@nkeaton Cyber under the CEO is actually the correct location for it (from my perspective) while the other securities (IT Security, Secure Software Development, etc.) should be under the appropriate operations/development teams. The important thing to remember is the cyber team evaluates not just technology, but people and process - technically the entire enterprise for compliance with internal instructions. So cyber reporting to the Chairman of the Board does make sense and normally the CEO has an alternative role which is the chairman of the board.