The CISO Role Changed Faster Than Most Organisations Adapted, represented by a high-end, cinematic corporate photograph of a senior male or female executive (the CISO) standing on the right side of a modern, dark-toned enterprise security operations room at night. The executive is viewed from a sharp three-quarter angle, wearing sophisticated business attire with rolled-up sleeves, looking out a large window at a blurred metropolitan city skyline. A subtle reflection of intricate infrastructure charts and risk metrics from a nearby monitor catches the glass. The entire left side of the frame features deep, clean negative space with soft, out-of-focus background elements of a darkened corporate office. Low-key dramatic studio lighting with a restricted colour palette of deep charcoal, slate gray, and an ambient warm glow. Elite thought-leadership aesthetic.The CISO Role Changed Faster Than Most Organisations Adapted, represented by a high-end, cinematic corporate photograph of a senior male or female executive (the CISO) standing on the right side of a modern, dark-toned enterprise security operations room at night. The executive is viewed from a sharp three-quarter angle, wearing sophisticated business attire with rolled-up sleeves, looking out a large window at a blurred metropolitan city skyline. A subtle reflection of intricate infrastructure charts and risk metrics from a nearby monitor catches the glass. The entire left side of the frame features deep, clean negative space with soft, out-of-focus background elements of a darkened corporate office. Low-key dramatic studio lighting with a restricted colour palette of deep charcoal, slate gray, and an ambient warm glow. Elite thought-leadership aesthetic.
S10 Group Article series · Why leadership changed

The CISO Role Changed Faster
Than Most Organisations Adapted

Responsibility stayed central.
Control became distributed.
Article #2
Published: 11 September 2026
By Stan van Gemert | S10 Group
By Stan van Gemert
The CISO series

Executive summary

The previous publication, When Systems Stay Up but Care Starts to Slow, showed how an organisation can remain technically operational while weakened trust begins to affect real-world performance. This article examines the leadership condition behind that problem. As technology, identities, suppliers and critical dependencies have become more distributed, the CISO has become accountable for business outcomes that no single security function can control alone.

The role now extends beyond prevention and detection to maintaining governability when trust is incomplete. Yet responsibility has too often expanded without equivalent authority to restrict access, isolate dependencies or interrupt dangerous activity. The next publication, The First Alert Was Not the Boundary, brings that gap into the live incident: it shows why visibility is not containment and why leadership must be able to create a boundary before uncertainty becomes reach.

The role did not change in one moment

The change rarely announces itself.

It does not arrive as one board decision, one transformation programme or one new regulation. It accumulates.

A hospital moves imaging into a cloud-hosted environment operated by an external provider. A bank connects payment flows, fraud analytics, identity platforms and outsourced services into one continuous operating model. An insurer adds AI-assisted claims handling, remote teams, specialist platforms and third-party data exchanges to speed up customer response.

Each decision can be reasonable. Often it is exactly what the business needs at the time. Faster service. Lower friction. Better scale. More flexibility. Less manual work. But when you sit with a CISO during a serious incident, those same decisions may suddenly no longer feel like separate operational improvements. They start to reveal an undiscovered map of operational trust: systems, suppliers, identities and dependencies that were connected long before anyone had to contain them under pressure.

Which supplier still has access? Which identity path is safe? Which system can be isolated without stopping something clinical, financial or customer-facing? Which dependency was documented in the architecture, and which one only becomes visible when someone says: “We cannot disconnect that, because this team still needs it”?

That is where the modern CISO role changed. Not because cybersecurity became more technical, but because the operating model around cybersecurity became more distributed than the governance model built to control it.

THE STRUCTURAL SHIFT
The CISO role did not become more difficult because cybersecurity became more technical.
It became more difficult because operational trust became more distributed than the governance model built to control it.

Responsibility stayed central. Control did not.

Many CISOs will recognise the uncomfortable pattern.

When the organisation is calm, cyber responsibility is shared. Business units choose platforms. IT operates infrastructure. Procurement manages suppliers. HR feeds identity processes. Operations protects continuity. Legal watches obligation and exposure. The CISO advises, challenges, governs and warns.

But when the incident becomes visible, the question changes.

Who owns this?

That question often moves quickly toward the CISO.

The difficulty is not that this is unfair in a simple sense. Cyber leadership should carry responsibility. The difficulty is that the CISO is increasingly judged on a system of trust that no single function fully owns.

Modern cyber risk does not only enter through an unpatched server or a missed alert. It can move through a valid session, a trusted supplier connection, a remote support route, a privileged workflow, a business-led tool, an identity exception or a helpdesk process that was never designed to carry this level of adversarial pressure.

On paper, the organisation may look governed. In the incident call, the reality can feel different.

Someone asks whether a supplier connection can be narrowed. Someone else says the operational impact is unclear. A system owner warns that disconnecting one route could affect a critical process. Legal wants evidence. Operations wants continuity. The board wants to understand whether the situation is under control.

This is the controllability problem.

THE CONTROLLABILITY PROBLEM
The organisation may appear governed on paper.
The incident reveals whether it remains governable once trust inside the environment is no longer clean.

The CISO is not only trying to prevent the next event. The CISO is trying to help the organisation remain governable when trust inside the environment is no longer clean.

The shift from prevention to controllability

For years, many organisations invested heavily in prevention maturity, compliance programmes, security tooling, visibility layers and response planning.

Those investments matter. They remain necessary. The point is not that prevention failed as a discipline.

The point is that prevention no longer answers the whole leadership question.

A board can approve more tooling. A security team can mature detection. A CISO can improve policy, reporting and risk governance. Yet once an attacker is operating through something that appears legitimate, the organisation still needs a different kind of capability.

It needs to decide what can be interrupted.

That sounds simple until the decision is real.

Interrupting access may stop malicious movement. It may also stop a business process, a payment flow, a clinical dependency, a manufacturing line or a service that nobody fully mapped to the affected identity path.

This is why the MGM Resorts incident is useful for modern cyber leadership. It is often discussed through the language of social engineering, identity compromise and operational disruption. For this article, the deeper lesson is not a single technical weakness. It is what happens when a trusted operational path becomes unsafe and the organisation has to decide what can still be contained.
MGM and the trusted-path problem
The MGM Resorts incident is useful here because it makes the trusted-path problem visible. The attack path is commonly discussed as a case where social engineering and identity workflows became part of the route into wider operational disruption. The exact technical details should always be validated before publication, but the management lesson is clear enough for this article.

Prevention was not the whole story. Detection was not the whole story. Once trust in an identity path or administrative workflow becomes uncertain, leadership needs to know which access, systems and dependencies can be restricted without creating a larger business crisis.

That is where the CISO role changes. The CISO may be judged on whether the incident remains controlled, but the control levers may sit across helpdesk process, identity governance, cloud administration, infrastructure, operations, legal, communications and executive authority.In a hotel group, hospital, bank, manufacturer or public-service environment, the pattern can appear in different language. A helpdesk process, remote support route, privileged account, cloud identity, supplier connection or operational workflow may all be legitimate in normal conditions. Under attack, that legitimacy can become the attacker’s cover.

The management lesson is not simply “train the helpdesk better”. The deeper lesson is that trusted workflows need containment boundaries before they are used under hostile pressure.

If a trusted identity path became unsafe tomorrow, who could restrict it - and what business consequence would that decision create?
View more details chevron A white downward-facing V-shaped chevron on a transparent background.
View more details
Close more details

When trusted routes are abused, the environment may still look functional from the outside.

People can still log in. Dashboards may still show activity. Some systems continue to operate. The business has not necessarily collapsed.

But leadership may already be asking a harder question: what can we still trust enough to keep running?

The CISO is now judged differently

During a serious cyber incident, very few executives begin with the detail of which control detected which signal.

They ask questions that are much closer to the business.

Can patient care continue? Can transactions still move? Can production remain safe? Can customer operations keep functioning? Can data exposure be narrowed? Can we stop this from spreading? Can we recover without restoring the attacker as well?

These are not purely security questions. They are continuity, trust and leadership questions.

That is why the CISO role now often becomes something broader than security ownership. In the decisive hours, the CISO may have to translate technical uncertainty into operational choices. They may need to explain risk before the full facts are available. They may need to advise on containment while the business is still calculating impact. They may need to help leadership decide whether waiting for certainty is safer than acting with incomplete information.

That is a difficult role to play.

What changed

Your organisation no longer only asks:

“Can we detect the intrusion?”

It increasingly asks:

“What exactly can we still interrupt safely once trust itself becomes uncertain?”

This requires technical understanding, but also judgement, authority, timing and the ability to make trade-offs visible without turning every decision into paralysis.

This is the part of the role many organisations have not fully adapted around.

They expanded the CISO’s accountability faster than they gave the organisation executable control paths to support that accountability.

What changed around the CISO

The strongest organisations are beginning to recognise that the answer is not to place every operational decision inside the security department; that would be unrealistic, and it would also be wrong.

The better question is whether the organisation has made the critical control decisions visible before an incident occurs. Which dependencies matter first? Which identities can be restricted quickly? Which supplier connections can be narrowed without creating unacceptable disruption? Which systems must remain available even in degraded trust? Which authority has already been agreed? Which decisions cannot wait for a full committee call?

These questions do not belong only to the CISO. But if they remain unanswered, the CISO is often left carrying them when the organisation has the least time to think clearly.

That is exactly why this shift matters now. The issue is not simply whether the organisation has invested in cybersecurity—many have. The issue is whether operational control has been designed with the same seriousness as prevention.

Responsibility became centralised while operational control became distributed.
That may be one of the defining resilience problems for the modern CISO.

Containment as operational governance

Our platform redefines how containment must be understood at the executive level. It is not introduced to add another dashboard, nor to serve as a replacement for prevention, and it is certainly not a promise that incidents will never happen.

Instead, containment matters because it gives leadership a governed, calculated move when prevention has been bypassed and trust is incomplete.

This is precisely why we built our containment layer: to detect malicious behaviour immediately after entry, interrupt its spread, limit the blast radius, and narrow exposure. By preserving operational continuity wherever possible, we stabilise the environment—buying leadership the vital room they need to act.

The value is not only technical; it fundamentally changes the decision environment. Instead of asking whether the entire business must be disconnected to stop an attack, leadership can work from a more controlled question: what can be contained, where, and with which operational consequence?

That is a fundamentally different position to be in.

WHY CONTAINMENT CHANGES THE DECISION
Containment does not remove uncertainty.
It gives leadership a governed move before uncertainty becomes wider operational loss of control.

Containment does not remove uncertainty. It gives the organisation a way to act before uncertainty becomes wider loss of control.

If a security breach happens tomorrow, would your executive team know what the CISO can actually control? Not in policy language but in operational terms.

Which dependencies matter first? Which identity paths can be restricted? Which supplier routes can be narrowed? Which functions must survive? Who has authority to contain before full certainty exists?

If those answers are unclear, the issue is not only prevention maturity.

It is operational controllability readiness.

Closing bridge

This article opened the strategic operational sequence by looking at how the structure around the CISO changed before many organisations fully noticed.

The next article in this series follows the consequence of that shift.

Because when organisations keep assuming that prevention determines outcomes, they often discover too late that security spend and operational controllability are not the same thing.

Control can still be regained - if a containment move exists.

Hear first when a new S10 Group release is published

Would you like to receive a short note when S10 Group publishes a new article or newsletter?

Leave your name and email address below. We will send a short update when a new release is available, with a brief summary and a direct link to the publication.

No noise. No automated campaign stream. Just a simple signal when there is something worth reading.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Coming soon

Friday 11 September:
"The CISO role changed faster than most organisations adapted."

Monday 14 September:
"When Ransomware Becomes a Standing Operational Pressure".

Further readings