From CISO to Business Risk Leader: The New Economics of Security
Key Highlights
- The traditional CISO role focused on preventing security failures, but modern demands require aligning security with business results and financial risk management.
- Cyber insurance has driven organizations to adopt a BISO role, emphasizing risk assessment, asset valuation, and compliance to secure coverage and manage costs.
- Key responsibilities of the BISO include continuous asset valuation, safeguarding AI-generated data, and maintaining human oversight over autonomous AI agents.
- The evolving threat landscape, including AI, geopolitical risks, and supply chain vulnerabilities, necessitates a more integrated and business-focused security approach.
- Organizations are formalizing the BISO role to ensure security strategies support revenue, profitability, and operational resilience in a complex environment.
For most of the past two decades, the CISO's job was defined by what they could stop. They would monitor networks, patch vulnerabilities, harden access controls, and contain incidents before they escalated. In other words, success was measured by the absence of bad outcomes.
While those things are still critical, they're no longer sufficient. A CISO today is also being evaluated on whether the business can obtain cyber insurance, and at what premium. The rise of ransomware, tightening underwriting standards, and new disclosure requirements have increased the stakes of cyber risk. Boards are now asking hard questions about financial exposure, operational continuity, and competitive risk that the traditional CISO role was never designed to answer.
Because the CISO no longer maps cleanly onto what the business actually needs, forward-looking enterprises are increasingly formalizing a new role, the Business Information Security Officer (BISO).
What Is a Business Information Security Officer?
A Business Information Security Officer is directly accountable for the business outcomes that security risk can affect. Traditional CISOs secure infrastructure like networks and systems; security is adjacent to the business, protecting operations but not formally tied to business results. Where the CISO is accountable for security, the BISO is accountable for things security ultimately protects, such as revenue, profitability, and competitive position. For the BISO, a cyber-breach is both a security failure and a business failure.
A growing number of security leaders at large enterprises are already doing this job, whether they call themselves BISOs or not. And the pressure to take on that accountability has come primarily from the cyber insurance industry.
How Cyber Insurance Forced the Transformation
In the early years of the cyber insurance market, through roughly the mid-2010s, insurers wrote policies without fully understanding the risk they were taking on. Unlike property or auto insurance, where actuaries had decades of claims data to draw from, cyber was a new and largely unquantified risk category. Premiums were not closely tied to actual security posture, and coverage was often bundled into broader commercial policies.
Then around 2019 and 2020, the losses started to scale. In a 2021 report, the U.S. Government Accountability Office analyzed data from A.M. Best, the Council of Insurance Agents and Brokers, and NAIC. GAO calculated that the loss ratio on standalone cyber policies doubled in just three years, rising from 16% in 2016 to 33% in 2019, with ransomware being the primary driver. And according to NCC Group's 2021 Annual Threat Monitor, ransomware attacks rose nearly 93% in 2021 alone.
These losses, combined with the emergence of more sophisticated and costly ransomware attacks, caused insurers to start auditing organizations and, in some cases, dictating what had to be in place before they would extend coverage. Premiums rose sharply, coverage limits shrank in high-risk sectors such as healthcare and education, and some policyholders found themselves denied coverage entirely until they met stringent new security requirements.
This puts a dollar figure on security decisions. Misconfigured endpoints or weak access controls now affect the organization's insurance premium, its coverage terms, or even its ability to get covered at all. Security became a business conversation. For the first time, security leaders had to understand financial exposure. They had to learn to read amortization tables, interpret underwriting risk scores, and know what insurance coverage gaps meant for the business. The BISO position evolved in response to these new business realities, and it has grown in prevalence ever since.
Misconfigured endpoints or weak access controls now affect the organization's insurance premium, its coverage terms, or even its ability to get covered at all. Security has become a business conversation.
What the BISO Must Own: Three Operational Priorities
The BISO mandate translates into three concrete operational priorities that distinguish it from the traditional CISO role.
- Continuous asset valuation
The instinct to protect everything equally is understandable, but infeasible. Organizations cannot protect 100% of their data. The cost would be too prohibitive, and the resources would be spread too thin. The volume of data organizations now manage has grown enormously, and new data types, including AI-generated, are being added constantly. Not all of it carries equal risk or equal value to the business.
One of the most important parts of the BISO's job is to know what data and systems are valuable and how compromises, exposures, and lockouts would materially impact revenue and reputation. That means working closely with business units to assess and understand what is operationally critical. Because businesses change, this requires constant auditing, classification, and recalibration.
- Protecting intellectual property in AI environments
Companies introducing AI risk losing control over proprietary information. Employees using public AI tools may inadvertently share confidential information in environments that sit outside the organization's security, data handling, and compliance controls. Teams driving AI-assisted innovation may also face new questions around inventorship, ownership, and patentability, requiring new processes to safeguard overall business interests. Using AI for generating imagery or text can create copyright and licensing risks.
The BISOs work with business units to build policies and inform good practices that distinguish between what data can and cannot flow into which categories of AI tools, under what conditions, and with what oversight.
- Maintaining human authority over AI decision-making
AI agents are built to do whatever they calculate is necessary to accomplish their objective. There is no inherent judgment about whether an action stays in the spirit of what was intended, only whether it serves the goal. At scale, with multiple agents operating simultaneously and without clear oversight, that can create problems.
For example, when two AI agents operate in the same environment without a governance framework, one agent can end up taking priority over the other. This doesn’t happen because a human decides it, but because the agents themselves resolve the conflict on their own, with one effectively deferring to the other's objective. Left unmanaged, an organization can end up with an agent that appears to work on its behalf but, in practice, serves a different goal entirely.
AI should enforce human decisions, not make its own. And the more autonomous agents become, the more important that distinction is. Organizations need clear lines of accountability to ensure humans set policies, AI executes them, and outcomes trace back to humans. Establishing and maintaining those boundaries is central to the BISO's mandate.
A Role Built for This Moment
Security leaders are operating in an environment that keeps getting harder to manage. Variables such as AI, cross-border data sovereignty, geopolitical risk, and supply chain exposure add complexity and are changing rapidly, sometimes daily. CISOs who remain narrowly focused on threat response will find themselves increasingly misaligned with what the business needs.
The BISO title is new, but the accountability it represents has been building for a long time.
About the Author
Chris BonavitaChris Bonavita
Vice President of Strategy and Technology Adoption for GTT
Chris Bonavita serves as GTT’s Vice President of Strategy and Technology Adoption, accelerating the company's efforts to expand its technology offerings and advance its networking and security-as-a-service solutions on the GTT Envision platform. Built on a top-ranked Tier 1 network, GTT Envision provides a unified platform for network orchestration, virtualization, and automation. The company’s portfolio includes SASE, SD-WAN, security, internet, and voice solutions, supported by professional services and global customer support. Through strategic innovation and collaboration, GTT delivers Greater Technology Together to help organizations navigate complex networking and security challenges.
