Who should a CISO report to?
In most Canadian companies under 500 people the CISO or vCISO should report to the CEO, with a standing line to the board or audit committee. Reporting into engineering is the arrangement that causes the most trouble later.
Report the security lead to the CEO, with a written right to address the board or audit committee at least once a quarter. That is the arrangement that survives an audit, an insurance renewal and a bad quarter. The common alternatives all have a specific failure mode: reporting into the CTO means the builder approves the assurance, reporting into the CIO buries security inside an IT budget it has to compete with, and reporting into legal turns every technical decision into a document review.
The four reporting lines, and what each one breaks
| Reports to | Works when | Fails when |
|---|---|---|
| CEO | Almost always in a company of 50 to 500. Budget conflicts get settled by the person who can settle them | The CEO has 14 direct reports and security gets 10 minutes a month |
| CTO or VP Engineering | Very early, when the whole company is one product team | An auditor tests segregation of duties, an exception needs approving, or security has to argue against a ship date |
| CIO or head of IT | The risk is mostly internal IT rather than product | Security and IT compete for the same budget and IT wins, because IT outages are visible and security debt is not |
| COO, CFO or general counsel | Regulated firms where security is one of several assurance functions, and there is an existing risk committee | The reporting line has no technical judgement in it and every decision escalates |
Why the board line matters more than the solid line
Directors owe a duty of care that they can only discharge on information they received. If the only path from the security lead to the board runs through the executive whose budget or ship date is being questioned, that information is filtered by exactly the person with a reason to filter it. The fix is small and cheap: a written statement that the security lead presents to the board or audit committee quarterly and may request time between meetings.
For a vCISO this is more important than for an employee, because a contractor has less standing to insist. Write it into the engagement. What goes into that quarterly paper is set out on reporting security to a board, and the section-by-section template is on the board report template.
The reverse case
Reporting into the CTO is not always wrong. In a 30 person product company where the entire risk surface is the product and the CTO is the only person who can direct the work, a security lead sitting outside engineering has influence and no authority to act on it. At that size, report into the CTO and add the independent line the moment an external party starts asking who approves exceptions. What you should not do is set it up that way at 150 people and hope nobody looks.
Where a vCISO sits
A vCISO is not on the org chart, so the question gets skipped. Answer it explicitly instead. The engagement letter is the only place the answer can live.
- Name the executive sponsor. One person, by name, who the vCISO escalates to and who can unblock budget.
- Write the board access down. Quarterly presentation, plus the right to request time.
- Say who approves a risk acceptance. The vCISO recommends. Someone employed by the company signs, and the signature is in the risk register.
- Say what happens on disagreement. If engineering overrules a recommendation, the recommendation and the override both get recorded rather than the disagreement evaporating in a call.
The fourth item is the one that gets left out and the one that matters during an incident review. The rest of what belongs in the agreement is on the vCISO contract checklist.
Regulated and public company differences
Federally regulated financial institutions in Canada work under OSFI Guideline B-13, which expects clear accountability for technology and cyber risk at senior management level and appropriate board oversight. In practice that pushes the reporting line towards a risk function rather than towards engineering. The detail is on vCISO work for OSFI regulated institutions.
Companies listed in the United States disclose their cybersecurity governance under Regulation S-K Item 106, including which board committee oversees cyber risk and the relevant expertise of the management people responsible. A reporting line that reads badly in a filing reads badly because it is bad. That disclosure is covered on SEC cyber disclosure for Canadian companies.
Under about 60 people there is no reporting line to design. What matters is that accountability sits with a named person, and that risk acceptances are not signed only by the person who benefits from shipping. Who owns security when there is no CISO works through the small company version, including the awkward case where the engineering lead already has the job and it is not working.
Get the reporting line right from the start
The reporting line decides how much authority the role actually has. Tell us what you need and compare providers who will tell you where they should sit.
Get matchedCommon questions
Our vCISO reports to our CTO. Is that a problem?
It is a problem when the CTO can quietly decline a recommendation without it being recorded anywhere. Fix it cheaply: keep the day to day working relationship with the CTO, and add a written line to the CEO for risk acceptances and a quarterly slot with the board. You do not need to restructure anything.
Does an auditor actually check the reporting line?
A SOC 2 or ISO 27001 auditor tests whether approvals were made by someone other than the person requesting the change, and whether management review happened. The reporting line is not itself a control, but a line that makes those two things impossible will produce findings against both.
Should the CISO attend every board meeting?
No. Quarterly is right for most companies of this size, plus attendance on demand after a material incident. A security lead in every board meeting usually signals that the board is managing rather than governing, and it burns retainer hours that would do more good elsewhere.