The growing case for deputy CISOs in the enterprise
Cybersecurity teams need a leader -- or do they need two? As the pressures on security professionals grow, the deputy CISO role has become a bigger topic of conversation.
The unrelenting burdens CISOs face are well understood and have spurred greater interest in the deputy CISO role.
In some situations, the appointment of a deputy CISO is seen as a way to share the management workload and to stabilize security in organizations that -- especially to those inside them -- never seem properly staffed.
"It's starting to get more traction because of the burnout and how many people are leaving," said Shawn Murray, president of Murray Security Services and former president of Information Systems Security Association.
Naming a deputy CISO is a complicated decision, and there's no standard for what the position might entail. Each organization defines the scope of the job as it sees fit. At some businesses, the deputy role might enable a CISO to become a more proactive risk manager with more time to engage with leaders at the executive and board levels. Other organizations might consider a deputy as part of succession planning for the top job.
While the deputy CISO role makes the most sense for large and complex companies, even the biggest of big businesses haven't universally embraced it. In its "2025 Security Organization Design" report, IANS found that 31% of Fortune 500-sized companies employed a dedicated deputy. Another 13% of organizations designated someone as their deputy CISO as part of a combination with another position.
One limitation is expense. Not every organization is prepared to add salary for a deputy CISO, which, with bonuses, can range from $240,000 to $419,000 per year at U.S.-based companies, according to IANS's "2026 Cybersecurity Talent Report."
A second set of hands on the wheel
Mike Buratowski is about a year and a half into his tenure as The Home Depot's first deputy CISO. For him, the position gives the company the chance to more forcefully emphasize continuity of operations. While analysts in the SOC can respond to contain a problem, Buratowski said, having someone besides the CISO ready to act is important, especially for a retailer conducting business at every hour of every day.
"One of the biggest things is to make sure that we always have somebody who has the responsibility to make emergency decisions, if need be, and tactical decisions," Buratowski said. "It's a force multiplier."
At The Home Depot, CISO Christopher Lanzilotta takes the lead on strategy, while Buratowski and others focus on operations, compliance and other vital daily activities.
It's necessary for a business to make one person accountable for cybersecurity activities, Buratowski said, but, in his view, the top job has become too big for one person to shoulder all the managerial load. That's where deputies come into play. "It's important that the deputies make sure that they understand where the CISO is trying to take the organization and be the enabler for those goals," he said.
Deputized for particular missions
Within cybersecurity circles, the deputy CISO is coming up in conversations and at industry events.
"It's something we see increasingly talked about -- and done," said Melinda Marks, practice director of cybersecurity at Omdia, a division of Informa TechTarget. "I can see it getting bigger."
A deputy CISO is most effective when given specific responsibilities, such as taking the lead on AI implementation, Marks said. "Security and compliance are always the top concerns for adopting any kind of new technology."
With AI, employees who aren't developers can now build productivity applications. But unlike a development team, those employees are likely not working within a DevOps or DevSecOps structure. "If the security teams are left out, then they don't know what's implemented," Marks said.
A deputy CISO could be the security leader devoted to AI safety who enforces rules on AI-assisted development, Marks said.
"If you have deputy CISOs, if organizations are investing more in those security roles, then you can be set up for success," Marks added.
A title but not a mandate?
A deputy could make sense in some situations, said Adam MaGill, senior vice president of global security and global CISO at Concentrix. An organization with many customers interacting directly with its technology, for instance, faces product security demands in addition to the classic duties of defending corporate systems.
Concentrix, a technology services company with more than 450,000 employees worldwide, does not have a deputy CISO. Instead, five vice presidents report to MaGill, each responsible for specific functions handled by the company's 500 security professionals. Adding a deputy to that model, MaGill said, would give that person some remit but not a full remit.
"Ultimately, everything still points up to the CISO -- and has to from an SEC perspective and potentially a DOJ perspective. You need to have one person that's ultimately responsible for all of the security elements," MaGill said.
For aspiring CISOs, the deputy role could be seen as a tempting career stepping stone, but MaGill advises caution.
"Having that in their title, it's a draw," MaGill said. "But you need to ask yourselves some really important questions, like: Does it come with a defined mandate? Do I have some authority? And what does that dynamic with the CISO look like? Does he or she have a plan to make sure you get the right visibility and set the tone coming in?"
What a good deputy CISO enables
Technical expertise matters, Murray said, but more than anything, a deputy CISO needs to be able to communicate with parts of the business that don't know the ins and outs of security and aren’t going to want to have a detailed conversation about, say, AES-256 encryption.
"Who's got the skill set, the drive and the patience? Because you've got to have business discussions with people outside of security," Murray said. "You've got to be able to speak that language. And you've got to be able to have tense conversations and keep your demeanor."
To Marks, having a dedicated second-in-command leader for cybersecurity signals a real commitment to doing things the right way.
"Strong leadership is very important," Marks said. "If it is a large enterprise, having the deputy CISO to free up the CISO to focus more on business skills and aligning with the business -- that helps the company. Then they're strategic about incorporating security and making security part of the company culture."
Phil Sweeney is an industry editor and writer focused on cybersecurity topics.