Key Takeaways
- User access, identity and Zero Trust have overtaken cloud security as the leading functional priority for CISOs.
- Boards increasingly expect security leaders to translate ransomware, data breach and third-party exposure into business risk.
- NIST Cybersecurity Framework and ISO/IEC 27001 remain useful reference points for investment, governance and resilience decisions.
Cybersecurity leadership is moving further away from a narrow focus on technical controls. CISOs are now expected to shape business decisions, brief boards, assess supplier exposure and help organizations recover from disruption. The threat stream has not slowed, either. Ransomware incidents, data breach reports and emergency patches from vendors such as Apple keep operational teams busy while executive expectations continue to rise.
That combination is changing priorities. According to Gartner, User Access, IAM and Zero Trust became the top functional priority for CISOs in 2024, overtaking cloud security. Measuring and communicating risk, along with third-party risk management, also remained among the five leading areas of focus.
The shift toward identity reflects how enterprise technology is now consumed. Employees, contractors, customers, software agents and external suppliers may access data across cloud services, internal systems and remote devices. A hardened network perimeter offers limited protection when attackers can sign in with stolen credentials or exploit excessive privileges.
Identity programs, however, are not simply technology purchases. Okta may feature in executive discussions about identity, just as CrowdStrike and Palo Alto Networks are commonly associated with endpoint and network security. But deploying another product does not automatically resolve weak account governance, fragmented directories or slow removal of access when roles change.
Identity security tends to expose organizational problems that have been sitting quietly for years. Who owns each account? Which privileges are justified? How quickly can access be revoked? Those questions cross human resources, procurement, IT, legal and business-unit leadership. They cannot be settled by the security operations center alone.
The leadership challenge is substantial. Gartner’s 2025 analysis found that only 14% of cyber leaders were successfully balancing strong data security with business objectives. That figure points to a persistent gap between controlling risk and supporting growth. Security teams can impose restrictions, but the more difficult task is designing safeguards that allow products, partnerships and digital services to move forward at an acceptable level of exposure.
Public discussion by CISOs on LinkedIn increasingly reflects that broader mandate. Posts and executive conversations often frame cybersecurity as business enablement, operational resilience and governance rather than a collection of defensive tools. This matters because boards generally respond more effectively to scenarios involving revenue, regulatory exposure, customer trust and recovery time than to lists of vulnerabilities.
Board oversight has become more formal as well. The research brief notes that 91% of boards assigned cybersecurity oversight to a committee in EY’s 2023 review of public-company disclosures. References to roles such as the CISO in board disclosures increased from 23% in 2018 to 57% in 2023 (source). Security leadership is more visible, and with visibility comes sharper scrutiny over investment choices and incident readiness.
What does a useful board conversation look like? It could connect identity weaknesses to likely business consequences, explain which critical services can be restored first after ransomware, and show how supplier dependencies affect operations. Technical metrics still matter, but measures such as patch volume or blocked alerts rarely tell directors whether the enterprise can continue serving customers during an attack.
The financial context adds urgency. The average cost of a data breach in the EU reached €4.4 million in the 2024 NIS Investments study, a 10% year-over-year increase. Those costs can include response work, operational interruption, legal obligations and reputational damage. Coverage from Computer Weekly has likewise documented the growing pressure on cyber leaders to connect technical risk with organizational resilience and executive accountability.
Frameworks can help create a shared language. The NIST Cybersecurity Framework gives leadership teams a way to organize activity around governance, identification, protection, detection, response and recovery. ISO/IEC 27001 offers a management-system approach that can support accountability, audits and due diligence. Neither removes judgment from the process. They provide structure for asking better questions.
That said, the emerging CISO agenda is not identity instead of cloud, endpoint or network security. It is a more integrated view of exposure. Identity controls, third-party governance, recovery planning and clear risk communication increasingly sit together. The CISOs who can connect those pieces to business priorities are likely to have greater influence over strategy, not just a larger security budget.
⬇️