Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Good advice on how CIO-CISOs can work together better!

By Peter Vogel on September 11, 2026
Email this postTweet this postLike this postShare this post on LinkedIn
Teamwork, women's power!
Antonio Janeski, Unsplash

SCWorld.com reported “For years, security leaders have debated whether the CISO should report to the CIO, the CEO, legal, or somewhere else entirely.”  The September 10, 2026 article entitled ” What CIO-CISO alignment looks like when it’s working” (https://tinyurl.com/muha4mnm) included following comments:

At the Boston Leadership Exchange, two executives responsible for making that relationship work argued the reporting line is far less important than the operating model behind it.

Salumeh “Sal” Companieh, chief digital and information officer at Cushman & Wakefield, and Erik Hart, the company’s chief information security officer, shared how they’ve built security into the business, where they’ve stumbled, and what they’ve learned about aligning technology and security leadership at enterprise scale.

Cushman & Wakefield’s environment presents unique challenges. The company supports more than 53,000 employees across 350 offices in roughly 60 countries, yet many employees work inside client facilities using client-owned technology. More than 10,000 employees receive no corporate-managed endpoint at all.

“Security becomes their identity,” Hart said.

The complexity extends well beyond technology. Roughly half the workforce is hourly, many employees are unionized, and a significant percentage speak English as a second language.

Rather than relying on security reviews at the end of projects, the company embedded security into its operating model. Every new application, technology purchase or architecture change requires cyber risk and architecture review before moving forward.

Getting there wasn’t immediate.

“It took about 18 months,” Companieh acknowledged, before the process became part of the organization’s culture.

The company also pairs every product and operations team with dedicated cyber counterparts, creating shared accountability rather than treating security as an external approval function.

Interesting story.

First published at https://www.vogelitlaw.com/blog/good-advice-on-how-cio-cisos-can-work-together-better

  • Posted in:
    Corporate Governance and Compliance, Privacy and Cybersecurity, Technology and AI
  • Blog:
    Internet, IT & e-Discovery
  • Organization:
    Peter S. Vogel PC
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo