"Perfect is the Enemy of Good": The CISO's Role in Enterprise Security as a Business Enabler
Kimberly Ruth, Veronica A. Rivera, Gautam Akiwate, Aurore Fass, Patrick Gage Kelley, Kurt Thomas, Zakir Durumeric
Abstract
Chief Information Security Officers (CISOs) are responsible for setting and executing organizations’ information security strategies. This role has only grown in importance as a result of today’s increasingly high-stakes threat landscape. To understand these key decision-makers, we interviewed 16 current and former CISOs to understand how they build a security strategy and the day-to-day obstacles that they face. Throughout, we find that the CISO role is strongly shaped by a business enablement perspective, driven by broad organizational goals beyond solely technical protection. Within that framing, we describe the most salient concerns for CISOs, isolate key decision-making factors they use when prioritizing security investments, and surface practical complexities and pain points that they face in executing their strategy. Our results surface opportunities to help CISOs better navigate the complex task of managing organizational risk, as well as lessons for how security tools can be made more deployable in practice.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get a05dd43b-a355-4d3c-be7a-c8bbc14ebb64Cited by top-tier papers2
- Hop: A Modern Transport and Remote Access ProtocolPaul Flammarion, George Hosono, Wilson Nguyen, Laura Bauman et al.USENIX Security 2026
- A First Look at Governments' Enterprise Security GuidanceKimberly Ruth, Raymond Buernor Obu, Ifeoluwa Shode, Gavin Li et al.USENIX Security 2025
Related papers
- Security Obstacles and Motivations for Small Businesses from a CISO's PerspectiveFlynn Wolf, Adam J. Aviv, Ravi KuberUSENIX Security 2021 · 18 citations
- "Where Are We On Cyber?" - A Qualitative Study On Boards' Cybersecurity Risk Decision MakingJens Opdenbusch, Jonas Hielscher, M. Angela SasseNDSS 2025
- "Cyber security is a dark art": The CISO as SoothsayerJoseph Da Silva, Rikke Bjerg JensenCSCW 2022 · 25 citations
- "Employees Who Don't Accept the Time Security Takes Are Not Aware Enough": The CISO View of Human-Centred SecurityJonas Hielscher, Uta Menges, Simon Parkin, Annette Kluge et al.USENIX Security 2023
- How Does Usable Security (Not) End Up in Software Products? Results From a Qualitative Interview StudyMarco Gutfleisch, Jan H. Klemmer, Niklas Busch, Yasemin Acar et al.S&P 2022 · 51 citations
