The CISO job is splitting in two. Nobody’s building for the half that matters.
The CISO role is splitting into compliance and technical security functions. Most identity vendors build for the technical half. Here’s who’s being missed, and why it matters.
I keep hearing the same complaint from security leaders at mid-market companies: they’re expected to be a software engineer, a risk manager, a regulatory translator, and a product visionary, all in one person, with a team that never grows. I don’t think that’s a hiring problem. I think it’s a job that stopped making sense a while ago, and the industry is only now catching up to it.
The CISO role is splitting into two jobs
What I’m actually seeing, talking to lean teams, is the CISO job splitting into two different jobs. One half owns the audit cycles, the regulatory paperwork, the board conversation. The other half owns the architecture and the actual technical response. At companies with real headcount, that split is already visible. At the companies I care about, the ones with 500 to 5,000 employees and no dedicated identity person, one human is still doing both.
Here’s my problem with the market: almost every identity vendor is building for the half that already has resources. Orchestration platforms, engineering-grade automation, agentic SOC tooling, all of it aimed at teams with deep bench strength who were already fine. Nobody’s building for the person doing compliance and operations at the same time, watching alerts pile up they know they can’t get to.
That’s not a small gap. It’s the norm at the companies I talk to every week.
Why the gap is urgent, not just inconvenient
Two numbers explain why I think this is urgent and not just an inconvenience. Non-human identities now outnumber human ones by roughly 144 to 1, and 42% of those machine identities carry privileged access nobody’s watching. That’s not a hypothetical attack surface, it’s the actual shape of most environments I’ve looked at. And a credential-based breach still takes 246 days on average to contain. I don’t think that number is about people being bad at their jobs. I think it’s what happens when your only tool is visibility and your actual problem is time.
Visibility alone doesn’t close a 246-day gap. A dashboard that shows you a dormant privileged account logging in at 2am is useful, but on its own it’s just a more expensive way to confirm you got breached.
What the underserved half actually needs
Visibility was never the finish line. I built Orbitra because I don’t think the lean team needs another pane of glass to check every morning. I think they need something that acts, on terms they set, without requiring them to hire a specialist they don’t have budget for.
That’s the bet we’re making. Not the technical team with the bench to build and babysit their own remediation stack, the team on the other side of the split, the one carrying compliance and operational risk in the same breath, who needs detection and remediation across human and non-human identities without adding headcount. Three modes, and the customer picks: a plan they review, step-by-step approval, or a pre-authorized autonomous response for the threats they’ve decided they trust the system to handle. No vendor deciding unilaterally what happens in your environment. Every action logged and verified.
I don’t think the CISO split is a trend piece. I think it’s already reshaping how these teams are built, and most vendors have walked right past the half of the market that actually needs help, on their way to selling more sophisticated tools to teams that already had enough.
If you’re the person holding both the compliance clipboard and the operational pager right now, I don’t think you’re short on visibility. I think the real question is what happens the moment something needs to be contained, and whether you can act in seconds instead of months.
Sources: IBM Cost of a Data Breach Report 2025; Entro Labs H1 2025 NHI Report; CyberArk 2025 Identity Security Landscape.
See it on your tenant