Report by Splunk

The CISO Report 2025

33 FINDINGSPublished Jan 1, 2025
View Original Report →

Key Findings

79% of CISOs say KPIs for their security teams have changed substantially over recent years.

SplunkThe CISO Report 2025·Jan 1, 2025
CISOKPIs

Cost-saving measures reported by CISOs include reduced security solutions and tools (50%), security hiring freezes (40%), and decreased or eliminated security training (36%).

SplunkThe CISO Report 2025·Jan 1, 2025
CISOCost-cuttingToolsStaffTraining

82% of security leaders report directly to the CEO in 2024, which is up from 47% in 2023.

SplunkThe CISO Report 2025·Jan 1, 2025
CISOCEO

51% of CISOs see upskilling or reskilling security employees as a priority, versus 27% of boards.

SplunkThe CISO Report 2025·Jan 1, 2025
BoardCISOUpskillingReskilling

36% of CISOs consider contributing to revenue growth initiatives a priority compared to 24% of board members.

SplunkThe CISO Report 2025·Jan 1, 2025
BoardCISORevenue

46% of CISOs said attaining security milestones was indicative of their success, compared to only 19% of board respondents.

SplunkThe CISO Report 2025·Jan 1, 2025
BoardCISO

18% of CISOs revealed they were unable to support a business initiative because of budget cuts in the last 12 months.

SplunkThe CISO Report 2025·Jan 1, 2025
CISOBudget

59% of CISOs said they would become a whistleblower if their organisation was ignoring compliance requirements.

SplunkThe CISO Report 2025·Jan 1, 2025
CISOComplianceWhistleblower

64% of CISOs said that lack of support led to a cyberattack.

SplunkThe CISO Report 2025·Jan 1, 2025
CISOSupport

21% of CISOs revealed they had been pressured not to report a compliance issue.

SplunkThe CISO Report 2025·Jan 1, 2025
CISOComplianceReporting

83% of security leaders participate in board meetings "somewhat often" or "most of the time".

SplunkThe CISO Report 2025·Jan 1, 2025
CISOBoard

64% of CISOs reveal that the current threat and regulatory environment make them concerned they’re not doing enough.

SplunkThe CISO Report 2025·Jan 1, 2025
CISOComplianceRegulatory

CISOs with good board relationships are more likely to be given the ability to pursue use cases for generative AI, such as creating threat detection rules (43% versus 31% of other CISOs), analyzing data sources (45% versus 28% of other CISOs), incident response and forensic investigations (42% versus 29% of other CISOs), and proactive threat hunting (46% versus 28% of other CISOs).

SplunkThe CISO Report 2025·Jan 1, 2025
BoardCISOGen AI

57% of CISOs prioritize regulation and compliance knowledge, compared to 44% of board members.

SplunkThe CISO Report 2025·Jan 1, 2025
BoardCISORegulationCompliance

29% of CISOs say they receive the proper budget for cybersecurity initiatives, compared to 41% of board members who think cybersecurity budgets are adequate.

SplunkThe CISO Report 2025·Jan 1, 2025
CISOBoardBudget

More board members than CISOs want CISOs to develop certain skills: Business acumen: 55% of board members vs 40% of CISOs, emotional intelligence: 45% of board members vs 35% of CISOs, Communication: 52% of board members vs 47% of CISOs.

SplunkThe CISO Report 2025·Jan 1, 2025
BoardCISO

52% of CISOs consider innovating with emerging technologies a priority, compared to 33% of board members.

SplunkThe CISO Report 2025·Jan 1, 2025
BoardCISOEmerging tech

53% of CISOs say their responsibilities and job expectations have become more difficult since they took the job.

SplunkThe CISO Report 2025·Jan 1, 2025
CISOResponsibilities

15% of CISOs ranked compliance status as a top performance metric, compared to 45% of boards.

SplunkThe CISO Report 2025·Jan 1, 2025
BoardCISOCompliance

18% of CISOs claimed they were unable to support a business initiative due to budget cuts in the past year, and 64% said that lack of support led to a cyberattack.

SplunkThe CISO Report 2025·Jan 1, 2025
CISOBudget

Only 29% of CISOs say their board includes at least one member with cybersecurity expertise.

SplunkThe CISO Report 2025·Jan 1, 2025
BoardCISO

When there is a CISO on the board, 80% of boards report excellent or very good working relationships with CISOs in setting and aligning on strategic cybersecurity goals, versus 27% when there isn't a CISO on the board.

SplunkThe CISO Report 2025·Jan 1, 2025
BoardCISO

For boards with a CISO member, 60% report excellent or very good working relationships when communicating progress against milestones, security goal achievement and plan of record, compared to 16% for boards without a CISO member.

SplunkThe CISO Report 2025·Jan 1, 2025
BoardProgressCISO

More board members than CISOs want CISOs to develop certain skills: Business acumen: 55% of board members vs 40% of CISOs, emotional intelligence: 45% of board members vs 35% of CISOs, Communication: 52% of board members vs 47% of CISOs.

SplunkThe CISO Report 2025·Jan 1, 2025
BoardCISO

50% of boards with a CISO member report excellent or very good relationships when budgeting adequately to meet goals, compared to 24% for boards without a CISO member.

SplunkThe CISO Report 2025·Jan 1, 2025
BoardBudgetCISO

60% of board members acknowledge that board members with cybersecurity backgrounds more heavily influence security decisions.

SplunkThe CISO Report 2025·Jan 1, 2025
BoardDecision-making

Board members with a CISO background report stronger relationships with security teams and feel more confident about the organisation’s security posture.

SplunkThe CISO Report 2025·Jan 1, 2025
BoardCISO

37% of board members with a CISO background express concern that they are not doing enough to protect the organisation, compared to a survey average of 62%.

SplunkThe CISO Report 2025·Jan 1, 2025
BoardCISO

29% of CISOs say they receive adequate budget to accomplish their goals, compared to 41% of board members who think the function has enough funds.

SplunkThe CISO Report 2025·Jan 1, 2025
BoardCISOBudget

CISOs with healthy board relationships report stronger partnerships with IT operations (82% versus 69% of other CISOs) and engineering (74% versus 63% of other CISOs).

SplunkThe CISO Report 2025·Jan 1, 2025
BoardCISO

When asked what skills CISOs should develop, the biggest gaps in importance include business acumen (55% for boards versus 40% for CISOs), emotional intelligence (45% for boards versus 35% for CISOs) and communication (52% for boards versus 47% for CISOs).

SplunkThe CISO Report 2025·Jan 1, 2025
BoardCISO

94% of CISOs report being victims of a disruptive cyberattack, with 55% experiencing them at least a couple of times, and another 27% experiencing them many times.

SplunkThe CISO Report 2025·Jan 1, 2025
CISOCyber attackMultiple attacks

Strategic CISOs earn 57% more than Functional CISOs and twice as much as Tactical CISOs.

SplunkThe CISO Report 2025·Jan 1, 2025
CISO