THREAT BRIEFING · 18.07.2026 DEENFRES

Strategy & Governance

The CDO as a Security Stakeholder: Why Digital Responsibility Doesn’t End with IT

By Alec Chizhik · June 6, 2024 · 2 min read

CDOs drive transformation. But with every digital initiative, the attack surface grows. The CDO builds what the CISO must protect. Why both roles need to collaborate and why the CDO should embrace security as part of their responsibility.

TL;DR

The Blind Spot

No board report measures the “attack surface of implemented systems.” Projects are prioritized based on business value, with security as an afterthought.

CDO and CISO as Allies

Every project over 50,000 Euro gets a security checkpoint before go-live. Not as a veto, but as a quality gate.

What NIS2 Means for the CDO

Personal liability for executives. Fines up to 10 million Euro. A CDO who introduces insecure systems is personally liable.

Conclusion

Digitalization without security is negligent. The synthesis is the core competency of the modern CDO.

Key Facts

CDO-CISO Gap: 68 percent lack regular exchange (McKinsey, 2024).

Cost of Delay: Retrofitted security costs 6.5 times more (IBM).

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

Should the CDO attend security meetings?

Yes – at least a monthly sync.

Should security be a CDO KPI?

Proportion of projects with review, MTTR, DSFA coverage.

NIS2 and CDO liability?

In cases of proven negligence: a real scenario.

Related Articles

More from the MBF Media Network

cloudmagazinCloud Trends on cloudmagazin.comDigital ChiefsIT Strategies on digital-chiefs.de

Further reading

Strategy & Governance · July 17, 2026

NIS2 Patchwork: Four States Face EU Court

The EU Commission sues Ireland, Spain, France, and the Netherlands over incomplete NIS2 implementation. What this means for CISOs.

A magazine by Evernine Media GmbH