Because knowing "AI discovery matters" is not a strategy.Sitecore acquires Scrunch
Because knowing "AI discovery matters" is not a strategy.Sitecore acquires Scrunch
Skip to main content
Sitecore
Request a demo

Search

Request a demo

The CISO community and the burden of risk

By Heather Hinton.

5 minute read

Every day, companies make decisions about what customers see, what data is used, and what actions are triggered automatically. A lot of that now happens through digital experience platforms, and increasingly, through AI. At Sitecore, we build the software global brands use to manage content, personalize experiences, and automate those interactions at scale.

That’s the backdrop for my job. And as AI becomes more powerful, the expectations placed on security leaders have shifted fast, often faster than many organizations are ready for.

I’m writing this after RSA 2026 because the conversations I had there put that shift into sharp focus. I’ve been to RSA at different points in my career, but becoming a CISO changed what the conference is useful for. It stopped being about learning what’s new and started being about connections and alignment. How we communicate risk and speak the language of the business, too.

This post is about that reality, why the role feels different now, and why the CISO community has become essential to doing the job well.

The isolation of ownership

There has always been a feeling of loneliness in the CISO position, but I believe it has intensified over the last decade. This is largely due to the elevation of the CISO to a business partner and “communicator of risk,” coupled with an increasing risk landscape and an often-misaligned assumption of ownership over that risk.

This and other realities faced by CISOs were addressed in the RSA panel I contributed to.

As a community, we need to get better at "business speak" — articulating risk in terms the board and other executives understand; and business partners need to get better at “cybersecurity listen.” Executive leaders need to understand that the cybersecurity landscape is fundamentally changing. To use the phrase, “what got us here (in terms of security practices) will not get us there (successfully defending in the age of AI and increasing nation-state activity)".

CISOs need to understand that their job is to advise, not to own the business decision or the ultimate risk. When we internalize the potential negative impact of the “what can go wrong” results in a business decision, we increase our mental and emotional stress. It’s this cognitive dissonance — operating in ways that sometimes conflict with our core security beliefs — that is a primary driver of burnout. We owe it to ourselves not to carry this stress.

Participating in conferences such as RSA is a critical way for the shared security leadership community to share information and build resilience to be effective security leaders and business partners.

"CISO-ing" & stakeholder communication cheat sheet

The advisory role of the CISO is not a simple one-to-one relationship. It requires navigating complex, customized conversations with multiple stakeholders across the organization. One of the things that makes “CISO-ing” so challenging and fun is understanding all parts of a business. As CISOs move to a more technical-business advisory and partnership role, one thing that we need to understand is how to partner with different stakeholders.

As a simple cheat sheet (take and customize for your organization), consider the following:

Stakeholder Primary Business Objective Business Speak: How to deliver the message Cybersecurity Listen: How we want the message to land
Legal Regulatory compliance, avoiding fines Addressing these security issues reduces the potential impact of legal exposure and non-compliance penalties. The likelihood of regulatory fines and penalties is increased if we don’t address these issues now
Head of Engineering, CTO Rapid product development and time-to-market Addressing these security issues reduces the potential (outsized?) negative impact on customers, trust, and long-term development stability. The likelihood of releasing an insecure or “broken” product is increased if we don’t address these issues now
COO / Operations Efficiency and streamlined processes Addressing these security issues reduces the potential of (security-related) operational disruption, downtime, and resource drain from incident response. The likelihood of inefficiency due to rework is increased if we don’t address these issues now

 

CISOs must meet their colleagues where they are. In a large organization, this means having many conversations, tailoring the message to each person’s business objectives, and ensuring they understand the “why” behind our recommendations. (This is very appropriate at a company like Sitecore, where we build technology to help marketers deliver the right message for the right person at the right time.)

The CISO community is crucial for exchanging strategies on how to effectively communicate these risks and bring the business along on the security journey. I’m lucky to do this at Sitecore surrounded by a team who sees my role and trust as central to the very products we build.

You may also like

Platform

  • Platform overview
  • Content Management System
  • Digital Asset Management
  • Content operations
  • Conversion optimization
  • Audience and insights
  • Commerce
  • Experience Manager (XM)
  • Experience Platform (XP)
  • Connect
  • Send

Solutions

  • Product strategy
  • Modernize your DX
  • Manage global content
  • Deliver limitless commerce
  • Optimize with data
  • All Customer Stories
  • All Experience Awards
  • All Analyst Reports
  • Sitecore Symposium

Resources

  • Thought leadership
  • Use case libraryNEW
  • Resource Hub
  • Insights
  • Events & Webinars
  • Trust Center
  • Support

Services

  • Managed Cloud
  • Sitecore Services
  • Sitecore360
  • Sitecore Learning
  • AI Innovation Lab

Company

  • About Us
  • Contact us
  • Newsroom
  • Careers
Sitecore Corporate Logo
envelope-regular.svglinkedin-in.svgx-twitter.svgfacebook-f.svginstagram.svgyoutube.svg

© Copyright 2026, Sitecore A/S or a Sitecore affiliated company. All rights reserved.

  • Cookie settings
  • Legal Hub
  • Privacy
  • Your privacy choices
  • webmaster@sitecore.net