---
title: "The Cybersecurity Control You Cannot Buy"
date: "2026-09-04"
summary: "The strongest cybersecurity controls aren’t always technical; trust between the CIO and CISO can determine how effectively an organisation responds when it matters most."
canonical: "https://thepragmaticcio.net/articles/the-cybersecurity-control-you-cannot-buy/"
tags: "CIO, CISO, Cybersecurity, Leadership, Cyber Resilience, Governance, Enterprise Risk"
---

# The Cybersecurity Control You Cannot Buy

The strongest cybersecurity controls aren’t always technical; trust between the CIO and CISO can determine how effectively an organisation responds when it matters most.

![When technology, risk and business collide, trust between the CIO and CISO becomes a security control in its own right.](cybersecurity-buy.png "When technology, risk and business collide, trust between the CIO and CISO becomes a security control in its own right.")

**The worst time for a CIO and CISO to discover they don't trust each other is during a cyberattack.**

By then, the technology is almost beside the point.

The board should not be watching two executives negotiate ownership, authority and risk in real time.

**That work should have happened months earlier.**

We spend enormous amounts of money building cybersecurity controls.

Identity. Endpoint protection. SIEM. SOC. Zero Trust. Threat intelligence. AI-enabled detection and response.

All of them matter.

But there is another control sitting inside the organisation that rarely appears on an architecture diagram.

**The relationship between the CIO and CISO.**

You cannot buy it. You cannot outsource it. And you certainly cannot create it during an incident.

## Trust Doesn't Mean Agreement

There is a dangerous assumption that a strong CIO–CISO relationship means the two executives agree.

I don't think it does.

In fact, I would be slightly concerned if they agreed all the time.

The CISO's job includes challenging risk. The CIO has a broader balancing act.

Security matters, but so do availability, usability, transformation speed, architecture, cost and business outcomes.

Those priorities will sometimes collide.

They should.

A CISO might reasonably argue that a particular risk is unacceptable.

The CIO might equally reasonably conclude that eliminating that risk would impose an unacceptable operational or financial cost on the business.

Neither person necessarily has to be wrong.

The executive work is finding the right decision between them.

That requires something considerably harder to procure than another security platform.

Trust.

**Trust isn't tested when the CIO and CISO agree. It's tested when they don't.**

## Healthy Friction Is Part of the Control

I don't want a CISO who tells me what I want to hear.

I want one who tells me what I need to hear.

Sometimes those are very different things.

A good CISO should be able to walk into the CIO's office and say:

*"I think you're wrong."*

And the CIO should be secure enough to hear it.

Equally, the CISO has to accept that identifying a risk doesn't automatically determine the business decision.

Security leadership is partly about making risk visible.

Executive leadership is about deciding what to do with it.

That distinction matters.

Because once disagreement becomes political, people stop challenging each other openly.

Conversations move into separate meetings. Emails start replacing discussions. People begin documenting positions rather than solving problems.

Eventually the organisation has two technology narratives.

The CIO has one. The CISO has another.

And the CEO and board are left trying to determine which one represents reality.

At that point, the relationship itself has become a security weakness.

## The Board Should Hear One Voice

This doesn't mean hiding disagreement from the board.

Quite the opposite.

Boards should understand material differences in risk appetite and judgement.

But there is a difference between **explaining a disagreement** and **performing one**.

The CIO and CISO should have already challenged each other's assumptions before entering the boardroom.

They should understand where they agree. They should understand where they don't. And if a decision has been made, they should understand who owns it.

A board meeting should not become the first time the CIO discovers the CISO intends to escalate a concern.

Nor should it be the first time the CISO discovers that the CIO has interpreted the risk differently.

That is not healthy governance.

It is failed communication with an executive audience.

When the relationship works, the board gets something much more valuable:

Clarity.

The CISO can say:

*"This is the risk."*

The CIO can say:

*"This is the business and technology impact."*

And together they can say:

*"This is what we recommend doing about it."*

That is a much stronger conversation.

## The Incident Changes Everything

All of this becomes more important when something actually goes wrong.

During normal operations, organisational friction is inefficient.

During a cyberattack, it can be dangerous.

Decisions that normally take days may need to happen in minutes.

Do we isolate a site?

Disable an identity environment?

Take customer systems offline?

Stop manufacturing?

Invoke disaster recovery?

Inform regulators?

Communicate publicly?

Each decision can have enormous technical, financial, operational and reputational consequences.

That is not the moment to establish who trusts whom.

Nor is it the moment to discover that the CISO believes they have authority the CIO thought belonged somewhere else.

The escalation paths, decision rights and relationships need to exist already.

Technology can accelerate detection. AI can analyse enormous quantities of telemetry. Automation can isolate endpoints faster than any human.

But eventually someone has to make a decision.

And when that decision crosses technology, security and business risk, the quality of the CIO–CISO relationship suddenly becomes very tangible.

## AI Makes the Human Relationship More Important, Not Less

There is an understandable temptation to believe AI will remove some of this dependency on people.

It probably will remove a lot of operational work.

Security platforms can already correlate signals that would take human analysts considerably longer to process.

Agents will increasingly investigate, recommend and potentially execute responses automatically.

But faster machines create faster decisions.

And faster decisions increase the importance of clear human accountability.

An AI system might determine that an identity is compromised. It might recommend disabling access. It might even have authority to do so automatically.

But what happens when the affected identity belongs to a production system responsible for millions in revenue?

Or a manufacturing environment where interruption creates a physical consequence?

The technical answer and the business answer may not be identical.

AI can provide evidence. It can recommend. It can execute within boundaries.

**It cannot manufacture executive trust at the moment you need it.**

That work remains stubbornly human.

## The CISO Cannot Carry Cyber Risk Alone

There is another reason this relationship matters.

CISOs are frequently given accountability that exceeds their authority.

They're expected to protect an organisation whose technology they don't entirely control, whose budgets they don't entirely own and whose business decisions they cannot entirely dictate.

Then something goes wrong and everyone asks:

*"How did security allow this to happen?"*

That's not a sustainable operating model.

Cyber risk belongs to the organisation.

The CISO helps identify, quantify and manage it.

But the business ultimately accepts it.

The CIO has an important role in ensuring that distinction survives contact with reality.

A strong CIO doesn't use the CISO as organisational insurance.

And a strong CISO doesn't attempt to transfer every difficult technology decision into a security veto.

Both behaviours destroy trust.

The relationship works when both understand that they're carrying different parts of the same problem.

## The Trust Test

So how do you know whether the relationship actually works?

Not by asking whether the CIO and CISO get along.

That's friendship.

I'm interested in whether the relationship performs under pressure.

I'd use five questions.

### Can we disagree?

Can the CISO challenge the CIO directly without worrying about political consequences?

Can the CIO challenge the CISO's assessment without being accused of ignoring security?

If disagreement isn't safe, important information eventually gets filtered.

### Can we decide?

When the clock is running, does everyone know who has authority?

Consultation is valuable. Ambiguity isn't.

A crisis is a terrible time to discover that five people believe somebody else owns the decision.

### Can we escalate?

Can either leader take a material concern to the CEO, executive team or board when necessary?

Escalation should not be interpreted as betrayal.

Sometimes it is governance working exactly as intended.

### Can we stand together?

Once a decision has been made, can both leaders explain it consistently to the organisation?

That doesn't require pretending disagreement never existed.

It requires clarity about the decision and who owns it.

### Can we take the blame together?

This may be the hardest test.

When something goes badly wrong, does the first conversation become:

*"How do we solve this?"*

Or:

*"Whose fault is this?"*

Blame destroys information flow precisely when the organisation needs honesty most.

People who expect punishment start protecting themselves.

People who trust each other start solving the problem.

That difference can determine how an incident unfolds.

## Build the Relationship Before You Need It

None of this requires the CIO and CISO to spend every day together.

There is no magic meeting cadence.

Different organisations, personalities and operating models require different rhythms.

What matters is that communication is frequent enough that neither executive is surprised by the other's thinking.

The relationship should exist outside incidents.

Talk about architecture. Talk about business priorities. Talk about investment. Talk about where security is creating friction. Talk about where technology is creating unnecessary risk.

And occasionally talk about something that has nothing whatsoever to do with cybersecurity.

Trust accumulates through repeated interactions.

By the time the major incident arrives, there should be very little left to negotiate about the relationship itself.

## The Pragmatic View

Cybersecurity has become extraordinarily sophisticated.

We have better telemetry. Better automation. Better threat intelligence. Better identity controls. Better detection.

And increasingly, better AI.

We should continue investing in all of them.

But technology cannot compensate indefinitely for executive dysfunction.

If the CIO and CISO don't trust each other, every governance process between them becomes slower. Every disagreement becomes more political. Every escalation becomes more dangerous.

And every incident becomes harder than it needed to be.

The strongest CIO–CISO relationships aren't the ones without friction.

They're the ones where friction doesn't destroy trust.

Where challenge is expected.

Where authority is understood.

Where risk can be discussed without theatre.

And where, when something genuinely serious happens, neither executive has to wonder whether the other one is standing beside them.

We spend millions building cybersecurity controls.

Perhaps one of the most important costs nothing to purchase.

It just takes considerably more work to build.

**If your CIO and CISO seriously disagreed during a major cyber incident tomorrow, would the relationship make the decision easier—or become another problem you had to solve?**
