The Chartered Institute of Information Security (CIISec) has released findings from its annual State of the Security Profession survey, focusing this year on the growing wave of regulation shaping the industry. With the EU AI Act, DORA, NIS2, and the UK’s Data (Use and Access) Bill all advancing, the results provide a clear message: responsibility for cyber security sits firmly at board level.
91 percent of respondents believe that ultimate responsibility for security lies with the board, compared to just 31 percent pointing to security managers or CISOs. More than half (56 percent) argue that senior management should face sanctions, prosecutions, or fines in the event of serious cyber incidents, while only 34 percent believe responsibility should fall on the employee directly involved in a breach.
The profession also expressed scepticism about whether current legislation goes far enough. 69 percent feel that laws are still not strict enough, citing the incoming UK Cyber Security and Resilience Act and the EU’s DORA, and NIS2 as the most significant regulatory drivers. Respondents emphasised that increased regulation is not simply a burden but a sign of progress, aligning cyber security with other established professions where standards and accountability are enforced through law.
Looking ahead, professionals called for immediate measures such as improved data sharing between organizations and mandatory, responsible disclosure of incidents. Longer term, respondents highlighted the need for greater professionalisation across the sector, including the role of chartering in validating expertise and enhancing credibility.
The message is clear: regulation is raising expectations, and boards must take the lead. For cyber security professionals, this means building stronger communication with senior stakeholders, deepening regulatory knowledge, and ensuring security is recognised as a strategic priority at the highest levels.






