During congressional hearings earlier this month, senators grilled Richard Smith, the former Equifax CEO, on the company’s reporting structure for cybersecurity; specifically, on the appropriateness of Equifax’s CISO reporting to the general counsel.  This has caused several companies to question their own reporting structures for cybersecurity issues.  So what is the right structure for CISO reporting?  As usual, there is no one right or wrong answer.

We have seen many different reporting structures for CISOs … Continue Reading