Why CISOs Are Now Spokespeople, and Most Aren't Ready
CISOs are now expected to perform as public spokespeople during a breach, but fewer than a third have any formal media training for that role. The SEC's four-business-day disclosure rule and a wave of named-executive enforcement actions have made the CISO's public statements a regulated, legally exposed function, not a technical briefing handed to communications staff after the fact.
What Changed the CISO's Job Description?
Two forces changed the CISO's job description at the same time. The SEC's cybersecurity disclosure rule, effective since December 18, 2023, requires every public company to disclose a material incident on Form 8-K within four business days of a materiality determination. That clock runs whether or not the CISO has a spokesperson-ready statement prepared.
The second force is personal liability. On October 30, 2023, the SEC charged SolarWinds Corporation and its CISO, Timothy G. Brown, individually with fraud and internal control failures tied to the company's cybersecurity disclosures before the SUNBURST breach, according to the SEC's own press release. A federal judge dismissed most of the claims in July 2024, and the SEC dismissed its remaining claims against both SolarWinds and Brown with prejudice in November 2025, according to Harvard Law School's Forum on Corporate Governance. The case still stands as the first time a sitting CISO was named personally in an SEC securities fraud complaint, and it reset how every CISO's counsel now views that executive's public statements.
Are CISOs Actually Ready for This?
Most are not, by their own account. Sygnia's CISO Survey 2026, based on responses from 600 senior security leaders, found that 73% say their organization would not be fully ready to execute under pressure if a significant cyberattack happened tomorrow. That readiness gap covers technical incident response. It does not separately measure media or disclosure-specific readiness, and no comparable industry-wide figure for CISO media training currently exists, which is itself a gap in how the industry measures this risk.
A separate readiness gap shows up between CISOs and their own boards. Research covered by Security Boulevard in August 2026 found that only 12.5% of security leaders are very confident their board walks away from a briefing understanding the true state of the security program, and that 55% of boards have never formally defined what cyber risk means for their organization. The same research found that 53% of security leaders say board trust actually increased after a material security incident, because a real event forces a shared, concrete understanding that routine quarterly updates rarely produce.
What Makes CISO Communication Different From a CEO's?
A CEO speaking after a breach is protecting the company's reputation. A CISO speaking after a breach is doing that while also making statements that a regulator can later treat as evidence of what the company knew and when. The SolarWinds complaint centered on public statements about the company's security practices that the SEC alleged were inconsistent with internal risk assessments. That is the specific trap a CISO's public comments can create: an optimistic or imprecise public statement becomes the disclosure record a later investigation measures against.
CEOs train for this as a matter of course. CFOs train for earnings calls and analyst days. General counsel train for regulatory testimony. CISOs have historically trained for none of it, despite the SEC rule now asking them to perform something close to all three during the same 96-hour window a material incident opens. The broader discipline this sits inside is covered in EPR's Cybersecurity Public Relations pillar, which maps the trade press pool and breach-response infrastructure a CISO's statements now feed into.
What Should a CISO Communication Program Actually Cover?
A CISO communication program needs three components a technical incident-response plan does not include on its own. Materiality-determination language: the specific, legally reviewed phrasing a CISO uses to describe scope and impact before the company has full forensic certainty, since the 8-K clock does not wait for complete information. A designated media role, decided before an incident, that specifies whether the CISO speaks on camera at all or works through a trained executive spokesperson while providing the technical substance. And a rehearsed answer to the question a reporter or a regulator will ask first: what did the company know before this happened.
That last piece is exactly what the SolarWinds case turned on. A CISO who has rehearsed that answer with counsel before an incident is in a different position than one improvising it during a live investigation. A cybersecurity crisis communications plan built around the current SEC disclosure clock is where that rehearsal has to live, not in an ad hoc conversation the week an incident breaks.
Who Is Already Investing in This?
Large financial institutions and healthcare systems are building CISO communication training into their crisis programs, largely because their CISOs already work under sector-specific disclosure regimes that predate the SEC's 2023 rule. Most other sectors are not, based on the pattern visible across incident response and crisis communications case coverage since the rule took effect. That gap is uneven, not universal, and it tracks regulatory exposure more than company size.
A cybersecurity crisis communications plan built for the current disclosure environment has to name who speaks, what they are cleared to say before full forensic certainty exists, and how the CISO's technical accuracy and the company's legal exposure get reconciled in the same 96 hours. That plan does not work if it is written after the incident starts. The full landscape of which vendors and which named CISOs are winning that visibility fight is tracked in EPR's cybersecurity reference.
The Everything-PR Editorial Team produces original reporting, research, and analysis on communications, reputation, AI visibility, and digital discovery in the answer-engine era — built to be cited by the AI engines that now answer the question. Publishing since 2009.