{"id":7495,"date":"2024-06-06T09:00:00","date_gmt":"2024-06-06T09:00:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/02\/post_id-5005\/"},"modified":"2026-07-04T12:24:42","modified_gmt":"2026-07-04T12:24:42","slug":"the-cdo-as-a-security-stakeholder-why-digital-responsibility-doesnt-end-with-it","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2024\/06\/06\/the-cdo-as-a-security-stakeholder-why-digital-responsibility-doesnt-end-with-it\/","title":{"rendered":"The CDO as a Security Stakeholder: Why Digital Responsibility Doesn&#8217;t End with IT"},"content":{"rendered":"<p><strong>CDOs drive transformation. But with every digital initiative, the attack surface grows. The CDO builds what the CISO must protect. Why both roles need to collaborate and why the CDO should embrace security as part of their responsibility.<\/strong><\/p>\n<h2>TL;DR<\/h2>\n<ul>\n<li>Every digital initiative increases the attack surface<\/li>\n<li>68 percent of companies lack CDO-CISO exchange<\/li>\n<li>Security by Design costs 10 percent upfront  &#8211;  retrofitting costs 300 percent<\/li>\n<li>NIS2 makes executives personally liable<\/li>\n<\/ul>\n<h2>The Blind Spot<\/h2>\n<p>No board report measures the &#8220;attack surface of implemented systems.&#8221; Projects are prioritized based on business value, with security as an afterthought.<\/p>\n<h2>CDO and CISO as Allies<\/h2>\n<p>Every project over 50,000 Euro gets a security checkpoint before go-live. Not as a veto, but as a quality gate.<\/p>\n<h2>What NIS2 Means for the CDO<\/h2>\n<p>Personal liability for executives. Fines up to 10 million Euro. A CDO who introduces insecure systems is personally liable.<\/p>\n<h2>Conclusion<\/h2>\n<p>Digitalization without security is negligent. The synthesis is the core competency of the modern CDO.<\/p>\n<h2>Key Facts<\/h2>\n<p><strong>CDO-CISO Gap:<\/strong> 68 percent lack regular exchange (McKinsey, 2024).<\/p>\n<p><strong>Cost of Delay:<\/strong> Retrofitted security costs 6.5 times more (IBM).<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>Should the CDO attend security meetings?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Yes  &#8211;  at least a monthly sync.<\/p>\n<\/details>\n<details>\n<summary><strong>Should security be a CDO KPI?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Proportion of projects with review, MTTR, DSFA coverage.<\/p>\n<\/details>\n<details>\n<summary><strong>NIS2 and CDO liability?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">In cases of proven negligence: a real scenario.<\/p>\n<\/details>\n<h2>Related Articles<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/05\/post_id-3819\/\">DsiN Annual Congress 2026: Digital Security in the Connected Society<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/02\/28\/post_id-3833\/\">Cyber Warfare 2026: When States Upgrade Digitally<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2025\/09\/18\/post_id-4970\/\">The CISO is a Scapegoat  &#8211;  Why the Role Needs Fundamental Reform<\/a><\/li>\n<\/ul>\n<p style=\"font-weight:700;color:#e6e3da;font-size:1.05em;margin:48px 0 16px;\">More from the MBF Media Network<\/p>\n<div style=\"display:flex;flex-direction:column;gap:14px;margin-bottom:40px;\"><a href=\"https:\/\/www.cloudmagazin.com\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#0bb7fd;\">cloudmagazin<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">Cloud Trends on cloudmagazin.com<\/span><\/a><a href=\"https:\/\/www.digital-chiefs.de\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#d65663;\">Digital Chiefs<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">IT Strategies on digital-chiefs.de<\/span><\/a><\/div>\n","protected":false},"excerpt":{"rendered":"CDOs drive transformation. But with every digital initiative, the attack surface grows. The CDO builds what the CISO must protect. Why both roles need to collaborate and why the CDO should embrace security as part of their responsibility. TL;DR Every digital initiative increases the attack surface 68 percent of companies lack CDO-CISO exchange Security by [&hellip;]","protected":false},"author":10,"featured_media":5007,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"cdo","_yoast_wpseo_title":"The CDO as a Security Stakeholder: Why Digital Responsibility Doesn't End with I","_yoast_wpseo_metadesc":"CDO security collaboration boosts digital trust and reduces risk. Align with IT to protect innovation\u2014start leading responsibly today.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":["post_id-5005"],"footnotes":""},"categories":[259],"tags":[],"class_list":["post-7495","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-strategie-governance-en"],"evm_reading_time_minutes":2,"wpml_language":"en","wpml_translation_of":5005,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7495","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=7495"}],"version-history":[{"count":5,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7495\/revisions"}],"predecessor-version":[{"id":19810,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7495\/revisions\/19810"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/5007"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=7495"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=7495"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=7495"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}