At what point does it make sense for the security lead to be directly reporting to the CEO and not a CIO/CTO?
Like