
We asked several current CSOs, CEOs, and IT staffing experts for advice on how security executives can best navigate a direct reporting relationship with their CEO. Offering insights below are George Gerchow, CSO at Bedrock Data and member of the IANS faculty; Matt Chiodi, CSO of Cerby; Chris Schueler, CEO at Cyderes; and Greg Fuller, vice president of the Technology Skills Suite at Skillsoft.
1. Understand how the CEO views your role
Most CEOs expect that, when you report directly to them, you fully own your functional area. Whether it’s cybersecurity, operations, or finance, they look to you as the expert in that domain. The CEO may have opinions, but ultimately, you are expected to lead and provide direction.
CEOs expect their CSO to be a true strategic partner, not just a risk reporter — connecting cybersecurity to revenue protection, regulatory compliance, customer trust, and operational resilience. In turn, CSOs should expect CEOs to treat governance as a strategic enabler, not a bureaucratic necessity.
