Technology leadership, explained

CIO vs CTO vs CISO: who owns what

Three titles that get used interchangeably and shouldn't be. The CIO keeps the business running on technology. The CTO builds the technology the business sells. The CISO makes sure neither one becomes the reason the company ends up in the news.

CIO vs CISO vs CTO comparison: primary domain, core question, who each faces, security ownership, key actions, how each is measured, and main driver.

Share it: Download the image (PNG) · Vector (SVG)

Side by side, in depth

Pick a role to spotlight its column. On a phone, pick a role to see just that role.

Dimension CIOOPERATE · Chief Information Officer CISOSECURE · Chief Information Security Officer CTOINNOVATE · Chief Technology Officer
Primary domain Internal systems, data, and the tools employees use to run the business: ERP, CRM, email, networks, devices. Cyber risk across every system the company touches: policy, controls, compliance, and incident response. The product or platform customers use, the architecture under it, and the engineering team that builds it.
Core question Does the business run efficiently on its technology, at a cost that makes sense? What could go wrong, how bad would it be, and are we ready when it happens? What should we build next, can it scale, and does it beat the competition?
Faces Inward. Employees, operations, finance, and the vendors that serve them. Across. The board, auditors, regulators, insurers, and customers asking security questions. Outward. Customers, the market, and product partners.
Owns in security Operates the defenses on internal systems: MFA, patching, backups, device management, access. Writes the rules, sets the risk appetite with leadership, and checks that everyone follows them. Builds security into the product: secure code, cloud configuration, release pipelines (DevSecOps).
Key actions Negotiates vendor contracts, runs ERP and CRM, manages the help desk or provider, owns the IT budget. Answers security questionnaires, runs audits, owns the incident response plan, handles cyber insurance. Sets architecture, decides build vs buy, hires and leads engineers, ships AI and product features.
Measured by Uptime, cost per user, projects delivered on time, adoption of new tools. Risk reduced, audit findings closed, time to detect and respond, clean customer reviews. Release speed, platform reliability, product revenue, engineering productivity.
Usually reports to CEO, CFO, or COO. Often the CIO; more and more often the CEO, COO, general counsel, or risk officer. CEO. In companies that don't sell technology, sometimes the CIO.
Main driver Efficiency and stability. Resilience and trust. Growth and speed to market.

Who owns it? Test yourself.

Ten situations companies actually face. Pick who should own each one. Most real problems have a primary owner and partners.

Where the roles overlap

The overlaps are where work gets dropped. Click a zone to see what lives there.

CIO CTO CISO CIO only CTO only CISO only CIO + CTO CIO + CISO CTO + CISO All three

Which one does your company need?

Pick the description closest to your company. The bar shows where a technology leader's time should go.

Splits are Yellow Coop's starting point for scoping an engagement, not survey data.

Can one person do all three?

Yes, at most companies under a few hundred people

A company with 150 employees rarely has enough CIO, CTO, and CISO work to fill three executive calendars. One experienced leader covering all three, with emphasis set by the business, is how most growing companies get the work done. That is the model behind a fractional technology executive.

With one check: independence

The person who runs the systems shouldn't be the only one grading their security. IANS Research puts it plainly: the CISO has to be free "to give honest, unbiased, clear evaluation and guidance." When one leader holds both seats, add an outside check: an annual penetration test, an external audit, or a direct line to the board on cyber risk.

64%

of security leaders still report into IT leadership. 36% report to a business executive such as the CEO, COO, general counsel, or chief risk officer.
IANS Research and Artico Search, State of the CISO benchmark, 2026

4 days

US public companies generally have four business days to disclose a cyber incident once they decide it is material, and must describe management's cybersecurity expertise every year.
SEC cybersecurity disclosure rules, 2023

1981

The year the CIO role was first formally defined, by William Synnott and William Gruber. The CTO title spread through the 1980s. The CISO is the youngest of the three.
Synnott & Gruber, Information Resource Management

What the references say

CIO

The senior executive responsible for the information technology and computer systems that support the organization's goals: IT strategy, business systems, vendors, service delivery, and continuity.

Common distinction: the CIO focuses on technology's use inside the business; the CTO on the technology itself, often customer-facing.

Synnott & Gruber (1981); widely used CIO vs CTO distinction summarized in the CIO reference entry

CISO

NIST, in its federal framework, defines the role as the official responsible for carrying out the CIO's information security responsibilities and serving as the CIO's primary liaison to the people who own and authorize systems.

NIST's Cybersecurity Framework 2.0 adds that "organizational leadership is responsible and accountable for cybersecurity risk", which is why the CISO increasingly reports outside IT.

NIST SP 800-37 Rev. 2 glossary · NIST CSF 2.0 (GV.RR-01)

CTO

The executive who owns technology strategy, research and development, architecture, and engineering delivery, with a long-range view of what the company must build to compete.

Roland Berger describes four CTO archetypes: operations expert, product and technology champion, business model strategist, and chief architect.

Roland Berger, CTO 2030 (2024) · CTO reference entry

More sources: SEC press release 2023-139 · IANS: the ideal CISO reporting structure · IANS and Artico Search, 2026 State of the CISO

Not sure which seat you need? That's what the first call is for.

Book a 20-min call