CISO role in Europe and Switzerland: Governance Part 5/5

The new CISO leadership role is the result of tighter regulation, rising board-level attention and increasing pressure on resource allocation. According to the PwC Global Digital Trust Insights 2025, only one in six companies in Switzerland allocates cyber budgets in a truly risk-based manner, which clearly indicates that governance and financial accountability still often remain insufficiently connected.

Why the final note: the CISO leadership role as a bridge-builder between risk, law and finance

In this fifth and final part of our series, we summarise the key findings and provide practical recommendations for boards of directors, executive management and CISOs. The facts are clear: CISOs are far more present in board meetings (according to the CISO Report 2025, 83% of European CISOs regularly attend board sessions). At the same time, many boards still lack dedicated cyber specialists. Consequently, a practical problem follows: budget decisions are often still made without systematically involving those responsible for security (PwC Switzerland).

Concrete recommendations for the board of directors to strengthen the CISO leadership role

The board of directors must understand cyber risks as a strategic business risk and set the conditions in which the CISO can act effectively, thereby anchoring the CISO leadership role where it belongs.

1. Clear reporting line and mandate: Formally embed the CISO function in governance (direct reporting to the CEO or a board committee). Swiss examples, such as the direct reporting path at SMG Swiss Marketplace Group (Swiss CISO Awards / SMG), show how transparency and decision speed increase when the reporting line is short. That clarity also stabilises the CISO leadership role.

2. Complement board capabilities: Ensure that the board of directors has cyber and IT risk expertise, if necessary through external advisers or dedicated committees. According to the CISO Report, only 29% of boards have this expertise. As a result, governance gaps open up, and the CISO leadership role cannot deliver its full impact.

3. Demand risk-based budget approvals: Require management and the CISO to present a risk-based budget model with clear KPIs. The PwC analysis shows that risk-based allocation remains rare in Switzerland. Therefore, the board should actively use this lever (PwC Global Digital Trust Insights 2025). This is also a core test of the CISO leadership role.

Recommendations for CEO, CFO and CISO: operationalise collaboration in the CISO leadership role

The interfaces between CISO and CFO, and between CISO and Legal, often become friction points. However, practical measures reduce losses and strengthen the CISO leadership role in day-to-day operations:

1. Define business metrics for cyber investments: CFOs and CISOs should agree on shared KPIs (for example expected loss reduction, Mean Time to Recovery, cost per incident). Only then can organisations evaluate cyber measures properly in the budget process. This directly addresses a central finding of the PwC study and it clarifies the value of the CISO leadership role.

2. Standard operations: monthly finance to security reporting: Short, standardised reports for the CFO and controlling (costs, Service Level Agreement fulfilment, third-party risks) create transparency and, consequently, prevent surprises.

3. Involve Legal early, not only during incidents: Collaboration with the legal department is not an afterthought. New notification duties under NIS2/DORA and the revised Swiss Data Protection Act require continuous alignment (see the regulatory overview by Baggenstos). In practice, this early coordination makes the CISO leadership role more credible at executive level.

Operational guardrails: governance, third-party risk and resilience tests

Regulatory requirements (DORA, NIS2, FINMA circulars) impose specific duties. Therefore, companies should prioritise the following measures, and they should frame them clearly within the CISO leadership role:

1. Introduce an ICT risk management framework: Implement a framework that unifies governance, risk assessment, KRIs and reporting. DORA requires such structures for financial institutions from 2025, while NIS2 brings extensive reporting and supply-chain duties (Baggenstos, 2024).

2. Operationalise Third-Party-Risk-Management: Supply-chain risks sit at the core of NIS2/DORA. Standardised third-party assessments, dynamic risk-scoring models and contractual Service Level Agreements belong in the obligation catalogues of governance and procurement. As a result, the CISO leadership role gains measurable leverage beyond the security team.

3. Run resilience and tabletop tests regularly: Tests of Incident Response capability, including communication chains to the board, the CFO and the legal department, must follow a defined plan. The European implementation of DORA increases expectations for documented tests and evidence. Consequently, the CISO leadership role must treat testing as a management discipline, not as an ad hoc exercise.

Practical examples: what works in Switzerland

The Swiss CISO Awards and 2024 case examples show how implementation can succeed, and they illustrate the CISO leadership role in action:

Logitech (Tana Dubel): A Zero Trust approach, ISO 27001 certification and close board integration led to stronger resilience and better compliance. This is a model for how governance, technical measures and diversity interact (Swiss CISO Awards / Logitech).

SMG Swiss Marketplace Group (Mostafa Hassanin): Direct reporting to executive management, the introduction of KRIs and close alignment with Legal improved transparency and decision processes. This shows how reporting standards can be implemented operationally (Swiss CISO Awards / SMG), and it reinforces the CISO leadership role as a governance function.

Fact overview: verifiable key points

– 83% of European CISOs regularly attend board meetings, while only 29% of boards have cyber expertise (CISO Report 2025), 2024.
– Only 1 in 6 Swiss companies allocates cyber budgets on a risk basis (PwC Global Digital Trust Insights 2025), July 2024.
– DORA enters into force for financial institutions from 2025, and requirements for ICT risk management, resilience tests and notification duties are binding (Baggenstos, 2024).

Conclusion: what to do now

The role of the CISO has evolved from a purely technical function into an integrated leadership task. Governance anchoring, clear financial accountability and close collaboration with the CFO and Legal are no longer optional. They are prerequisites for regulatory compliance and operational resilience. Organisations that delay these steps risk high regulatory and economic costs. If you want to professionalise the CISO leadership role with external support, you can reach TECHWAY via contact.

CISO practice: next steps (checklist)

– Formally anchor the CISO role in governance (reporting to the CEO or a board committee), and define the CISO leadership role unambiguously.
– Demand a risk-based budget model with clear KPIs (CFO involvement), therefore linking spend to outcomes.
– Implement an ICT risk management framework in line with DORA/NIS2, and document it consistently.
– Operationalise third-party risk assessments and contractual Service Level Agreements, consequently reducing supply-chain exposure.
– Conduct regular resilience and tabletop tests and report the results to the board and Legal, so decision-makers can act quickly.

Further sources and reading tips

For deeper reading and implementation support, we recommend: PwC Global Digital Trust Insights 2025, the CISO Report 2025 (Bitkom / Splunk), as well as the regulatory overview by Baggenstos. For Swiss practice examples, the reports on the Swiss CISO Awards 2024 provide useful reference points for the CISO leadership role.

Key takeaway: act now

The board of directors and executive management must anchor the CISO function strategically. Furthermore, the CFO and CISO should establish joint reporting that stands up to financial scrutiny, while Legal should be involved early. European regulation (DORA, NIS2) makes these steps urgent. The question is no longer whether a company needs a CISO, but how it governs, funds and legally safeguards the CISO leadership role.

Security Ratings: What Your Company Score Really Says
Coro Cybersecurity Platform: Replace Six Tools with One Solution
TECHWAY - CISO leadership role

Send us a message!

Fill out this field
Fill out this field
Please enter a valid email address.
Fill out this field

By: