August 19, 2014 By Christopher Burgess 2 min read

Another C has found its way into the lexicon of the C-suite: the chief risk officer (CRO).

Some may be scratching their heads and wondering why CROs are necessary. After all, isn’t risk already part of the domain responsibility of the chief executive officer (CEO), general counsel, chief security officer (CSO), chief information officer (CIO), chief information security officer (CISO) and chief operating officer (COO)?

The answer is yes; every member of the C-suite is responsible for their domain and for ensuring the remainder of the enterprise or company benefits from their decisions and counsel for collective risk management. Bringing the CRO — or the digital risk officer, as the role is sometimes referred to in the technology world — to the forefront allows risk management to be consolidated and uniform throughout the enterprise.

The Rise of the CRO

Gartner projects that one-third of large enterprises will have a digital risk officer by 2017 and that the role will broadly emerge in 2015. The role will require skills in business knowledge, communication, risk management, privacy and technology. This sounds eerily similar to what has been advocated for the CISO who wishes to secure his or her seat at the corporate strategy table. Make no mistake: The CISO who exhibits dexterity in identifying and mitigating cyber risks will continue to be a key piece of the CISO-CRO dance.

The CRO who has visibility across the enterprise or company — specifically into the domains of the general counsel, CEO, CIO, COO, etc. — ensures that risks are addressed in the broadest possible manner, with the business outcomes at the forefront. This allows the CISO’s team to address the local execution against the constant onslaught of the technological probes and attacks hitting the company’s infrastructure perimeter and evolving from within.

The role also allows for the natural evolution of a business-driven solution of information technology (IT) policies and procedures. Business ownership enforcement ensures the IT security department is not the “No Police” but rather a key part of the solution. This way, policy creation is a risk management solution, and no IT policy will stunt the company’s business processes. Should a risk be identified as both open and with no immediate migration solution, the CRO with a broader perspective can advise as to the course of action to be taken.

CISO at the Corporate Strategy Table

The CISO’s place at the corporate strategy table is not a risk. The CISO will be at the right hand, if not attached to the hip, of the CRO.

The CISO’s cyber incident response team (CIRT) will be a critical component as well. The CIRT will be able to move beyond the infamous “whack-a-mole” technique and engage in both incident response and education.

With education and overall boosted awareness, the individual user and his or her principals — those in the various roles within the C-suite) — will recognize the evolution from “No, don’t do that,” to, “This is how we should do that, and for these reasons.”

Download the IBM Report: Cybersecurity perspectives from the boardroom and C-suite

More from CISO

Making smart cybersecurity spending decisions in 2025

4 min read - December is a month of numbers, from holiday countdowns to RSVPs for parties. But for business leaders, the most important numbers this month are the budget numbers for 2025. With cybersecurity a top focus for many businesses in 2025, it is likely to be a top-line item on many budgets heading into the New Year.Gartner expects that cybersecurity spending is expected to increase 15% in 2025, from $183.9 billion to $212 billion. Security services lead the way for the segment…

On holiday: Most important policies for reduced staff

4 min read - On Christmas Eve, 2023, the Ohio State Lottery had to shut down some of its systems because of a cyberattack. Around the same time, the Dark Web had a “Leaksmas” event, where cyber criminals shared stolen information for free as a holiday gift. In fact, the month of December 2023 saw more than 2 billion records breached and 1,351 disclosed security incidents, according to research from IT Governance — an increase of 332% and 187%, respectively, over the month of…

Overheard at RSA Conference 2024: Top trends cybersecurity experts are talking about

4 min read - At a brunch roundtable, one of the many informal events held during the RSA Conference 2024 (RSAC), the conversation turned to the most popular trends and themes at this year’s events. There was no disagreement in what people presenting sessions or companies on the Expo show floor were talking about: RSAC 2024 is all about artificial intelligence (or as one CISO said, “It’s not RSAC; it’s RSAI”). The chatter around AI shouldn’t have been a surprise to anyone who attended…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today