Approximately 41% of companies do not have a succession plan for their CISO, according to a report from executive recruiting firm Heidrick & Struggles.
"We consider not having a CISO succession plan to be a serious material risk that companies can easily mitigate," said Matt Aiello, partner and global cybersecurity practice leader at Heidrick & Struggles.
"The lack of a successor could disrupt business-as-usual cybersecurity operations, resulting in delays, gaps in critical cyber risk management activities, and hindered cyber incident response and decision-making," Soo said.
"Lack of proper succession planning could result in disruption throughout an organization," he said.
CISO succession planning should also involve anticipating future security requirements by considering the evolving nature of the business and technology landscape.
Persons:
CISOs, Matt Aiello, Aiello, " Aiello, Daniel Soo, Soo
Organizations:
Istock, Getty, Companies, Deloitte