What CIO-CISO Alignment Looks Like When It's Working
SC Media, Thursday, September 10th, 2026
Cushman & Wakefield's CDIO and CISO explain why the operating model matters more than the CISO reporting line.
At the Boston Leadership Exchange, Cushman & Wakefield CDIO Salumeh Companieh and CISO Erik Hart argued that access and operating model matter more than who the CISO reports to; Hart presents to the board himself.
Across 53,000 employees in about 60 countries, every new application or architecture change gets a cyber risk review, a process that took 18 months to become culture.
The team measures success with business metrics such as lower cyber insurance costs and faster RFP responses, invests in storytelling training, and designs controls around how employees actually work.
Security makes risk transparent, while the business owns the decision.