Back to Insights
Leadership·SG/NL/AE

The CISO Who Reports to the Board: How Regulatory Pressure Is Rewriting Security Leadership

SEC cyber disclosure rules, NIS2, and MAS TRM are forcing CISOs into board-level reporting. The CISO who thrives in this environment is a different hire from the one who managed a SOC. Here's what the search brief should actually say.

Harald H.R. AgterhuisHarald H.R. Agterhuis·March 3, 2026
Contents · 5 sections+

The CISO role has undergone a structural transformation that most search processes haven't caught up with. Three regulatory developments — occurring simultaneously across three jurisdictions — have elevated cybersecurity leadership from a technical function to a board-level accountability.⁠‌‌​​​​‌​‍‌​‌​‌​​‌‍​‌​‌​​‌‌‍​‌​​​‌​‌‍​‌​‌​​‌​‍​‌​​​​‌‌‍​‌​‌‌​​​‍​‌​​‌​​‌‍​​‌​‌‌‌‌‍​‌‌​​​‌‌‍​‌‌​‌​​‌‍​‌‌‌​​‌‌‍​‌‌​‌‌‌‌‍​​‌​‌‌​‌‍​‌‌‌​‌‌‌‍​‌‌​‌​​​‍​‌‌​‌‌‌‌‍​​‌​‌‌​‌‍​‌‌‌​​‌​‍​‌‌​​‌​‌‍​‌‌‌​​​​‍​‌‌​‌‌‌‌‍​‌‌‌​​‌​‍​‌‌‌​‌​​‍​‌‌‌​​‌‌‍​​‌​‌‌​‌‍​‌‌‌​‌​​‍​‌‌​‌‌‌‌‍​​‌​‌‌​‌‍​‌‌​​​‌​‍​‌‌​‌‌‌‌‍​‌‌​​​​‌‍​‌‌‌​​‌​‍​‌‌​​‌​​‍​​‌​‌‌​‌‍​‌‌‌​​‌‌‍​‌‌​​‌​‌‍​‌‌​​​‌‌‍​‌‌‌​‌​‌‍​‌‌‌​​‌​‍​‌‌​‌​​‌‍​‌‌‌​‌​​‍​‌‌‌‌​​‌‍​​‌​‌‌​‌‍​‌‌​‌‌​​‍​‌‌​​‌​‌‍​‌‌​​​​‌‍​‌‌​​‌​​‍​‌‌​​‌​‌‍​‌‌‌​​‌​‍​‌‌‌​​‌‌‍​‌‌​‌​​​‍​‌‌​‌​​‌‍​‌‌‌​​​​‍​​‌​‌‌​‌‍​‌‌​​‌​‌‍​‌‌‌​‌‌​‍​‌‌​‌‌‌‌‍​‌‌​‌‌​​‍​‌‌‌​‌​‌‍​‌‌‌​‌​​‍​‌‌​‌​​‌‍​‌‌​‌‌‌‌‍​‌‌​‌‌‌​⁠

The result: the CISO your organisation needed in 2022 is not the CISO your organisation needs in 2026. And the difference is not technical depth. It's governance fluency.

I.The Three Regulatory Catalysts

**SEC Cyber Disclosure Rules (US, Global Impact)**: The SEC's cybersecurity disclosure requirements mandate that publicly listed companies report material cybersecurity incidents within four business days. They also require annual disclosure of cybersecurity risk management, strategy, and governance — including board-level oversight of cybersecurity risk. For any organisation with US listing, US investors, or US operations, the CISO is now a disclosure-relevant role. Their judgment about materiality directly impacts securities filings.

**NIS2 Directive (EU/Netherlands)**: NIS2 expands the scope of entities subject to cybersecurity obligations across the EU. It introduces personal liability for management bodies — meaning board members and senior executives can be held personally accountable for cybersecurity failures. In the Netherlands, the Wet beveiliging netwerk- en informatiesystemen (Wbni) implementation creates specific obligations for essential and important entities. The CISO's reports to the board are no longer advisory. They are compliance evidence.

**MAS TRM Guidelines (Singapore)**: MAS Technology Risk Management Guidelines require board-level awareness and oversight of technology risk. MAS expects CISOs (or equivalent roles) to have direct reporting lines to senior management and, in practice, regular engagement with the board. MAS supervisory examinations increasingly assess the quality of board-level cyber risk reporting — not just the technical controls.

II.What This Means for the Search Brief

The traditional CISO search brief focuses on: - Years of experience in information security - Technical certifications (CISSP, CISM, etc.) - Experience with specific security technologies - Incident response experience - Team leadership

These are baseline requirements. They are no longer differentiating.

The search brief for a board-reporting CISO must additionally assess:

**Board communication capability**: Can this person translate technical risk into financial exposure language that non-technical directors understand? Not as a presentation skill — as a cognitive capability. The CISO who thinks in vulnerabilities and patches will struggle to communicate in terms of business impact and risk appetite. The CISO who thinks natively in both registers is a fundamentally different hire.

**Regulatory judgment**: Can this person make materiality determinations under time pressure? SEC disclosure timelines create a four-day window for decisions that have securities law implications. MAS supervisory expectations create an environment where under-reporting is dangerous and over-reporting is credibility-destroying. The CISO must calibrate — and that calibration is a form of judgment that technical security experience alone does not develop.

**Governance architecture**: Can this person design a cybersecurity governance framework that satisfies multiple regulatory expectations simultaneously? NIS2, MAS TRM, and SEC disclosure requirements have different reporting cadences, different risk taxonomy expectations, and different oversight models. A CISO operating across corridors must build a single governance architecture that demonstrates compliance in all three — without creating three separate reporting frameworks.

III.The IMPACT Assessment for Board-Level CISOs

Our assessment of CISO candidates for board-reporting mandates weights three IMPACT dimensions heavily:

**Conviction Depth**: Will this CISO tell the board something it doesn't want to hear? The most dangerous failure mode in cybersecurity governance is a CISO who calibrates their message to the audience's comfort level rather than the organisation's actual risk posture. We assess whether candidates have a documented history of escalating uncomfortable findings — and whether those escalations were effective.

**Accountability Architecture**: Has this CISO built governance frameworks that survived regulatory examination? Not theoretical frameworks. Frameworks that were actually tested — by incidents, by regulatory audits, by board-level challenges. The difference between a framework on paper and a framework that works under stress is the difference between a capable CISO and a transformative one.

**Trust Mechanics**: Can this CISO build and maintain trust with a board that doesn't understand cybersecurity? Board trust is not earned by technical brilliance. It's earned by consistent, calibrated communication that respects the board's governance role without patronising its members. This is a specific interpersonal capability that technical security career paths rarely develop.

IV.The Compensation Recalibration

Board-reporting CISO compensation has recalibrated sharply upward since 2024:

Singapore: CISO roles with direct board reporting command SGD 350K–550K base plus bonus. MAS-regulated entity experience adds a 15–25% premium.

Netherlands: NIS2-scope CISO roles command EUR 200K–380K base. Personal liability implications under NIS2 are creating demand for directors' and officers' insurance coverage as a compensation component — a structural shift that signals the governance weight of the role.

UAE: CISO roles with DFSA/ADGM regulatory experience command AED 500K–850K base. The thin talent pool for CISOs with GCC regulatory experience maintains premium pricing.

The CISO who manages a SOC is a security professional. The CISO who reports to the board is a governance leader. The search process that treats them as the same role will deliver the wrong hire. And in a four-day disclosure window, the wrong hire is not a recruitment problem. It's a securities law problem.

V.Key Citations

SEC Final Rule: Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure (2023) · NIS2 Directive (EU) 2022/2555 · MAS Technology Risk Management Guidelines (Updated 2024) · DIFC Data Protection Law · Heidrick & Struggles Global CISO Survey 2025 · Gartner CISO Effectiveness Survey 2025 · ISC2 Cybersecurity Workforce Study 2025

Three Ways to Begin a Mandate.

Every engagement starts with alignment. Choose the path that matches where you are.

Confidential · 30 minutes · Partner-led · No obligation

Three candidates, every one we would hire ourselves.

Commission a Search

You know the role. You need the operator. Define what this hire needs to unlock.

Begin AI Assessment

Two weeks of precision diagnostics before committing to a search. Know what you need before you hire for it.

See the Assessment

Submit a brief without your company name. We confirm fit before any details are exchanged.

Request Partner Allocation

A confidential briefing with a resident corridor partner. No gatekeepers, no intermediaries.

Request Partner Allocation

Secure calendar allocation — cross-border mandates only.