
There is a conversation I have had more times than I can count — sometimes with my CISO over coffee, sometimes in a boardroom under pressure, and occasionally during a security incident unfolding in real time. It is the conversation about who owns what. And every single time, I realise we are having it a little too late.
The CISO–CIO relationship is one of the most consequential partnerships in any modern enterprise. Yet, in my experience leading technology across a large, multi-business conglomerate like CK Birla, it is also one of the most under-formalised. We speak of it often. We assume it works. And then a cloud misconfiguration surfaces, or a vendor access breach, and we realise that assumption was doing far too much heavy lifting.
The ownership question nobody wants to answer. In an organisation spanning healthcare, automobiles, cement, and real estate — each with its own technology stack and maturity curve — the question of who owns security decisions is not academic. It is deeply consequential. The informal understanding has always been that the CIO owns technology and the CISO owns security. Clean on paper. Chaotic in practice. What I wish we had formalised far earlier is a joint ownership matrix that explicitly answers: Who signs off on a new cloud platform deployment? Who defines the security baseline for a greenfield business unit? Who has the final word when a security recommendation conflicts with a business deadline?
Cloud accountability — the grey zone we created ourselves. When we accelerated our cloud journey, the excitement was justified. What we underestimated was how rapidly cloud would become the terrain where the CIO–CISO boundary is tested most severely. The CIO’s office drives cloud adoption; but who monitors configuration drift on a Tuesday afternoon? Who reviews IAM permissions hastily set up during a go-live weekend? We needed an internal Cloud Security Accountability Charter — defining our own shared responsibility model, well beyond what hyperscalers hand you.
Operational escalation: who calls whom at 2 AM? Security incidents do not arrive with neat labels and clear owners. What I have learnt, sometimes the hard way, is that the escalation model cannot be improvised. You cannot decide in the middle of a ransomware event who leads response, who briefs the Board, who engages regulators. That structure must exist on paper, tested in simulation, long before the incident occurs.
Ultimately, the CISO–CIO partnership is a relationship of genuine mutual respect between two leaders protecting the same thing — the organisation’s ability to function and be trusted. The formalisation we once treated as optional is now, simply, a matter of enterprise resilience.
It is time we treated it that way.





