From the Boston Leadership Exchange.For years, security leaders have debated whether the CISO should report to the CIO, the CEO, legal, or somewhere else entirely. At the Boston Leadership Exchange, two executives responsible for making that relationship work argued the reporting line is far less important than the operating model behind it.Salumeh “Sal” Companieh, chief digital and information officer at Cushman & Wakefield, and Erik Hart, the company’s chief information security officer, shared how they’ve built security into the business, where they’ve stumbled, and what they’ve learned about aligning technology and security leadership at enterprise scale.Hart reports to Companieh, but both were quick to dismiss reporting structure as the determining factor.”There was no gating factor between the CISO role and the CIO role,” Companieh said. “That was a non-negotiable for us.”Instead, they pointed to five practices that have made the partnership effective.
Access matters more than the org chart
Companieh presents to the board roughly quarterly, while Hart presents twice a year. Those presentations belong to him.”I am on the call should there be any questions,” Companieh said. “But the communication is Erik’s.”Hart also maintains direct relationships with business leaders, the general counsel and the CFO. He argued there is no universal reporting model for CISOs. Some organizations are best served by having security report through legal, others through technology. What matters is whether security has the independence and executive access necessary to influence decisions.”If you report into technology, how are you building peer relationships across the business?” Hart asked. “If you report outside of technology, how are you building them back into technology?”In seven years at Cushman & Wakefield, he said, no technology initiative has ever been put into production over a security objection.
Security became part of how the business operates
Cushman & Wakefield’s environment presents unique challenges. The company supports more than 53,000 employees across 350 offices in roughly 60 countries, yet many employees work inside client facilities using client-owned technology. More than 10,000 employees receive no corporate-managed endpoint at all.”Security becomes their identity,” Hart said.The complexity extends well beyond technology. Roughly half the workforce is hourly, many employees are unionized, and a significant percentage speak English as a second language.Rather than relying on security reviews at the end of projects, the company embedded security into its operating model. Every new application, technology purchase or architecture change requires cyber risk and architecture review before moving forward.Getting there wasn’t immediate.”It took about 18 months,” Companieh acknowledged, before the process became part of the organization’s culture.The company also pairs every product and operations team with dedicated cyber counterparts, creating shared accountability rather than treating security as an external approval function.
Business metrics resonate more than security metrics
The executives said they intentionally avoid measuring success through traditional security activity metrics.Instead, they focus on outcomes the business already understands.Among the measures they track are year-over-year reductions in cyber insurance costs, improvements in external security posture through NIST-based assessments and independent scanning, and the speed at which security teams can support customer RFPs.That last metric has become particularly important.Responding quickly to customer security questionnaires helps the business close deals faster, making security a contributor to revenue rather than simply a control function.
Understanding the business changes security conversations
Companieh argued one of the highest-return investments security organizations can make has little to do with technology.”If you are not running your cyber team through storytelling training,” she said, “I would call that a key investment that you can make.”Early on, security teams often entered conversations focused on explaining why something couldn’t be done. That changed after security personnel spent time observing employees in the field.Hart recalled visiting a Boston site where the first thing a user told him was how much she disliked multi-factor authentication.Rather than dismissing the complaint, his team watched how she worked: constantly switching between applications on unmanaged client devices and repeatedly authenticating throughout the day.The result wasn’t weaker security. It was a secure single sign-on experience designed specifically for that workflow.”Don’t sell it as security,” Hart said. “This is about what they’re going to feel.”The company applies the same philosophy to employee education. The executive responsible for teaching employees how to use tools such as Microsoft Copilot, Claude and Workday also oversees security awareness, allowing security guidance to become part of day-to-day digital training rather than a standalone annual requirement.
Security identifies risk. The business owns it.
Perhaps the most important principle the two executives described was separating risk transparency from risk ownership.Board reporting has evolved through several iterations and now maps security programs directly to the business functions and revenue they protect.”It’s not Erik or I,” Companieh said. “It’s the enterprise.”Security’s role is to explain business risk clearly enough for executives to make informed decisions—not to make those decisions on behalf of the business.”We’re there to bring transparency to the risk,” she said, “not to either accept it or decline it.”That same philosophy extends to incident reviews. Following significant security events, the company shares complete retrospectives with the board, including what happened, how different business functions responded, what will change and how external technology partners performed.Companieh acknowledged that level of transparency requires an organizational culture willing to hear difficult conversations.
Moving at AI speed
Asked how security keeps pace with rapidly evolving AI technology, Companieh said the company has compressed its decision-making timelines dramatically.A recent enterprise AI rollout — from initial concept through licensing, deployment planning and architecture — took roughly 36 days.Every deployment undergoes an AI readiness assessment that evaluates not only the technology but whether the requesting business unit is prepared to use it responsibly.Supporting that effort is a dedicated innovation team that monitors emerging technologies and venture capital investment trends while working closely with learning and development. The company’s technology, product, security and service leaders also share a common communication channel to discuss emerging developments.”I don’t have a perfect answer,” Companieh said. “Other than overcommunicate.”When restrictions become necessary, however, they come from business leadership — not IT.Policy changes affecting employees are communicated by the CEO or business president rather than the technology organization.
People still matter most
Hart closed the session with a reminder that cybersecurity leadership remains a human profession despite its increasingly technical focus.Both executives said they spend significant time supporting their teams’ well-being and maintaining perspective in roles that rarely slow down. For them, the effectiveness of the CIO-CISO relationship ultimately comes down to trust — not reporting lines, governance models or organizational charts.
