Splunk Inc. has released its 2023 CISO Report, a new global research report detailing emerging trends, threats, and strategies for today’s chief information security officers (CISOs), chief security officers (CSOs), and other qualified security leader equivalents.
The c-suite and board of directors are increasingly relying on CISOs for guidance across a sophisticated threat landscape and changing market conditions. These relationships provide CISOs the opportunity to become champions who strengthen an organization’s security culture and lead teams to become more cross-collaborative and resilient. By communicating key security metrics, CISOs can also guide boards on adopting emerging technologies, such as generative AI, to help improve cyber defense management and prepare for the future.
Jason Lee, CISO, Splunk.
Notably, 86% of surveyed CISOs believe generative AI will alleviate skills gaps and talent shortages on the security team, filling labor-intensive and time-consuming security functions and freeing up security professionals to be more strategic. 35% report using generative AI for positive security applications and an additional 61% will likely use it within the next 12 months.
Ninety percent of respondents reported their organization experienced at least one disruptive cyber attack last year. Numerous industries experienced ransomware attacks that significantly impacted their systems and business operations, including financial services (59%), retail (59%), and healthcare (52%). 83% of organizations paid the attackers in the wake of a ransomware attack, and more than half paid at least $100,000. The retail industry is the most likely to pay the ransom, with 95% of respondents reporting they either paid directly, through cyber insurance or a third party.
CISOs are trying to stay ahead of generative AI
cyber adversaries more opportunities to commit attacks, yet 35% are already experimenting with it for cyber defense including malware analysis, workflow automation, and risk scoring. CISOs in healthcare (88%), manufacturing (76%), and financial services (72%) express the most fear that generative AI would give either a strong or slight advantage to cyber adversaries. 51 percent of CISOs in financial services say they planned to implement specific cyber security controls to mitigate AI security risks. 93 percent of CISOs have extensively or moderately implemented automation into their processes.
Cyber resilience is becoming more of a strategic area
In 47% of organizations surveyed, the CISOs are now reporting directly to the CEO, indicating a closer relationship with the c-suite and their respective governing boards. Boards of directors are increasingly looking to CISOs to guide cyber resilience strategy, offering an opportunity for CISOs to articulate value and fill in communication gaps. Numerous CISOs across many industries report regular participation in board meetings, including technology (100%), government (100%), communications and media (94%), healthcare (88%), and manufacturing (86%). 90% of CISOs say their governing board cares more about different KPIs and security metrics today than it did two years ago. The top three CISO metrics for success are: results of security testing, the ROI of security investments, and the ability to purchase cyber insurance.
Cross-functional collaboration will be critical for a lasting resilience strategy
92% of respondents report either a significant or moderate increase in collaboration between cyber security teams, IT, and engineering organizations; largely driven by initiatives like digital transformation, cloud native development, and a greater emphasis on risk management. CISOs agree that strategic collaboration will be vital to gain visibility and ensure resilience throughout the organization.






