Obsolence under discontinuity
Is it time to rethink the CISO role from the ground up?
I’ve had this persistent image in my mind about the implications of that favorite science fiction trope of a multi-generational starship. This is, I believe, one of the silliest solutions to the problem of space being absurdly large (and a lazy form of narrative world building). I won’t bother detailing this, many others have done so with more specificity than I have patience to do here. But the image I keep returning to is this: what happens when 3000 years into a journey, someone invents faster than light travel1 and in a short time, catches up to that ship and says “time to stop - you don’t need to do this anymore”?
The issue I want to discuss in this post isn’t science fiction, it’s about when one technology or principle leapfrogs its predecessor, rendering that predecessor utterly obsolete. In particular, I’ll explore the question: is the CISO role as we think of it today, about to become historical baggage? And if so, what should replace it and why?
It seems obvious the CISO role has been undergoing an evolution. But the CISO role may be structurally misaligned with emerging architectures. The CISO has evolved from operations manager to organizational executive as the role’s scope has been remapped from technical controls to risk. What we call “technical controls” has itself been broadened from elements of technology to elements of process or workflow. Yet the CISO chafes at being constrained: limited in both span of control and recognition as an institutional operator, the CISO is burdened by an increasing scope with limited authority and span of control.
But constraint is the operative word. Especially within higher ed, the CIO has traditionally been seen as a service delivery system - focused on availability, performance, cost, or user satisfaction. In contrast the CISO is seen as a constraint system, controlling risk or enforcing control validation. These aren’t just different domains; they produce competing signals. For the CIO the success signals (and the rewards tied to them) are visible: systems work, users are happy, and delivery is fast. These are low-friction signals. The success signals for the CISO are both quieter (invisible actually) or when visible, rarely warmly embraced. The CISO signals that risk is reduced, controls are enforced, and friction is introduced (when necessary). These are cost-inducing signals. This is why organizations put the CISO under the CIO because the constraint signal is subordinate to the delivery signal.
This delta also operates in the financial space. This is why CIOs always focus on ‘optimization’ or cost reduction. Their goal is to minimize friction and accelerate delivery. Whereas the CISO generally imposes costs on the organization by introducing friction where risk demands it. Allocative friction2 would be the right label. In the context of my earlier post on deviation from the narrative becoming more expensive than the narrative deviating from reality, left to its own devices, the organization will reliably optimize for lower friction over higher assurance. After all uptime is visible while security failures are probabilistic and often delayed. In effect, the reporting line of CISO to CIO becomes a biasing mechanism w/in the institution: it structurally suppresses costly security signals.
I think this is why, every conversation about why the CISO needs to be elevated quickly devolves into some version of security needing an independent path to impose cost. We couch it in all the prose of shining a light on risk or ensuring leadership is properly informed during the decision making process, but it boils down to the same thing: pay attention, you need to resource these mitigations.
We, correctly, point out that the existing reporting structure normalizes quiet risk acceptance. We see this over and over again: project pressure leads to a “temporary exception.” A CIO incentivized to deliver will result in the exception being accepted. This disincentivizes the CISO to escalate and with that, the exception becomes the new baseline. As I mentioned in a recent post, “Behavioral signals reveal what our preferences are when under constraint - essentially signaling how we behave when tradeoffs are real.” And exceptions, especially when they become normalized, articulate our preferences more clearly than the finest policy statements.
The question is, why does this argument show up more often in discussions about the role of the CISO than in other areas? I think it’s because, sticking with the security as constraint model, this aligns it more closely with other functions that are independent from the operators they constrain. I’m thinking of roles like legal counsel or internal audit. CISOs - security - constrain the system itself. Counsel and Audit have independence from operational incentives. If we look at some of the other typically executive functions, in contrast, they optimize within the system, for example, the CFO for finance, the CHRO for the workforce, or the CIO for operational efficiency.
Essentially, the CISO can function anywhere in the organization (particularly if it benefits from multiple reporting lines), but the interrogative question we should ask is: can the organization sustain costly security signals when they conflict with delivery signals? If the entity responsible for imposing cost reports to the entity incentivized to remove it, the cost will eventually disappear.
But I want to pivot a bit at this point, and introduce a new thread to the discussion. As I was talking to a friend and colleague the other day about the role of the CISO, we were marveling at the problem set being laid at the CISOs feet. Four quick examples that came up in the conversation are now plumping up the portfolio of every CISO: post-quantum cryptography (PQC), a redefinition of critical infrastructure, becoming the vanguard of cultural change, and of course artificial intelligence3. I speak to CISOs all the time both personally and professionally and almost no one has time, capacity or expertise to tackle these. These are not incremental problems, but rather they are discontinuous shifts. Most of us are flailing to stay on solid ground, while the chaos of modern information assurance spins us like cows sucked into a tornado4.
Let me briefly unpack those four examples. While it may feel like post-quantum cryptography is perpetually over the horizon, in practice we can now start to see what that looks like and anticipate its arrival. Every cryptographic algorithm currently in use, securing everything from web traffic, to personal communications, to banking, to data archiving will need replacing. Worse, we’ve just seen one of the top candidates for a PQC algorithm fall to Claude’s Mythos’ analysis. Perhaps this is a one-off, but it illustrates that the perfect storm is brewing - the basis of all secure data technologies is collapsing and the power of nearly unlimited spending is attacking its replacement.
This leads directly to the next question: the redefinition of critical infrastructure. Traditionally “critical infrastructure” was meant to cover life-safety services or health services: power, water, emergency response, healthcare. In our digitally mediated world, however, digital infrastructure now supports almost all of our daily activities. Computers steer tractors, authentication is required to access medical care, most financial transactions are digital. For higher education, as we saw with the recent Canvas incident, when digital systems disappear, so does instruction and much of research. Eliding with PQC, if the algorithms underpinning digital activity collapse, should every cryptographic element now become part of your inventory of critical infrastructure?
Finally, what do I mean by cultural change? For the CISO (or really, any security professional), cultural change results from our introduction of friction into existing practices. Wanna get on the network? Now you’ve got to register your laptop. Wanna access a specific website? You’re going to need MFA installed on your phone or a token. But today, the real action is in the research space. Addressing security mitigations is far more than just requiring faculty to use MFA or back up their data: it’s introducing constraints into a system that has long operated without or with minimal administrative influence. It’s a separate system entirely, one that prides itself on autonomy, discovery, and entrepreneurialism. CISOs need to approach research less as established functionaries in an organization, but more as anthropologists studying a foreign civilization5.
If the portfolio has expanded to include quantum-proofing civilization, redefining critical infrastructure, and rewriting faculty culture - all while trapped inside a reporting structure designed to subordinate constraint to delivery - the current CISO role hasn't just become difficult, but pyrrhic. Add to this the sizable personal liability CISOs now face by having, for example, to attest to security practices for any number of data sharing agreements or to the accuracy of SPRS scores6. Modern CISOs are increasingly treating employment negotiations like corporate officers and demanding specific D&O (Directors & Officers) insurance coverage, explicit corporate indemnification, and dedicated budget for independent legal counsel before taking a job. Given how far higher education has to go in this dimension, one begins to question the viability of the role in its entirety. Or at least the wisdom of anyone incautious enough to accept it.
Which returns me to the example of the poor, obsolete generational starship. Despite FTL travel, the starship doesn’t have to abandon its mission. It’s free to continue on its course, struggling with the inertia of endless existential maintenance and social stress. But it is no longer relevant in the larger saga of human expansion into space.
The modern CISO role is our starship: a self-contained artifact of historical practice driven by inertia, while discontinuous shifts in technology and liability warp space around it. Are we so mired in existential and social maintenance, that we are blind to being made obsolescent by the advancement of the world around us? The present crisis is not a temporary gap to bridge, but a reckoning - the role is being left behind by the very world it was built to secure.
Obviously, I’m suggesting the CISO is a transitional role - necessary for a prior architecture of control, but misaligned with the one we are entering. The question is not whether the role continues, it clearly will, but whether it remains aligned with the architecture of the world it is meant to secure.
To practice cybersecurity today feels like we are trying to enforce a traditional “architecture of control” over an increasingly chaotic and expansive domain: it’s like trying to manage air traffic with a stop sign. The CISO is left maintaining the rituals of control (e.g., policy documents, annual awareness training, and manual audits) while the actual velocity of technology and data moves around them unimpeded.
I see the necessity of moving past the current formulation of the CISO as a consequence, not of role failure, but of the CISO having to bridge two incompatible paradigms. In the first, we have security as a managerial function. Here security is treated as a separate function that “adds protection” to existing systems, after the fact, through policy and monitoring. That is, security as an overlay. In the second, we have security as an ambient attribute. Security is built into the underlying “physics” of the architecture itself. A place where data provenance, cryptographic boundaries, automated compliance validation, and resilient systems are native to how code, networks, and data operate. This is security as a system property. These are not incremental problems—they are discontinuous shifts. Thus the modern CISO must simultaneously engineer systems while effecting cultural change, all while swallowing institutional liability.
In an earlier post I argued for the evolution of the CISO into something called a Chief Digital Risk Officer (CDRO)7, largely decoupled from operational responsibilities. I still believe this is the right next step for institutions. It represents a kind of codification in different people and roles, both of the two paradigms I just described. But does it truly position us for the kind of disruptive changes we can already anticipate for our environment?
It’s a valuable exercise to speculate on the future of the CISO. If we stick with evolutionary models, the CDRO is not a disruptive step, it’s a kind of adaptive mutation, not a speciation event; fundamentally it is a specialized form of CISO. However, increasingly the field is leaning into risk enforcement as embedded and federated: where security decision rights are codified into platforms, pipelines, and procurement gates. In many ways we’re trying to change security from a centralized constraint function to become a property of the system’s governance fabric. I don’t need to review every software purchase, the purchasing process natively enforces this for me8.
If we want to continue evolving the CISO, we want to ask what it would take to achieve an environment where we’re not managing exceptions but designing systems where exceptions are impossible or irrelevant. This suggests not a CISO but something like a Chief Trust Architect, who is not managing risk, but rather they’re eliminating entire classes of risk through design constraints.
Of course, once this sort of role is possible, the next logical step would be to imagine it within the context of automation, AI driven or not. Here we’re moving from human decision making to machine-enforced reality. Essentially a policy compiler coupled to control plane ownership. In this world a non-compliant system doesn’t trigger a meeting, but is entirely unable to deploy. Similarly, unauthorized data use isn’t ‘detected’, but cannot be executed. This is truly the disruptive moment (and frightening in some ways given how technology can be abused by authority), but with this realized, the CISO as we know it, disappears. Security is no longer a function, but an emergent property of the architecture. Risk management has been transformed into risk elimination9.
Even today, we see elements of this vision manifesting in our environments. But these remain narrowly scoped and are exclusive to technology. We don’t see it in the human and governance dimension. Of course, this is precisely the dimension most CISOs struggle with. While technology can be compiled, human trust and faculty governance cannot. If we automate the technical controls, the actual work left for security leadership isn’t managing firewalls, it’s navigating human politics, institutional ethics, and research trust. This is particularly challenging in higher education, because university culture is explicitly built against centralized control planes and “policy compilers.”
Earlier I described the breakdown of signals, when the organization cannot sustain costly behavioral or allocative signals, it defaults to weak ones such as policy or exceptions to those policies. The system’s true preference is for delivery over assurance. In the vision I’ve described, you can see a new signal architecture defined: that of “ambient security,” where in place of declarative signals (e.g., “policy requires MFA”) we are moving towards compiled behavioral signals, (e.g., “non-MFA systems cannot deploy”). This doesn’t just evolve the CISO but it eliminates the gap between signal and enforcement. That’s a transition from social signaling systems to computational signaling systems.
In the final analysis, all of this suggests that while the technology will become ambient and self-enforcing, the CISO role will either dissolve into platform code or survive strictly as a political/diplomatic function that mediates between human culture and machine enforcement. The CISO exists today as the human mechanism for enforcing costly signals, but as institutions fail to sustain those costs, the role may be displaced by architectures that make deviation impossible rather than punishable.
As much as I wish it were otherwise, FTL travel simply isn’t going to happen outside of science fiction.
As a reminder, an allocative cost is one imposed through budget, time, or operational delay.
I think everyone is familiar enough with the impact of AI that I don’t need to expand on it here.
Not an image I’ve ever applied to cybersecurity before, but it’s growing on me.
Hopefully not as evangelicals trying to convert a remote tribe. History has shown us how that never ends well.
Higher Ed may still be somewhat insulated, but it doesn’t take a mind reader to look at something like the U.S. Securities and Exchange Commission (SEC) Cybersecurity Disclosure Rules to see what our future holds. Its voluntary dismissal notwithstanding, the prosecution of the SolarWinds case demonstrated a willingness to target CISOs individually under securities fraud and reporting statutes when regulators believe public assurances mask unaddressed internal vulnerabilities.
With a hat tip to my old friend and colleague in just this role at the University of Illinois System Office.
Yes, I realize this is an ideal state - practice is far more complicated.
This deserves some pushback - it’s unclear to me if we’re truly eliminating risk in this vision or just displacing it. Reality is a harsh mistress.


