CISO Salary Trends and Market Demand with Nick Kakolowski
Nick Kakolowski, senior director of research for IANS, dives into what’s happening with CISO salaries given the current levels of demand for expertise.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Nick Kolowski, who's the senior director for Research for Iron, and we're talking about CISO salaries and compensation and what's going on with the, the money as they say.
Hey M**k, welcome to the show. Hey Michael, great to be here. Thanks for having me.
They say with great responsibility comes great compensation, or at least that's the theory. So what are we seeing here For CISOs? They're clearly under more stress than ever, but are they getting rewarded Incrementally, but not necessarily to a degree that reflects the level of pressure that's been added to the role over the past year or so.
We are seeing significant compensation increases when CISOs change jobs, but the market's been fairly stagnant and so overall compensation's been increasing at a declining rate compared to some past years, And yet the responsibilities are increasing. Is that gonna continue or do we need to kind of break up the job a little bit more? We see CISOs kind of becoming almost digital risk problem solvers.
They're the folks in the org who are really best equipped to solve a lot of digital problems, and so they're getting pulled into more and more processes. We don't see that changing anytime soon. We do see CISOs looking to add more functional department heads to their team in areas like AI data governance, particularly around data actually, and getting some more support systems around them to balance out some of those responsibilities.
But what we see really interestingly is the CISOs who have taken on a new job that has a dramatically larger scope are generally really happy about it. They're excited to have that new opportunity and they're going into a new org with a chance to kind of build from scratch and solve some key problems. The CISOs who are just having new responsibility thrown onto them without a huge compensation bump, without a change in org are just kind of getting all the problems dumped on them, is kind of how they end up feeling, and it's having a significant downward impact on satisfaction.
So finding ways to support those CISOs more effectively is gonna be key for orgs to keep them happy and retain them over time. You know, I, I looked at their report and that was one of the things that leapt out of me a little bit is that, uh, it felt to me like the new responsibilities were enabling the CISOs to be much more proactive rather than reactive. And maybe one of the reasons they're happy about it is they can actually do something about preventing a problem versus always being in the fire bucket brigade.
Oh yeah. A lot of these developments are great for the ciso. There's a bigger seat at the table, there's a larger voice to influence the organization.
There are more opportunities to solve problems at the ground level rather than being having, you know, fires thrown over the wall at them. There's just more opportunity across the board For CISOs, it's just a question of growing pains, the how much time it takes for the sports systems around the CISOs to build up to help them keep up with the stress and incremental challenges that come with all those opportunities. How big is the talent pool for cybersecurity leaders?
I mean, we hear that the overall pool is small and the percentage of those folks that are able to maybe have a conversation with the business is even smaller. So you would think that given the relative amount of expertise that's available that the salaries would keep going. So what's mitigating factors?
It's really just the lack of movement. We're seeing in general a lot of economic uncertainty across 2024, election season, geopolitical conflict, et cetera, leading to a situation where companies are generally not hiring a lot and folks aren't trying to move a lot. We start that to change in 2025, we've had 75% of CSOs are interested in a job change and we expect companies to start opening up more opportunities.
Right now it's been a little flat solely for the reason of lack of movement. We do believe that that movement is coming and that we're gonna see changes next year. What is the overall turnover rate like for CISOs these days?
I mean, is it high, medium, low, or about the same as it's always been? What's your sense? Retention has been very strong historically.
It's been a very quick turnaround role, often as short as averages of 18 to 24 months. We are seeing that change in shift in CISOs are sticking around for longer, but we want to caution folks who are looking to hire CISOs that that's not because everyone's happy and really pleased with their jobs, it's because the opportunities and the movement in the market aren't there. And once we, once that movement picks up again, we expect to see a lot of change.
Is it your sense that CISOs are getting better at being able to talk to the business? I mean, one of the things we heard for so long was that CISOs needed to get a seat at the board, but when they got there it wasn't clear that they understood how to communicate in a way that the board could understand. So are we making any improvements there?
Definitely it's, it's a long road and everyone's in different places, not just CISOs as individuals but organizations as well. There's a bit of everyone having to kind of come together and find a middle ground boards and executives need to start getting a little bit conversant in cyber and technology just because digital tools are such a critical part of the business and CISOs need to be able to translate up to those or to that part of those parts of the organization more effectively. We see both things happening.
Some orgs have gotten really good at it at this point. Some CISOs are excelling there, others are starting to catch up and get better. We're seeing competence overall becoming stronger though How We perceive the relative happiness of a CISO and their investments in ai.
There are gonna be some correlations there because I think one of the issues has always been troubling is there's just a lot of paperwork and a lot of toil in the whole profession. So you know, maybe we're on the cusp of where this becomes more manageable. We are seeing automation growing as a talking point heading into 2025, but AI is still at a stage of promising way more than it can actually deliver.
And for the most part we hear CISOs at a place of frustration of everyone's rushing to use ai, but it's not delivering the business value commensurate with the risks. When we can find the right use case, it's great, but the number of use cases where AI can really help us are still fairly narrow, but looking for more ways to automate more ways to become more efficient and distribute some of that work is becoming critical. How is the accountability changing for this position?
We heard a lot of, um, discussion about these issues when the SEC law was being debated last year and the year before. Um, you know, is the job just the definition just dramatically expanded? Yeah, it's very complicated right now because the CISO role is so different from organization to organization, there still isn't a defacto, this is what a CISO does.
This is always what they're responsible for. This is always what's under their jurisdiction. Therefore everyone knows, okay, if something went wrong in this area, it's on the ciso.
There's a lot of navigating who actually has the direct signature responsibility for this risk decision? Is it the ciso? Is it a line of business?
Some folks want to share risks, some CISOs want to be risk influencers but not the decision makers. And some are starting to take ownership of more areas of risk that wouldn't traditionally fall under cyber because they're the most knowledgeable person to do so. There isn't a defacto best practice at this stage.
I think the emerging ideal scenario is one in which the CISO is an active participant and leader in the vast majority of digital risk conversations, but the business unit leader who is closest to the actual process is still the one ultimately owning that risk in partnership with the ciso. What does it take to be a CISO then, for all the folks who are watching this who kind of are already in cybersecurity and are thinking about um, maybe you know, moving up the ladder, I'm assuming there's a lot of soft skills, but other than the fact that maybe after improve my golf game, what does it take? Start building cross-functional relationships and getting involved in business projects?
We see what happens a lot. If you talk about, think about the development of a typical sales leader or marketing leader organizational function, the nature of their work exposes them to a variety of executives in a variety of lines of business in a way that helps them build the relationships and the varied knowledge of how the business works and how the business makes money to impact the org. Whereas a lot of security leaders as they come up through the engineering ranks, the analyst ranks, they get siloed in the technical side of the business and then they get into the more executive ranks, the leadership roles and they're asked, okay, start impacting the organization and how it makes money and they just haven't been exposed to it by osmosis and they've had to try to catch up on what other folks have been doing gradually for years.
Take the time to get involved in some of those cross-functional side projects that might not be directly under your jurisdiction. That might be, you know, volunteering for broader risk committees, things of that sort serving on nonprofit boards that will help get you exposed to governance issues and how governance leaders think about things. Those kinds of side projects can kind of start helping you build those soft skills and those influencing skills that become more important in the CISO role.
How do we get the business folks to buy into that? 'cause they'll be blunt about it a lot of times. You know, they see the security people coming and they just clam up and they're trying to do some project somewhere and they're hoping that it'll pass down the road, but they don't wanna share early.
So how do I get the security people into that conversation then it might make a difference sooner. Ultimately, it's kind of the same as most business relationships on some level are transactional. What can you do for them so that they'll do something for you?
Go in looking for ways to help them to make their lives better, to solve their problems, understand what they need and what they want from an interaction with a business partner and do what you can to help them. And then when you show them that you can offer them value, they're gonna be more interested in bringing you into conversations earlier and having you involved. What's your crystal ball telling you about 2025?
Is demand for CISOs gonna increase? Will there be more salaries? Should CISOs go higher their own agents like a ballplayer?
I don't know how much demand on the high level will increase, but movement from CISO role to CISO role will we expect fully to increase dramatically? We think our real recommendations for CSO is to kind of figure out what is their unique superpower, what is the thing that makes them special? And look for the roles that are with orgs that need that specifically.
There's a lot going on scope wise, but ultimately what's driving business expansion and business growth is gonna be what makes them excited for a specific CISO in a role and help you differentiate from the other CISOs in the industry. I think it's fair to say that um, CISOs have a lot of stress. Have you seen anybody do anything or kind of master any techniques for managing that stress?
'cause stress equals burnout. The CISOs that I see who are most balanced are able to find ways to take ownership of their calendar and not get pulled in so many different directions and kind of choose where they go. That's usually comes from a blend of building strong leadership teams below them so they can delegate more and take on more strategic tests themselves and not be as in the weeds and building executive partnerships so that they have the respect and influence in the org to kind of own their calendar and own their priorities because they know the rest of the org knows that they're balancing and aligning with the business.
One of the things we've seen in the last year, and I wouldn't call it a major massive trend, but it's, uh, showing up more often. You're seeing CISOs maybe take over the entire IT department, um, and sometimes they become the CIO. Is that a viable thing or, um, ultimately should I always have the CISO and the CIO be separate functions because maybe, you know, it's too much of, uh, the fox guard in their own hand house.
Yeah, we see about 30% of CISOs have ownership of some elements of it. As we speak to the community about this, they're pretty excited about this transition as an opportunity to kind of have more synergy between what's going on in the technology side of the shop and the security side. Ultimately what's happening is there's more and more orgs are putting most of their technology in the cloud.
There's less infrastructure to manage, there's less business value to be gained by being better at managing the technology and there's more business value to be gained by getting better at managing the security and the digital risk. And so the CISO is being positioned to own the technology, maybe having ahead of technology reporting into them while they're kind of a CISO and CIO role and we expect this to continue becoming more common. And we see this both in very large orgs and very small orgs.
It's not, it's not a phenomena that's just for smaller orgs that are very resource constrained. I almost feel like there's a separation now between security ops and the actual threat hunting and being an analyst and, um, some of that security ops is being managed by an IT team that may or may not report up into the ciso, but it feels like we're getting more into separation of concerns with our limited resources. Yeah, a lot of traditional lines and security, whether it's between security and tech security and privacy security and data governance are all getting blurred and responsibilities are shifting over to the places where it just ends up making sense for that business.
Um, I don't know if you have children or not, but if they were in college, would you at this moment recommend them to get into the cybersecurity field and become a cisa? Yeah, Tony, I was, um, one of our faculty, Steve Marano was just talking about this yesterday. If he, his, his language is something to the effect of, if I was talking to a young professional or someone heading into college and they were deciding do I wanna go into it or go into security, I would wholeheartedly recommend they go into security.
All right, well folks, you heard it here. Hey, as always, with security, it's the best and worst of times and no matter what year it's gonna be, but the good news is, hey, compensation's worth it. Hey Nick, thanks for being on the show.
Thanks for having me, Michael. All right, and back to you guys and Steve.