Hired for security, judged on growth: the CISO dilemma

Boards judge CISOs on cost, growth and customer trust while hiring focuses on technical security. 2025–26 surveys show data privacy is buyers’ top concern and rising compliance hurts profits.

Chief information security officers are commonly recruited for technical expertise and leadership but evaluated by company boards on cost control, revenue growth and customer trust. Industry surveys from 2025 and early 2026 list data privacy and compliance as top concerns for enterprise buyers and link growing compliance complexity to lower profitability.

A survey of more than 3,000 enterprise technology buyers conducted in early 2026 found data privacy and compliance were the single most important customer concern, cited by over half of respondents. The same survey reported that among buyers who switched providers in the previous year, cybersecurity was the leading reason for leaving, ahead of price, coverage and reliability. A 2025 global compliance survey found 72% of executives saying rising compliance complexity over the prior three years had harmed company profitability.

Recruiting for CISOs typically emphasizes security experience, technical depth and leadership. When boards review performance, they focus on financial and market metrics. Many security leaders report being asked to prove a negative outcome — that nothing went wrong — a standard they say frames the role as insurance rather than linked to business results.

Security and compliance teams frequently prepare for annual audits and respond to buyer questionnaires in varied formats. A control that passed an audit on a single day provides no direct evidence it operated continuously. When prospective customers ask whether a control is working right now, vendors often can only give a qualified answer, and that uncertainty can delay or stop deals.

Some security leaders have changed how they work to align with sales and market objectives. Dave Brown, CISO of Andesite and author of The Lean CISO, described joining sales calls, keeping quick access to the chief revenue officer and building an evidence library that converts security reviews that once took weeks into same-day responses. Brown recounted a sale that closed after a prospect’s CEO spoke directly with the security leader.

One chief executive asks CISOs three direct questions: how are you making us stronger, how are you helping us grow and how will we recover if something goes wrong. Executives report most CISOs can address strength and recovery; fewer provide concrete evidence that security work directly enables sales or opens new markets.

Security leaders report several measurable steps that align security work with business goals. Examples include earning the compliance certifications required to sell in a specific region within a set timeframe, cutting turnaround time on customer security questionnaires from nearly two weeks to one day, and preparing to meet contractual security terms fast enough to avoid delaying deals. Practitioners say these commitments can be tracked alongside sales forecasts and do not always require larger security budgets.

Buyers are giving preference to vendors that can produce up-to-date proof of controls on demand. Firms that can show which deals a security program helped close and which markets it enabled report different budget conversations with boards than firms that report mainly on incidents prevented. Industry surveys also show CISO tenure is shorter than most other C-suite roles, while compliance requirements and buyer questionnaires continue to expand.

Executives and security leaders note that programs built primarily to survive annual audits will be judged as overhead unless they shift toward continuous proof of controls and measurable business outcomes.

Articles by this author