
Some larger enterprises opt to have a deputy CISO as a way to manage the workload. In this case, the CISO is responsible for strategic direction, engaging with the board and other executives, and risk management, while the deputy role handles more of the operations.
Brown says a deputy is important for succession planning and continuity of day-to-day operations, while also providing a way to develop people who can eventually become CISOs. “It’s important to have that depth in the organization,” he says.
Both Brown and Fitzgerald say the answer isn’t to create two CISOs. It’s one CISO with clearly defined technical, governance, and operational responsibilities.
