The Power of Partnerships Between CISOs and Their Boards

CISOs have officially arrived in the C-Suite, and it is safe to say we’re working more closely with our boards than ever before. Eighty-two percent of CISOs interact directly with the CEO*, and 83% participate in board meetings somewhat often or most of the time. Splunk’s annual CISO Report deep dives into how we are getting a more prominent seat at the table and where CISOs can have more influence over budget and policy, and boards have more insight into the organization’s security posture.

The good news is that we’re in sync with our boards on some of the issues that matter most. We agree on the importance of protecting sensitive information and the need to hone and grow our leadership skills.

But, like any budding relationship, we’re still figuring each other out. Perhaps not surprisingly, there are still a few growing pains as CISOs expand into the role of business leaders. For example, when it comes to setting strategic goals for the security program, 61% of CISOs called their relationship with the board very good to excellent, compared to only 43% of boards who characterize the relationship in such glowing terms.

But it doesn’t have to be that way. This year’s CISO Report illuminates some of the gaps between CISOs and their boards, as well as best practices that will help CISOs reach across the aisle and accomplish their goals while also gaining the board’s trust.

Bridging the CISO-Board Divide of Priorities, Skills, and KPIs

When the relationship is built on a foundation of misaligned priorities, CISOs and boards will likely end up further apart if they continue the same trajectory.

Many current divisions can be attributed to boards and CISOs having very different backgrounds. As technologists at heart, 58% of CISOs say the bulk of time we and our teams spend goes into choosing, installing, and operating technology. In contrast, 52% of boards believe we spend our days enabling the business. And although CISOs say the impact of security incidents is the best measure of their success, boards are gauging us by the ROI of our security investments.

So, how do CISOs narrow these divides? If we want to earn the board’s confidence and trust, we have to consider how our priorities, goals, and time relate to revenue and business objectives. We’ll have to take it upon ourselves to educate our boards on how security metrics benefit the business. By doing so, we’ll be able to articulate how our security objectives fit into the greater mission and get the resources and support we need.

Why Speaking “Board” Will Help Secure Budget

Of the most valuable skills for CISOs to develop, the ability to solicit adequate budget tops the list. Only 29% of CISOs say they receive enough funding for initiatives and goals. And we’re concerned — perhaps rightly so — given how budget shortfalls affect our ability to protect our organizations. This is an opportunity to position cybersecurity initiatives as something that enables the business and drives it forward.

Boards reported that they prioritize business growth, even over improved cybersecurity posture. That means CISOs need to think beyond risk metrics and dive deeper into how a solution will benefit the broader business. It means articulating the potential or inevitable costs of not implementing a security solution or best practice. Our report details ways CISOs can better champion security budgets and reframe their efforts into ROI that lands well with their boards.

In many ways, CISOs don’t have a choice. Cutbacks, even small ones, can have significant consequences. For example, 18% of CISOs revealed they were unable to support a business initiative because of budget cuts in the last 12 months, and 64% said that lack of support led to a cyber attack.

The Benefits of a Strong CISO-Board Relationship

But fret not. There is a clear pathway to success. When CISOs take the time to build strong relationships with their boards, the results can be magical. For example, CISOs who report having a good relationship with their board see many benefits vs. those who do not, including:

Like any relationship, nurturing will help it flourish. As CISOs, we need to manage up rethink approaches so we can tackle new challenges and make strides in innovation together.

Get your copy of Splunk’s CISO Report to learn more about which gaps CISOs are experiencing with their boards and how they can come together and build strong relationships that reap tangible benefits.

*This report has been updated on February 21, 2025. The data point of '82% of CISOs report directly to the CEO’ has been clarified and revised to reflect: ‘82% of CISOs interact directly with the CEO.' The previous version also used a data point from 2023 that was not applicable.

Related Articles

Security Predictions 2026: What Agentic AI Means for the People Running the SOC
Leadership
10 Minute Read

Security Predictions 2026: What Agentic AI Means for the People Running the SOC

Splunk's Hao Yang shares our security predictions for 2026 and how agentic AI is reshaping how we see the SOC.
The Performance Playbook: Why Business Context Is the Key to Customer-Centric Visibility
Leadership
4 Minute Read

The Performance Playbook: Why Business Context Is the Key to Customer-Centric Visibility

Systems show symptoms. Business context shows impact. Discover why the future of observability is understanding what matters most to your customers.
MachineGPT, Agentic AI, and the New Foundation for Digital Resilience
Leadership
4 Minute Read

MachineGPT, Agentic AI, and the New Foundation for Digital Resilience

MachineGPT is foundational to the rise of Agentic AI in the enterprise, which is poised to fundamentally reshape digital operations – and it's advancing faster than we expected.
MachineGPT: Speaking the Language of Machines to Shape the Future of AI
Leadership
4 Minute Read

MachineGPT: Speaking the Language of Machines to Shape the Future of AI

MachineGPT brings the power of generative AI to one of the most overlooked resources: machine data. Splunk SVP & GM Kamal Hathi explains why mastering data as the heartbeat of the digital world is a game changer.
Powering and Protecting the AI Revolution: A New Era for Splunk and Cisco at .conf25
Leadership
3 Minute Read

Powering and Protecting the AI Revolution: A New Era for Splunk and Cisco at .conf25

Splunk's Kamal Hathi recaps our innovation highlights from .conf25, marking a pivotal moment for Splunk and Cisco as we deliver significant new value to our customers that make the use of AI a practical reality in their organizations.
Machine Data: Fighting Fire With Fire for Digital Resilience
Leadership
2 Minute Read

Machine Data: Fighting Fire With Fire for Digital Resilience

Kamal Hathi shares how Cisco and Splunk are helping organizations manage the explosion of machine data and AI-driven complexity, delivering real-time digital resilience to counter threats at machine speed and scale.
.conf25: Reinventing Digital Resilience for the Agentic Era
Leadership
3 Minute Read

.conf25: Reinventing Digital Resilience for the Agentic Era

Kamal Hathi shares how Cisco and Splunk deliver the data foundation, agentic intelligence, and cross-domain insights needed to build a more secure, resilient, and always-on digital enterprise.
UK Needn’t Fear The Data Deluge
Leadership
4 Minute Read

UK Needn’t Fear The Data Deluge

UK businesses face a data explosion—fueling growth but also raising risks in security, compliance, and operations. With smart data management strategies, organisations can regain control, boost resilience, and turn data into a true competitive edge.
Digital Resilience By Design: Seamless Troubleshooting Across Splunk & Cisco
Leadership
7 Minute Read

Digital Resilience By Design: Seamless Troubleshooting Across Splunk & Cisco

Cisco and Splunk deliver Digital Resilience by Design with seamless troubleshooting across security, observability, and networking domains, powered by AI innovations to manage complexity and stay ahead of risk.