According to industry surveys, CISO tenure has long lagged behind other leadership positions, and one reason for this is a double standard. When recruiting, the focus is on technical depth, security experience and leadership skills. But when budget season begins and the board assesses the performance of a market leader, the focus turns to costs, growth, customer trust and brand protection.
Many CISOs feel this clearly. They were created by security or by risk and compliance, and they speak fluently. Your board is not. It gets people thinking about costs, growth and customer commitments, and a security leader who can’t connect their work to this language is seen as important but rarely strategic.
Part of this depends on how the job was defined. For a long time, a CISO’s success was measured by his or her ability to prove a negative by showing that nothing had gone wrong. This is an impossible task and presents the entire function as more of an insurance policy than a business driver.
The company is not wrong to expect this
Security plays a major role in purchasing decisions. In McKinsey’s In an early 2026 survey of more than 3,000 enterprise technology buyers, privacy and compliance were cited as a top customer concern by more than half of respondents, and vendors that lack security and compliance were increasingly excluded from consideration, regardless of price or features. The same survey found that among buyers who switched providers in the past year, cybersecurity was the top reason they left, ahead of price, coverage and reliability. Trust makes or breaks the deal. And yet, in most organizations, security is still seen as the team that slows things down, buried in a review that only begins after everyone else has agreed to move on.
I see the same thing as a CEO, as a buyer and as a boss. When I talk to my own CISO, I don’t ask how many alerts his team has closed. I ask three things. How do you make us stronger? How do you help us grow? And how do we recover when something goes wrong? Every CISO I know can talk about strength and recovery. Far fewer can concretely demonstrate how they enable business growth by demonstrating trust and closing deals.
Why the gap is so difficult to close
Why does daily reality still feel like an overhead? Because the work underneath has not changed. Compliance is becoming increasingly difficult. In PwC’s 2025 Global Compliance Survey72% of executives said the increasing complexity of compliance has impacted their company’s profitability over the last three years. Every new framework and every longer questionnaire involves effort that doesn’t have an obvious payoff, so teams do the only thing the calendar allows. You collect evidence once a year, answer the same questions in slightly different formats for each buyer, and move on.
This is where security on paper becomes a real problem. A passing audit or a clean dashboard tells you that the control was working on the day it was reviewed and nothing about the rest of the year. So when a customer’s security team asks if this control is currently working, most vendors can only say they believe it is. This hesitation causes the deal to stall while everyone waits for confirmation, and this can repeat itself throughout the pipeline. Buyers don’t find these questions difficult either. They ask because they have seen a weak provider become their own breach.
This isn’t about effort. These teams work hard. The problem is design: a program designed to survive an annual audit will always be perceived as overhead, no matter how well it runs.
What strategic security actually looks like
Strategic security leaders are already positioning themselves this way. I’ll keep talking Virtru’s Hash It Out In the podcast, Dave Brown (CISO of Andesite and author of The Lean CISO) described how managing security is something that should drive business, not hinder it. He takes part in sales meetings. He retains what he calls “speed dial” access to the CRO. He built an evidence library that turns security clearances that once took weeks into same-day responses. He even tells the story of a prospect whose CEO wouldn’t sign until he spoke directly to the head of security. One conversation later, the contract was signed over the phone.
Every CISO can translate this into concrete commitments. Suppose the board wants 50 percent growth next year. A security leader contributing to this goal could commit to three specific things: obtaining the compliance certifications the company needs to sell in Europe within four months, completing customer security questionnaires in one day instead of twelve, and being willing to meet new contractual security requirements quickly enough so that negotiations are never held up. This way, each one reads like a growth commitment that a CFO can track alongside revenue forecasting. And none of this required a larger security budget. There was a need to align that same program with the outcomes the company already cared about.
From an important player to a strategic partner
The encouraging thing is that the tools and data needed to do this already exist, and buyers are already rewarding the companies that can provide evidence when requested. A security leader who can show what the program has made possible, what deals it has closed and what markets it has opened will enter a very different budget conversation than someone who is still reporting on attacks repelled.
My advice to security leaders is simple, and it’s the same advice I ask of my own team. Stop letting your program be judged by whether there is no bad news. Tie it to the results your board is already tracking, report on them transparently even if a number is ugly, and show that you’re improving quarter over quarter. If you do this consistently, the company will finally see security for what it can be: one of the clearest sources of growth the leadership team has.
( Learn more in the CISO forum )
Related: Four risk committees cannot be treated as background noise
Related: What CISOs can expect in 2026 and beyond
