CISO Compensation Factors – Nick Kakolowski, IANS
Nick Kakolowski, research director for IANS, dives into the factors that are affecting the level of compensation a CISO can expect.
Transcript
This is Textron tv. Hey guys, thanks for the thrill. We're here with Nick Kakolowski, who's senior research director for ions and they, along with uh, ANCO search, come up with a survey on what's going on with salaries and CISO these days.
Nick, welcome the show. Great, thanks. It's great to be here.
Michael, From what I can see from the survey, salaries are up again, but maybe not as much as in previous years, but what do you think is going on in terms of demand for CISO? Because, well it is one of the most coveted jobs out there, but it's also, shall we say, somewhat stressful. Yeah, and it was a a bit of an unusual year.
We've seen compensation rates for CISO going up consistently over the past few years and this year they continued to rise but by a smaller percentage than what we had seen in the past. So we've often seen double digit compensation rises and this year that rise was just about um, 11%, which is this pretty significant drop from 14% in 2022. Still eking out in that double digit rise but not nearly as high.
And a lot of what we're seeing, and some of this is a mix of anecdotal and actual data. So we saw about 12% of CISO changing employers in our respondent base compared to 21% last year. And when you think about it, you know, not many people are gonna be getting just an iterative 10% raise at their job.
They're probably looking at 3%, 5% cost of living raises. A lot of the big jumps in compensation come from CISO changing jobs, CISO getting retention incentives, those sorts of things. And with only 12% of CISO changing employers last year because of a more tepid hiring market, we saw the overarching compensation numbers drop a little bit.
Is it in your sense therefore that demand for CISO is steady about the same or slightly decreasing? What's kind of the drivers of the fluctuation? I put it up mostly to macroeconomic conditions.
We're not necessarily seeing demand for the role decrease. If anything, the CISO rules getting elevated in orgs as the new S E C rules and the general awareness of the cyber risks alignment with business risk along among businesses are leading to more CISO being thought of as executive roles part of the C-suite. What we're really seeing is businesses are just getting a little more conservative about their hiring, a little more tentative to, you know, reshuffle their programs and make major changes in the current economic climate.
And we expect that at some point that's gonna change and the market's gonna return pretty much to normal. What's your sense of the stress level that CISO are currently experiencing? Because, well if you're gonna take that kind of compensation these days, there's a lot that goes into that and uh, I guess the question I'm asking you, is it worth it?
Uh, you have to ask some CISO but anecdotally, so we'll have some more research coming out on this later this year. What we've seen in the past couple of years is around 60 to 70% of CISO considering job changes this year, that figure jumped up to 75%, which is the jump from an eight percentage point jump from last year. And I'd say, you know, we typically see like an 18 to 24, maybe 36 month retention cycle on the CISO role, the job where folks tend to move pretty quickly and pretty often because it is so stressful, you get in, you achieve your initial goals of helping that program and then the stress adds up and you kind of move on and work your specialization somewhere else is a fairly common path for folks.
And what we're seeing is now there is some pent up readiness for a job change in the market that isn't being satisfied by the amount of available positions. And we expect when availability opens up that CISO are gonna be moving along just as they have been in the past. I Feel like a lot of the times these jobs are, shall we say unwinnable in the sense that there's always gonna be a breach and there's a tendency to blame the security people.
And I frankly don't get why, because um, if your house burns down, you don't blame the fire department. So how come we're blaming the cybersecurity people every time there's a breach when generally speaking it wasn't their fault, they're just there to clean it up. Yeah, and I can empathize with a lot of CISO that are feeling that frustration and you know, our data doesn't speak to this exact issue, but we can see it in the marketplace.
There is a tendency for, you know, mid-size firms with maybe less mature security programs where they don't necessarily view security as a partner in the business. They view security as a regulatory checkbox to then blame the CISO when things go wrong. But then we also see the more mature orgs that are bringing the CISO into the C-suite, into the boardroom regularly investing in their programs and recognizing the CISO as a partner.
And that kind of shows up in our compensation data. You know our, so the median compensation figure for CISO this year was 388 K and the average was 550 K. And anytime we see such a big gulf between median average, that tells you that the market is stratified.
And when we looked at that a little bit more closely, we saw that about 50% of CISO are making a total comp package of less than 400 K and another 30% are making a total comp package of around 600 K or more. There aren't a lot of folks in the middle. And it tells us, you know, there are a lot of businesses who are still kind of figuring out how to uplevel and upcycle how the way they think about the CISO role and the way they think about their security programs.
But there's also a large contingent in the market that is starting to prioritize security and think of the CISO differently. And I think in those kinds of businesses you're gonna see less and less of the CISO being looked at as a scapegoat and more and more of the CISO being part of the solution. And we reach some level of saturation in terms of organizations that are willing to hire a ciso or do you think we'll see more organizations maybe smaller down in terms of volume and size starting to add this title?
Yeah, I can't speak to that too much. In our data we tend to focus more on the wide swath of the market and not as much on the smaller orgs that are kind of emerging into the CSO role. I will say anecdotal, I shouldn't say anecdotally in terms of methodology and some of the work behind our data, there's a wide range from CISO who are regarded as directors to CISO who are regarded pro full on as C-level folks.
And the compensation figures vary a lot based on those roles and how those folks are perceived in their org can vary a lot based on really where they are. So even if they have a CISO title, they might be regarded more as a director within the business. Do you have any advice to folks that you've seen anecdotally about how to become a better candidate to become a CISO these days?
Is there anything out there that you see in terms of soft skills maybe that are kind of a requirement We constantly see and talk about from our faculty and folks that are really working in the industry, that executive presence is just becoming a critical skill in the industry. As CISO get brought into more board level conversations as they seek to really get a seat at the table with business issues and being made, being able to really belong among that executive suite is critical to kind of getting out of the back office tech stack and really being thought of as a partner in the business. So if you're someone who's aspiring to be a ciso, really investing in understanding how the businesses are functioning, where they get value and then how you can contribute to that value and organize a program around that.
And having a point of view that you can articulate in a concise way is really valuable. And if you're a CISO looking to kind of grow, a lot of what we recommend is really investing in projects that extend beyond cyber. Whether it's EXCO assignments, whether it's you know, working in risk, partnering with legal to kind of help solve some risk problems and governance problems.
Really figuring out how you can contribute to the business's broader risk conversations, not just cyber conversations. Is it worth going to get some business courses under your belt is if you wanna be a CISO these days so you can have those conversations. 'cause most business people, I know they're really good at talking about risk, but you know, you have to talk in the terms that they know A degree can be helpful.
There are also plenty of cyber training programs that focus on business development skills and there's real world experience is valuable. The key thing is to be able to have something that you can concisely show on your resume that displays that you've had exposure to business development skills, whether that's a degree that's great or whether it's I have worked on, you know, specific projects across lines of business that I can demonstrate on a resume to show that I've learned things here. It doesn't really necessarily matter as much as it's the ability to demonstrate that you've done it.
Is there anything in the data that surprised you that kind of leapt out and said, wow, I didn't think that would be the case? I think think we were all a little bit struck by how much VC backed firm compensation is pretty comparable to that of publicly listed companies. Like we kind of expected that VVC backed businesses would compensate their CISO fairly well because those orgs are very dependent on customer trust to be able to move forward.
But we expected the cash compensation to be so low that it would be hard to catch up. 'cause we also know those orgs tend to have a harder time, tend to use equity as a way to attract folks into roles. And what we saw is VC back CISO, their cash compensation was around 369 K, but when you threw in equity, their comp, total compensation packages rose up to an average of 6 74 K, which was only 10 K below folks in publicly I listed companies.
So if equity is ca helping them catch up a lot for VC back folks And anecdotally, do you think CISO have to worry about liability more than they did in the past? Should they all be investing in their own personal insurance policies or make sure that's covered through the companies they work for? Or is is that something, you know, we've heard people, you know, winding up being, uh, indicted for their roles.
So what exactly should CISO be thinking about on that regard? That's funny you bring this up. So this is something we're talking about a lot at our events and I will frame this first by saying, you know, I'm not a lawyer, I am not a board member or an insurance person.
I'm a lowly researcher who looks into a lot of this stuff and hears a lot of the content. I would say there it's understandable, very, very understandable that CISO have more concern here. They're seeing issues like the Sullivan case that are frankly frightening.
It's worrying that you're gonna get scapegoated for a breach, the business isn't gonna have your back and you're gonna end up becoming someone who ends up held liable for something. In practice, investing in your relationship with the executive team, documenting your processes, understanding exactly what your job role dictates you're supposed to be doing and are responsible for and documenting when the executive team has you acting outside of that role. And if you do need to act outside of that role, making sure everyone is clear that that is the case and is behind it.
And again, that that gets documented is huge. And then you know, whether you should be on the corporate D N O insurance has a lot to do with how the business is structured and where your title fits into the bylaws and overarching org structure. So look into that.
It's a great place where you can get some protections. If you can't get d and o insurance, start trying to negotiate for some indemnity so that if you aren't pulled into a court case, you have financial protections. And then personal insurance can also be useful.
Just lean in on really understanding your role in the business, what's being asked of you and where you need to partner with other leaders as ultimately it's an executive group decision between the folks who own that risk around issues that might bring up liability, make sure you're not left making that decision in isolation and stuck in a situation where you then would be held, held liable. There's a lot that goes into being a successful ciso, whether it's your staff or your relationship with other business executives. Do you see anything that's trending that kind of is an intangible that would be your best advice to folks that who aspire to be CISO to focus on this particular thing?
Yeah, like I said earlier, the executive presence is there, and then within executive presence there's having a real network of partners within the business who you trust and can trust you. The relationship with sales leaders, relationship with risk leaders and other parts of the org can be vital when you get into sticky situations or when you're trying to rise up in the business and you need sponsors who are gonna say yes, that person thinks in interesting ways about the business, not just thinks in interesting ways about security, but actually has ideas about what we're doing and how we can be better as an organization. That then translates into the security program and adds value to everybody.
And when you have folks in the org who recognize you as that kind of voice, it becomes incredibly valuable to rising up within the business. All right folks. Well you heard it here.
To be a ciso, you gotta kind of be a business executive who understands it rather than just being an IT security expert. And those skills are hard to come by and generally speaking, they only come with experience. So hang in there folks.
Hey Nick, thanks for being on the show. Thanks for having me Mike. It was great.
Alright, and back to you guys in the studio.