A review of websites of the global top 100 companies by market value finds only 5% have listed a CISO or a CSO in their executive leadership pages
Brian Krebs / Krebs on Security : Tweets: @briankrebs and @harshilshah1910 Tweets: @briankrebs : Companies like to say they take their customers' privacy/security seriously, blah blah. But very few of the world's biggest companies list any security executives among their executive leaders http://krebsonsecurity.com/... http://twitter.com/... Harshil Shah / @harshilshah1910 : This feels like a weird metric to track. Especially when you see that the title for one of the 5 is “President of Cyber” (MasterCard) http://twitter.com/...
Context & Ripple Effects
Brian Krebs' audit of the global top 100 by market value found only five companies — including MasterCard, whose security chief carries the unusual title 'President of Cyber' — list a CISO or CSO on their executive leadership pages. As Harshil Shah noted in response, the website listing is itself a shaky proxy: a company can employ senior security leadership without publishing it.
The finding reads differently in hindsight. Later research showed the gap ran deeper than web pages: an S&P 500 board study found 88% of directors lacked direct cybersecurity experience, with only seven seating a current or former CISO, while new US breach-disclosure rules have since raised the personal legal stakes for public-company security chiefs.
First-order effects
- The five companies that do publish a security executive — MasterCard most prominently — get an immediate reputational contrast against the 95 that don't, pressuring communications teams to decide whether silence signals absence or modesty.
Second-order effects
- Boards already short on cyber expertise per the S&P 500 and Fortune 500 studies face pressure to recruit security-experienced directors, since regulators and litigants increasingly treat governance gaps as evidence of negligence.
Third-order effects
- If disclosure rules keep raising CISOs' personal liability while firms like Microsoft tie security goals to executive pay, the role shifts from an unlisted operational function to a board-accountable officer position — making the 2018-era invisible CISO structurally untenable.
The trend: Cybersecurity leadership is being pulled from the org chart's margins into board-level accountability, driven by disclosure regulation and compensation-linked security goals rather than voluntary transparency.