budgets suddenly become available, ambitious initiatives are launched and expectations rise. But as competing business priorities re-emerge, projects become fragmented, momentum fades and the promised transformation never fully materializes. Everything starts again at the next incident.
The common denominator is not inadequate technology. It is an inability to sustain and drive organizational change.
That is why I have consistently argued that cybersecurity should be viewed first and foremost as a business protection issue—not simply an IT or compliance function.
Cybersecurity protects revenue, operations, customer trust, intellectual property and corporate reputation. It safeguards the organization’s ability to operate and grow. It therefore deserves to be considered alongside other strategic business priorities rather than being confined to the technology function.
The Modern CISO Must Lead Without Authority
This creates a unique challenge for today’s CISO.
The modern CISO is expected to transform the organization’s security posture while controlling only a fraction of the resources required to achieve that objective. Critical decisions affecting cybersecurity are made every day by technology teams, business units, procurement, legal, human resources and operational leadership.
The CISO rarely has direct authority over any of them.
Success therefore depends far less on technical expertise than on cross-functional leadership, influence and credibility.
The most effective CISOs are not necessarily those with the deepest technical knowledge. They are the ones who can build trusted relationships across business and geographical units, navigate organizational politics, align competing priorities and maintain executive support over several years—not just during the weeks following a major cyber incident.
Business Short-Termism Remains The Greatest Obstacle
This is hard because business leaders naturally prioritize today’s operational pressures over tomorrow’s uncertain threats. Most executive teams are rewarded for quarterly performance. Investors expect immediate returns.
Cybersecurity, by contrast, often requires organizations to invest today to avoid problems that may not materialize for months or even years. That tension explains why executive attention frequently peaks after a breach before gradually returning to other priorities once the immediate crisis has passed.
Unfortunately, cybersecurity transformation cannot be achieved through short bursts of executive attention.
Stop Building Projects. Start Building An Operating Model.
It requires sustained commitment.
This is why I believe organizations should stop thinking primarily in terms of cybersecurity projects or even cybersecurity programs. Projects and programs have a start, a middle and an end. Operating models endure.
The organizations that consistently improve their resilience are those that embed cybersecurity into everyday business decision-making. Security becomes part of investment governance, procurement, product development, mergers and acquisitions, operational resilience and corporate strategy. It ceases to be viewed as the responsibility of one executive and instead becomes an integral part of how the enterprise operates and its culture.
This is not about promoting the familiar slogan that “security is everyone’s responsibility.” That phrase has become one of the industry’s most overused clichés but responsibility without accountability quickly becomes nobody’s responsibility.
The objective is different.
The objective is to ensure that business leaders own the decisions within their areas while the CISO provides leadership, direction and independent oversight across the enterprise.
That is a governance model—not a communications campaign.
The CISO’s Biggest Challenge Is Leadership
Ultimately, the biggest challenge facing today’s CISO is not defending against increasingly sophisticated attackers. Attackers will continue to evolve, just as they always have.
The defining challenge is transforming organizations quickly enough to keep pace with a threat environment where cyberattacks are no longer hypothetical events but an inevitable feature of modern business.
Organizations that continue searching for technological silver bullets will remain trapped in a cycle of reactive investment and recurring disappointment.
Those that recognize cybersecurity as a leadership challenge—and approach it as a long-term business transformation objective—will be far better positioned to build resilience, protect enterprise value and create a lasting competitive advantage.
JC Gaillard
Founder & CEO
Corix Partners
Contact Corix Partners to find out more about developing a successful Cyber Security Practice for your business.
Corix Partners is a Boutique Management Consultancy Firm and Thought-Leadership Platform, focused on assisting CIOs and other C-level executives in resolving Cyber Security Strategy, Organisation & Governance challenges.
An edited version of this article was published on Forbes on 14th August 2026 and can be found here.
