# CISO Version 2.0

DevFeed: [CISO Version 2.0](<https://devfeed.tech/articles/ciso-version-2-0-39485.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/ciso-version-2-0>)

Author: Phil Venables

Published: 2026-06-12T13:05:15Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [version](<https://devfeed.tech/topics/version.md>), [Security](<https://devfeed.tech/topics/security.md>), [benchmarking](<https://devfeed.tech/topics/benchmarking.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [opinion](<https://devfeed.tech/tags/opinion.md>), [risk](<https://devfeed.tech/tags/risk.md>), [security](<https://devfeed.tech/tags/security.md>), [technology](<https://devfeed.tech/tags/technology.md>), [version](<https://devfeed.tech/tags/version.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

The article argues that the CISO role has evolved from an IT security manager into roles including cyber-defense leader, compliance director, and technology risk manager. It also argues that cybersecurity benchmarking is unhelpful when it focuses on inputs such as budgets rather than control effectiveness.

## Source excerpt

Everyone, no doubt, has an opinion on how many versions of the CISO role we have gone through since its inception. There has been a constant evolution from what was essentially an IT security manager, to cyber-defense leader, compliance director, technology risk manager, and beyond. However, I would argue the incarnation of the CISO role up until recently has been CISO Version 1.0 albeit with some "point releases" on the way. This is simply because version 1 of the role is a mode where most...