Skip to main content
  • Personal
  • Business
  • Foundation
    Close
  • Select Region
    • Global
    • India
    • MENA
  • mySHRM Login
  • MySHRM
    • Dashboard
    • Account
    • Logout
SHRM
  • Membership
    • Membership

      As a SHRM Member®, you’ll pave the path of your success with invaluable resources, world-class educational opportunities and premier events.

      Membership Benefits
      Secure your membership
  • Learning
    • SHRM Certification

      Demonstrate your ability to apply HR principles to real-life situations.

      • Register for the SHRM US Batch
      • Self-Study for your SHRM CP/SCP Certification
      • Book your SHRM CP/SCP Exam
      Prepare for the Exam
      • Exam Preparation
      • SHRM BASK
      • SHRM Learning System
      • Instructor-Led Learning
      • Self-Study
      Specialty Credentials

      Demonstrate targeted competence and enhance your HR credibility.

      ACHRM
      CEHRM
      AI in HR
      ACE.W
      PMQ
  • Events
    • MENA Events

      Demonstrate your ability to apply HR principles to real-life situations.

      • MENA Annual Conference
      • CEO Academy
      • SHRM Leadership Circle
      Global Events
      • US Annual Conference
  • Resources
    • Resources

      Stay up to date with news and leverage our vast library of resources.

      • Flagships
      • HR Research
      • Tools & Guides
      • Webinars
      HR Topics
      • AI in the Workplace
      • Civility at Work
      • Inclusion & Diversity
      • Talent Acquisition
      • HR Technology
      • Workplace Violence Prevention
  • Partners
Become a Member
Renew
Rejoin Now
Renew
Close
  • Personal
  • Business
  • Foundation
  • Membership
    back
    Membership
    • Membership

      As a SHRM Member®, you’ll pave the path of your success with invaluable resources, world-class educational opportunities and premier events.

      Membership Benefits
      Secure your membership
  • Learning
    back
    Learning
    • SHRM Certification

      Demonstrate your ability to apply HR principles to real-life situations.

      • Register for the SHRM US Batch
      • Self-Study for your SHRM CP/SCP Certification
      • Book your SHRM CP/SCP Exam
      Prepare for the Exam
      • Exam Preparation
      • SHRM BASK
      • SHRM Learning System
      • Instructor-Led Learning
      • Self-Study
      Specialty Credentials

      Demonstrate targeted competence and enhance your HR credibility.

      ACHRM
      CEHRM
      AI in HR
      ACE.W
      PMQ
  • Events
    back
    Events
    • MENA Events

      Demonstrate your ability to apply HR principles to real-life situations.

      • MENA Annual Conference
      • CEO Academy
      • SHRM Leadership Circle
      Global Events
      • US Annual Conference
  • Resources
    back
    Resources
    • Resources

      Stay up to date with news and leverage our vast library of resources.

      • Flagships
      • HR Research
      • Tools & Guides
      • Webinars
      HR Topics
      • AI in the Workplace
      • Civility at Work
      • Inclusion & Diversity
      • Talent Acquisition
      • HR Technology
      • Workplace Violence Prevention
  • Partners
Become a Member
Renew
Rejoin Now
Renew
  • Select Region
    • Global
    • India
    • MENA
SHRM
mySHRM Login
  • MySHRM
    • Dashboard
    • Account
    • Logout
Close

  1. Topics & Tools
  2. Workplace News & Trends
  3. Talent Acquisition
  4. Why You Can't Find a Chief Information Security Officer
Share
  • Linked In
  • Facebook
  • Twitter
  • Email

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Vivamus convallis sem tellus, vitae egestas felis vestibule ut.


Error message details.

Copy button
Reuse Permissions

Request permission to republish or redistribute SHRM content and materials.


Learn More
News

Why You Can't Find a Chief Information Security Officer

October 18, 2022 | Drew Robb

Two business people looking at a laptop.


​Chief information security officer (CISO) is one of the hottest jobs in all of IT and C-level management, according to executive search firm Heidrick & Struggles. This position is vitally needed in light of a 500 percent increase in cybercrime over the last two years. In response, 69 percent of organizations are raising spending on cybersecurity this year. But technology solutions are not enough. Cybersecurity requires expert guidance to manage risk and plot a course toward a more secure future.

"Without someone holding CISO duties, technology purchases will be hit-or-miss and the organization's risk profile will increase," said Roy Azoulay, co-founder & COO of Cynomi, a network security firm based in London and Herzliya, Israel.  

The problem is that such leaders are in short supply. Skillsoft's IT Skills and Salary Report found that three-quarters of IT organizations face critical skills gaps. A survey from InfoSec IT and Security Pipeline noted that 92 percent of respondents have difficulty filling open cybersecurity positions. The general shortage of IT and security talent, therefore, has caused pay rates for C-level execs and cybersecurity personnel to skyrocket. The average CIO or CISO can command a salary of $170,000 and above. Bidding wars for top talent are common.

In some states, salaries are much higher. New York and a few other states have passed laws requiring every firm operating within certain regulated markets, such as financial services, to employ a CISO. The average salary of a CISO in the greater New York City area has soared well above $250,000, according to Heidrick & Struggles.

The supply/demand mismatch is such that CISOs, chief security officers and other high-ranking security executives are changing jobs faster than ever. According to a study by CyLumena, the average tenure is down to 18-26 months. With so few people highly skilled in both C-level and cybersecurity management, headhunters are constantly on the prowl with attractive offers.

"There is a big shortage of strategic cybersecurity expertise," Azoulay said.

CISOs Needed Now More Than Ever

Large organizations are where CISO jobs can usually be found, according to Matt Aiello, a partner at Heidrick & Struggles. But a spike in cyber risk is shifting the equation. Now midsize enterprises and even some smaller businesses see the need to hire a CISO. The position is there to coordinate the purchase of cybersecurity tools and software, devise the right tactics and strategies to lower risk, and institute processes and policies to ensure the organization is protected. While most cybersecurity and IT personnel are immersed in security logs, lists of potential vulnerabilities, detection of phishing e-mails, and watching for any signs of ransomware or exfiltration, the CISO stands aloft like a general on the battlefield. Instead of charging at individual problems, the CISO constantly assesses the risk profile of the organization; reviews summarized data from IT and cybersecurity personnel; and develops, implements and enforces measures to protect critical systems, identities and data. All of this is done in alignment with the overall goals of the business. 

The CISO, Azoulay said, is typically involved in functions such as developing and implementing processes and systems that prevent, detect and mitigate cyberattacks; monitoring, evaluating and managing cybersecurity risk; setting a cybersecurity strategy to guide investment in technology; overseeing cyber governance, risk and compliance processes; and reporting to top management and the board.

These functions have become even more critical in recent years due to so many people working remotely. In the current climate, CISOs must be constantly on the lookout for changes in the risk profile, adjusting plans and policies accordingly, and monitoring compliance. Holding this position necessitates knowledge of industry standards such as NIST, ISO, and PCi-E, and regulations such as the Sarbanes-Oxley Act, the Health Insurance Portability and Accountability Act and the General Data Protection Regulation.

Success as a CISO requires two relatively rare commodities: a great deal of experience in security and IT, and the right qualifications. According to David Foote, an analyst at Foote Partners, the qualifications typically include an MBA as well as advanced degrees in IT and cybersecurity, and certifications such as the Certified Information Systems Security Professional (CISSP), Certified in Risk and Information Systems Control (CRISC) or Certified Information Security Manager (CISM). 

What Is an HR Department to Do?

Faced with demands to hire a CISO now, what is HR to do? The options are relatively few:

  • Compete on price and be prepared to outbid others in the fight over top talent.
  • Promote someone from within who has both the experience and the qualifications.
  • Train someone internally or recruit someone who can earn the qualifications needed to function as a CISO.
  • Look to managed service providers that now offer virtual CISO services. The virtual CISO is contracted for a certain number of hours per week or month to fulfill this demanding role and provide the strategy and guidance necessary.

Drew Robb is a freelance writer in Clearwater, Fla., specializing in IT and business.

HR Technology
Privacy & Security Compliance
Recruiting
Risk Management

Was this resource helpful?

Leave Feedback

SHRM-CP Promo Image
Validate your HR expertise

Earning your SHRM-CP credential makes you a recognized expert and leader in the HR field.

Get Certified


Related Content

(opens in a new tab)
News
How One Company Uses Digital Tools to Boost Employee Well-Being

Learn how Marsh McLennan successfully boosts staff well-being with digital tools, improving productivity and work satisfaction for more than 20,000 employees.

(opens in a new tab)
News
A 4-Day Workweek? AI-Fueled Efficiencies Could Make It Happen

The proliferation of artificial intelligence in the workplace, and the ensuing expected increase in productivity and efficiency, could help usher in the four-day workweek, some experts predict.

(opens in a new tab)
News
Rising Demand for Workforce AI Skills Leads to Calls for Upskilling

As artificial intelligence technology continues to develop, the demand for workers with the ability to work alongside and manage AI systems will increase. This means that workers who are not able to adapt and learn these new skills will be left behind in the job market.

HR Daily Newsletter

Stay up to date with the latest HR news, trends, and expert advice each business day.

Success title

Success caption

Manage Subscriptions
Our Brands

SHRM Foundation Logo
SHRM Executive Network Logo
CEO Circle Logo
SHRM Business Logo
SHRM Linkage Logo
SHRM Labs
Overview


  • About SHRM
  • Careers at SHRM
  • Press Room
  • Contact SHRM MENA
  • Ask an Advisor
  • SHRM Newsletter
  • Copyright & Permission
Contact Us


Email: SHRM.MEA@shrm.org
Landline: +971 43649464

SHRM KSA Office (Riyadh)
+966507266968

SHRM UAE Office (Dubai)
+971581101786


© 2026 SHRM. All Rights Reserved
SHRM provides content as a service to its readers and members. It does not offer legal advice, and cannot guarantee the accuracy or suitability of its content for a particular purpose. Disclaimer

Follow Us

  • LinkedIn
  • Facebook
  • Twitter
  • Instagram
  • YouTube

  1. Your Privacy Choices

  2. Terms of Use

  3. Accessibility

Join SHRM for Exclusive Access to Professional Content

SHRM Members enjoy unlimited access to articles and exclusive member resources.

Already a member? Login
Free Article

Login to unlock unlimited access or join SHRM today to get unlimited access to articles and member-exclusive resources.

Already a member? Login
Limit Reached

You've reached the limit of 1 free article this month. Join to access unlimited articles and member-only resources.

Already a member? Login
Free Article

Login to unlock unlimited access or join SHRM today to get unlimited access to articles and member-exclusive resources.

Already a member? Login
Exclusive Executive-Level Content

You've reached the limit of 1 free article this month. Join the Executive Network and enjoy unlimited content.

Already a member? Login
Unlock Your Career with SHRM Membership

Please enjoy this free resource! Join SHRM for unlimited access to exclusive articles and tools.

Already a member? Login
Join SHRM for Exclusive Access to Professional Premium Content

SHRM Members enjoy unlimited access to articles and exclusive member resources.

Already a member? Login
Join SHRM for Exclusive Access to Student Content

SHRM Members enjoy unlimited access to articles and exclusive member resources.

Already a member? Login
Join SHRM for Exclusive Access to Executive Network Content

SHRM member enjoys unlimited access to articles and exclusive member resources.

Already a member? Login

Your membership is almost expired! Renew today for unlimited access to member content.

Renew now

Your membership has expired. Renew today for unlimited access to member content.

Renew Now

Your Executive Network membership is nearing its expiration. Renew now to maintain access.

Renew Now

Your membership has expired. Renew your Executive Network benefits today.

Renew Now