Cybersecurity leaders are no longer solely assessed by the technology they use or the security breaches they mitigate. Today’s CISO owns enterprise cyber risk, operational resilience, third-party risk, regulatory compliance and the security impact of digital transformation.
That expanding mandate makes the structure of the role as important as its compensation. State Bank of India’s recent advertisement for a contractual Group CISO, with annual compensation up to ₹2.5 crore, has triggered a larger question: can a fixed-term security leader build capabilities that will remain effective long after the contract ends? SBI’s appointment is initially for three years, with scope for extension by up to two more years.
The issue is not whether a CISO should be permanent or contractual. It is whether the role comes with the independence, authority, board access, resources and continuity required to own enterprise-level cyber risk.
Here are some points for both the company and the cybersecurity leader to keep in mind before drafting and signing their respective contracts.
The strategy Must Outlast the CISO
A contractual hire does not mean the selected CISO is expected to deliver only a short-term security program; it also depends on whether the company has the vision to give that person enough continuity, authority, and institutional support to build capabilities that outlast the individual.
Souvik Das, Partner at PwC India
As Souvik Das, Partner at PwC India, puts it, “Long-term strategy cannot be person-dependent; it must be a function only.”
That distinction matters. The institution’s cybersecurity, governance structure, and resilience capabilities must remain embedded even if the CISO has a defined tenure. Thus, the problem is not only related to the condition of the CISO´s contract but also to whether the corporation would be able to sustain the plan after the CISO leaves.
What the contract should contain: a multi-year roadmap; cyber risk ownership at board level; explicit handover and succession planning requirements; and the authority to create long-lasting capacity versus one-off project delivery.
Authority Matters More Than Tenure
The other important thing to look for in a contract role is how much power the role truly has. Because CISOs are the ones who are responsible for protecting the enterprise, they should have the freedom to challenge decisions, allocate resources and escalate significant risks to the Board.
Dr. Sushanth Nair, Group CISO at Seviora Group
Dr. Sushanth Nair, Group CISO at Seviora Group, puts it this way: “From a Global/Group CISO perspective, the key question isn’t whether the role is permanent or contractual. It’s whether the CISO has the right mandate, independence, authority and direct access to senior management and the Board.”
Pranay Ghadge, CISO, APAC Financial Services
Pranay Ghadge, CISO, APAC Financial Services, says, “If a CISO feels that raising difficult risks could impact
contract renewal, it may create an unconscious conflict between business expectations and security responsibility.”
Nair points out that the function of cybersecurity has expanded far beyond IT, and CISOs now determine the cyber strategy for the future, increase cyber resilience, defend sensitive data, and oversee third-party and systemic risks.
Therefore, for a contract-based CISO, the title (decision maker), availability to the board, and the ability to employ take priority over the duration of the employment.
What the contract should spell out: reporting line, direct board or board-risk-committee access, authority to elevate risk, approved budget and team, rights to decision-making around all the key security controls, access to the business units and third parties, and safety against consequences of escalated risk.
Measure the Resilience Left Behind
If access and authority determine what a contractual CISO can do, the next question is how success should be measured.
Shashank Bajpai, CISO & CTSO at Yotta Data Services, says the focus should be on sustained organizational resilience rather than the duration of the engagement.
Shashank Bajpai, CISO & CTSO at Yotta Data Services
“A contractual CISO should be measured not by the duration of the engagement or the number of security initiatives delivered, but by the organization’s sustained ability to anticipate, withstand, respond to, and recover from cyber threats.”
For Bajpai, this entails evaluating results like risk mitigation, incident preparedness, recovery readiness, high-risk finding closure, and third-party security. Instead of an organizational reliance on a single person, the key question is whether or not the CISO leaves behind improved leadership, governance, and security capabilities.
What the contract should spell out: outcome-based success criteria tied to resilience—such as improved incident response and recovery times, stronger third-party risk controls, better audit and regulatory outcomes, and a demonstrably more capable security team and operating model.
The Tenure May be Fixed, Cyber Resilience Responsibility Cannot be
For companies, the question is whether the contract creates durable security capability rather than dependency on a single individual. For CISOs, the question is whether the role provides enough independence to challenge the business when risk and commercial priorities collide.
The tenure may be fixed. The responsibility for cyber resilience cannot be.