Industry surveys have long put CISO tenure below that of other C-suite roles, and part of the reason is a double standard. During recruitment, the focus is technical depth, security experience, and leadership. But when budget season arrives and the board weighs a leader’s performance, the lens is cost, growth, customer trust, and brand protection.
Many CISOs feel this acutely. They came up through security, or through risk and compliance, and that is where they are fluent. Their board is not. It wakes up thinking about cost, growth, and customer commitments, and a security leader who cannot connect their work to that language will be seen as important, but rarely as strategic.
Some of this comes down to how the job has been defined. For a long time, a CISO’s success has been measured by proving a negative, by showing that nothing went wrong. That is an impossible assignment, and it frames the entire function as insurance rather than a business driver.
The business is not wrong to expect this
Security plays a significant role in buying decisions. In McKinsey’s early-2026 survey of more than 3,000 enterprise technology buyers, data privacy and compliance ranked as the single most important customer concern, named by over half of respondents, and providers that fall short on security and compliance were increasingly excluded from consideration regardless of price or features. The same survey found that among buyers who switched providers in the past year, cybersecurity was the number one reason they left, ahead of price, coverage, and reliability. Trust makes or breaks the deal. And yet at most companies security is still treated as the team that slows things down, buried in a review that starts only after everyone else has agreed to move forward.
I see the same thing from the CEO seat, as a buyer and as a boss. When I talk with my own CISO, I do not ask how many alerts his team closed. I ask three things. How are you making us stronger? How are you helping us grow? And how will we recover if something goes wrong? Every CISO I know can talk about strength and recovery. Far fewer can concretely show how they enable business growth by proving trust to close deals.
Why the gap is so hard to close
So why does the daily reality still feel like overhead? Because the work underneath has not changed. Compliance keeps getting heavier. In PwC’s 2025 global compliance survey, 72% of executives said the rising complexity of compliance over the past three years had hurt their company’s profitability. Every new framework and every longer questionnaire piles on effort without obvious payoff, so teams do the only thing the calendar allows. They collect evidence once a year, answer the same questions in slightly different formats for every buyer, and move on.
This is where being secure on paper becomes a real problem. A passed audit or a clean dashboard tells you a control worked on the day someone checked it, and nothing about the rest of the year. So when a customer’s security team asks whether that control is working right now, most vendors can only say they think so. That hesitation is where the deal stalls while everyone waits for confirmation, and it can repeat across the pipeline. Buyers are not asking these questions to be difficult, either. They ask because they have watched one weak vendor turn into their own breach.
This is not about effort. These teams work hard. The problem is the design: a program built to survive an annual audit will always read as overhead, no matter how well it runs.
What strategic security actually looks like
Strategic security leaders are already positioning themselves this way. Speaking on Virtru’s Hash It Out podcast, Dave Brown (CISO of Andesite and author of “The Lean CISO”) described running security as something that should move deals rather than gate them. He sits in on sales calls. He keeps what he calls “speed dial” access to the CRO. He built an evidence library that turns security reviews that once took weeks into same-day answers. He even tells the story of a prospect whose CEO would not sign until he had spoken with the security leader directly. One conversation later, the contract was signed on the call.
Any CISO can translate that into concrete commitments. Say the board wants 50 percent growth next year. A security leader contributing to that goal might sign up for three specific things: earn the compliance certifications the company needs to sell into Europe within four months, turn customer security questionnaires around in a day instead of twelve, and be ready to meet new contractual security terms fast enough that they never hold up a negotiation. Written that way, each one reads like a growth commitment a CFO can track alongside the sales forecast. And none of it took a bigger security budget. It took pointing the same program at the outcomes the business already cares about.
From important player to strategic partner
The encouraging part is that the tools and the data to work this way already exist, and buyers are already rewarding the companies that can produce proof on demand. A security leader who can show what the program made possible, the deals it helped close and the markets it opened, walks into a very different budget conversation than one still reporting on attacks fended off.
My advice to security leaders is simple, and it is the same thing I ask of my own team. Stop letting your program be judged on the absence of bad news. Tie it to the outcomes your board already tracks, report against them transparently even when a number is ugly, and show that you are improving quarter over quarter. Do that consistently, and the business will finally see security for what it can be: one of the clearest sources of growth the leadership team has.
[ Learn more at the CISO Forum ]
