The board is asking, and nobody in the room can answer.
The businesses with 50 to 500 people have the same regulators and the same attackers as the big ones. They just do not have the budget for a full-time CISO, and they do not need one to have someone in that seat.
A CNBC piece a few weeks ago looked at how the CISO role has changed. It used to be a back-office job, largely kept in its own silo. Now it is a boardroom job. One security chief in the article said his workload has doubled or quadrupled. Another went from talking to his CEO once a month to three times a week.
None of that surprised me. It matches what I have been seeing for a while.
I spend a good amount of time in front of boards and executive committees. A couple of years ago those meetings were pretty quiet. I would give an update, somebody would ask about the budget, and we would move on. That is not how it goes anymore. Somebody on the board read about a breach. Or the insurance carrier sent over a questionnaire with 80 questions on it. Or they want to roll out AI and are worried about an employee pasting client data into a chatbot. The conversation got a lot longer and a lot more specific.
The part the article only touches on
The companies hiring seven-figure CISOs are the big ones. The businesses with 50 to 500 people, the accounting firms, regional banks, law firms, medical clinics, insurance agencies, credit unions, manufacturers, have the same regulators and the same attackers. They just do not have that budget. So the job lands on the IT manager, or an outside MSP, or nobody, and the board keeps asking questions that nobody in the room can answer. Even the managed security providers are mostly selling detection and response, not maturing the program.
The middle ground
You do not need a full-time executive to have someone in that seat. You need someone who has been in those rooms, knows what the board is actually asking, and can say it in plain English. That is most of what I do these days: the roadmap, the policies, the risk assessment, the carrier questionnaire, the exam prep, and the board report a director can read.
The threats are not slowing down and the questions are only getting harder. If your board is asking and nobody has a good answer, it might be time to find someone who does.
Cybersecurity
The program measured against the standard it is held to, the policies and plans a client will be asked to produce, and the board report.

Tell us what the board is asking.
Whether a carrier questionnaire, an exam, or a director’s question started it, share the type of matter and the date it runs against, and keep the details for the call. An experienced professional will normally respond within one business day.
Request a Free Consultation