EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.
Explore our Offerings
-
Discover how EY's cybersecurity, strategy, risk, compliance & resilience teams can help your organization with its current cyber risk posture and capabilities.
Read more
Change reporting structures and metrics
CISOs and the rest of the organization can only enhance cyber resilience by building trust and collaboration. This is seen in successful organizations today that effectively leverage enterprise diversity — such as business line owners, customer management, marketing, fulfillment, talent management and technology. They not only recognize that collaboration can take place organically, but also intentionally work on uniting and radically transforming how the business operates and serves its customers.
This poses a fundamental question of whether the hierarchical structures that worked before are still relevant, or whether cross-functional teams with a common purpose can be more effective for change to happen.
Respondents in the GISS said that 37% of SEA CISOs report to the organization’s CIO and only 20% report directly to CEOs. The former’s traditional reporting structures could leave cybersecurity in a less strategic position, with the CIO required to act as a conduit. CISOs must seize the opportunity to collaborate more closely with the business lines implementing the changes, and to play an active role from the start.