Security1 publisher2 min readPublished
Cushman & Wakefield's CIO and CISO put board access ahead of the reporting line
Erik Hart reports to Salumeh Companieh at Cushman & Wakefield, and both told a Boston panel the line matters less than who owns the board slot and what has to clear cyber review before it gets built.
The Watch · Security desk

What happened
- Two Cushman & Wakefield executives told the Boston Leadership Exchange that the CISO reporting line matters far less than the operating model behind it, with no gating factor between the CIO and CISO roles.
- Companieh, the chief digital and information officer, presents to the board roughly quarterly and CISO Erik Hart twice a year, and she said the board communication belongs to him while she stays on the call.
- Every new application, technology purchase or architecture change at the company has to clear cyber risk and architecture review before it moves forward, replacing end-of-project security reviews.
- Hart said that in seven years at Cushman & Wakefield, no technology initiative has ever been put into production over a security objection.
- The pair said they avoid security activity metrics and report instead on cyber insurance costs year over year, NIST-based external posture scoring and how fast security can support customer RFPs.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure For the employees working on client-owned hardware, identity is the only control left: there is no company endpoint agent to see what a stolen credential does after it authenticates.
- decision A security leader arguing to be moved off the CIO now has a cheaper thing to measure first, namely how many board presentations they own outright and how many of their objections have been overridden.
- cost Tying security to insurance premiums and RFP turnaround puts the function in numbers the CFO already audits. That is a different budget conversation from patch counts and blocked phish.
Getting the review to stick took time. "It took about 18 months," Companieh said, before the process became part of the organization's culture [18]. Alongside it, the company pairs every product and operations team with dedicated cyber counterparts, so accountability is shared instead of security acting as an external approval function [19].
Hart applied the same test to both directions of the org chart. "If you report into technology, how are you building peer relationships across the business?" he asked. "If you report outside of technology, how are you building them back into technology?" [9][10] He said there is no universal reporting model for CISOs, that some organizations are best served reporting through legal and others through technology, and that what matters is whether security has the independence and executive access to influence decisions [8]. He also keeps direct relationships with business leaders, the general counsel and the CFO [7].
The environment explains why the gate sits before the build. Cushman & Wakefield supports more than 53,000 employees across 350 offices in roughly 60 countries [12]. Many work inside client facilities on client-owned technology, and more than 10,000 receive no corporate-managed endpoint at all [14][13]. Divide 10,000 by 53,000 and that is about 19% of the workforce with no company agent on the device they use [24]. "Security becomes their identity," Hart said [15]. Roughly half the workforce is hourly, many employees are unionized, and a significant percentage speak English as a second language [16].
Companieh named a non-technical investment as one of the highest-return ones available to a security organization. "If you are not running your cyber team through storytelling training," she said, "I would call that a key investment that you can make" [22]. Hart recalled visiting a Boston site where the first thing a user told him was how much she disliked multi-factor authentication [23].
What the panel supports is narrower than the argument it was making. The seven-year record of no override is Hart's own count, offered from inside a structure where he reports to Companieh [11][3]. There is no comparison case here against a company whose CISO reports to the CEO or to legal, so the transferable parts are the checkable ones. Hart owns the board slot [5]. The review has to clear before something gets built [17]. That review took 18 months to become routine [18].
What to watch
- Whether the seven-year record of no initiative shipping over a security objection survives the first agentic AI rollout the business wants fast.
- Whether year-over-year cyber insurance cost reduction stays a reportable metric once renewal pricing turns against buyers.
- Whether any other company publishes how long its pre-build cyber review took to become routine, giving the 18-month figure something to sit against.