CISO Reporting Today, and Predictions for the Future
Interview with Julie Myerholtz, CISO, Brunswick Corporation
The discussion around CISO reporting is more prevalent than ever. With conflicting priorities, at times, between business and security, the shift has begun. At one time, the majority of CISOs reported to the CIO or CTO; however, with the speed at which businesses are focusing on technological advancements and with AI leading much of it, security must be at the forefront of decision-making.
I had the chance to speak with Julie Myerholtz, Vice President, Chief Information Security Officer of Brunswick Corporation, to get her take on it. Myerholtz joined Brunswick Corporation in March 2024 and currently serves as the Global CISO, leading their security strategy, overseeing the protection of digital assets and ensuring regulatory compliance. Her responsibilities include modernizing security capabilities, governance and integrating advanced threat intelligence. This encompasses product security, cyber risk management, IT resiliency, security operations, threat and vulnerability management and holistic identity and access management.
Cyber Security Tribe: In your opinion who should the CISO report to now? Do you that as changed since the discussion five years ago?
Julie Myerholtz: I do think it's changed a lot, and there's data showing that it's changing. There are several studies that show that 20 years ago, 100% of heads of security reported into CIOs, but now you're seeing it's close to a 50-50 split. Today, we see many companies having their head of security reporting to a Chief Risk Officer or CEO and in some cases, legal.
As the landscape of cyber has shifted, the CIO and the CISO can have competing agendas, and when that person reports into the CIO, it could impact the cyber program for the overall corporation.
Cyber Security Tribe: Do you think that trend will continue to shift further beyond the 50-50 split?
Julie Myerholtz: I do. I predict that 5 years from now it will be unusual for somebody to be reporting into the CIO or head of technology, and more typical to be outside of the traditional reporting structure of technology.
I saw a conference with Kevin Mandiant a while ago, who was talking about how the importance of security is getting larger for companies than it was 5 to 10 years ago; he made the switch to having the CIO report into the CISO. In that case, everything within information technology was approached with a security lens for the business within IT.
I think reporting structure is personal, to an extent. It very much depends on the company and what the company is trying to achieve. It also depends on the type of CISO you have within the organization.
You can have a policy-based CISO who just puts policies out there and the company executes against them. You might have a more strategic CISO who is part of the business that's helping develop secure business products, or you might have an operational CISO who is more in the technical weeds. Those are different types of CISOs who would own different capabilities and report in different places in the organization, depending on the outcomes you're looking to achieve.
Cyber Security Tribe: What are some of the advantages of having a CISO report into the CIO, if there are any still, and where do you think it creates the biggest challenges?
Julie Myerholtz: One of the advantages to that reporting structure is that security is very dependent on infrastructure and IT. So, as peers working side-by-side, with the right leader in place who focuses on security outcomes, you may be more efficient and effective at getting results since you don't have to influence across organizational lines. There is a partnership there that you can take advantage of when you're part of the same team in information security following the same processes.
However, a CIO is accountable for delivering technical outcomes and technology; the CISO is more in line with identifying and managing cybersecurity risk within the company's risk tolerances.
Sometimes speed to execution of delivering the needs of technology can overrule security when security reports to the CIO, because they're measured on the deliverables. They may skip security steps, or compromise security because of the velocity. You also can find funding for security doesn't always get its fair share when they report to the CIO, because the CIO may be distracted with other projects to deliver for the business and take away funding from security. Ultimately this can compromise the security posture of the overall company.
Cyber Security Tribe: As companies are accelerating their AI adoption, do you see new tensions emerging between the innovation goals and security responsibilities?
Julie Myerholtz: I'll speak for myself, but most of us CISOs were not prepared for the speed of AI hitting companies. There really weren’t a lot of tools to help us control and govern AI a year ago, much less to be able to keep up with the speed of execution. What I'm personally seeing and I'm hearing my peers say is that their CIO/CTOs want to accelerate the use of AI and get it out there as fast as possible to enable business cases, which is great, but if you don't have the right guardrails and policies and security in place, that could lead to a big mess coming down the pike.
We saw this first-hand with one of our third-party vendors we work with. I don't know how this happened, but when we leveraged their AI tool for our product, it put very inappropriate words into the document that it was supposed to be describing, so clearly their AI model had gone rogue.
Thank God for human intervention, and we caught it. But if a major third-party provider that's providing this AI model can have that happen to them, just think of what can happen to us with our self-developed models and all the things that companies are doing internally.
Cyber Security Tribe: How do you think that a CISO can maintain sufficient independence to challenge decisions when security concerns arise related to AI-driven business initiatives?
Julie Myerholtz: It goes back to the governance model, and the head of security must have an equal say. When it comes to managing AI, it can't just be the CIO making the final call, in my opinion.
You will find great people out there who make the right call for security who are CIOs, but that's not always the case. Sometimes it's easy to get distracted by what you're being measured on and shortcut other areas. I think it's critical that the CIO and CISO have equal say on whether or not you can move forward with these models, have the right guardrails in place, and implemented the right controls are there before they're able to move forward.
Cyber Security Tribe: We see organizations that have moved the CISO reporting to the CEOs, while others are going with legal, risk or compliance functions; what do you think the strengths and weaknesses of each approach might be?
Julie Myerholtz: I think it goes back to the type of CISO and the type of security organization the business needs. There are pros and cons to each model. If you’re more policy-based, I can see that going under Chief Compliance Officer, a Chief Risk Officer or legal because you set the policy and guidance, and you monitor to make sure that those don't go out of control within the boundaries. With an operational CISO who is hands-on and more technical, I could see reporting to a Chief Operations Officer where they're more hands-on inside the day-to-day operations of the business. With a strategic CISO who is part of the business strategy and protecting a product that is connected, I would say those CISOs are the ones who will sit with the CEO and be peers with the individuals who are operating the business.
Cyber Security Tribe: Does industry impact that, such as highly regulated and high-tech industries?
Julie Myerholtz: The industry definitely influences where the CISO should sit, because a CISO at a high-tech company is much more relevant to that business success than potentially at a non-public manufacturing company. It just depends on the organization, the size, and what they're producing. Regulation can weigh heavily in the reporting structure based on industry. I think you will find a very different reporting structure at a bank or financial institution than a company that manufactures physical non-connected product.
Cyber Security Tribe: What role do you think the board should play in cybersecurity oversight, regardless of where the CISO sits?
Julie Myerholtz: The board should have an active role in it. It is a risk to the business, and it proves that it's only becoming a bigger risk to business and operations. AI is making it more difficult. I saw an article today about a major company that was recently breached, and it took them 30 seconds to achieve lateral movement and execute a ransom attack. The speed of attack is significantly increasing.
AI is accelerating attacks much faster than what we've seen in the past with manual attacks.
Hugging Face was just breached by an autonomous AI agent, and it carried out more than 17,000 automated actions in just a few days. The importance of security is only getting larger for all companies to minimum disruption to the business and continuing operations. So, the board needs to understand the risks that they're accepting and managing.
Cyber Security Tribe: In your opinion, what will it look like for CISOs in five to ten years?
Julie Myerholtz: In publicly traded companies, infrastructure and security are starting to merge together under one team, because infrastructure is the core of security. I think we will continue to see that trend for the operational and strategic CISOs.
Where I envision CISO's role going over time is they will own the infrastructure and security, reporting as a peer to what used to be a traditional CIO. I think the traditional CIO role is migrating to a Chief Digital Officer who will own those applications, AI, and digitalization for the company. CIOs will no longer own the infrastructure and hardware, and they work as peers together to execute against the security strategy.
You May Also Like
These Related Stories

The CISO as Fiduciary

Key Cybersecurity Statistics from the 2024 State of the Industry Report


