Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Organizations do not need a new executive title to align technology, security, and data. They need CIOs, CISOs, and chief data officers to shape important initiatives together—before architecture and delivery decisions are locked in. In a September 2, 2025 opinion article, former CIA deputy director for digital innovation Jennifer Ewbank describes a “digital C-suite” approach built around that idea. Her account offers a useful operating model, not a publicly verified CIA performance study or an official government endorsement.
What problem was the digital C-suite meant to solve?
When IT, cybersecurity, and data leaders optimize their own functions in parallel, the seams can become the obstacle. Security may be asked to review an architecture after it has been chosen; data governance may be treated as a compliance checkpoint rather than a condition for useful analytics; and infrastructure teams may select platforms without resolving how data access, protection, and operations will work together.
Ewbank describes capable leaders pursuing partially disconnected objectives, with duplicated work, competing priorities, slower decisions, and potential security gaps as consequences. The issue, in her account, was structural and cultural—not a failure of individual competence. When no shared operating mechanism connects the functions, executives and project teams become informal integrators, often too late to prevent rework. Ewbank’s CIO opinion article includes a disclaimer that its views do not represent an official U.S. government position or CIA authentication.
What the CIA account does—and does not—establish
Ewbank says she took on the CIA digital-innovation role in 2019 and describes bringing the CIO, CISO, and chief data officer into closer strategic alignment. She says the approach was tested on a project intended to shorten the path from worldwide data collection to availability in enterprise analytics tools. That work, as she recounts it, depended on infrastructure, data governance, secure communications, and cybersecurity controls being coordinated.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
She reports that involving security at the architecture stage helped avoid retrofits and rework and accelerated deployment. The published account does not provide independently verifiable performance figures, a baseline comparison, budget, or detailed operational architecture. The pilot’s objective should not be mistaken for a publicly documented result. Treat the example as a practitioner’s account and a prompt for organizational design—not proof that a particular structure will produce a specific speed or security gain. CIO’s author profile identifies Ewbank as a former CIA deputy director for digital innovation.
Build an operating model, not another executive layer
The practical lesson is shared planning and accountability, not a new reporting line or standing committee. Each leader retains a distinct remit while making cross-functional decisions early enough to affect the design.
- CIO: Owns infrastructure, platforms, modernization, workforce access, and operational scalability.
- CISO: Leads cyber-risk strategy, security architecture, resilience, controls, and incident readiness. Collaboration should not erase independent risk escalation.
- CDO: Leads data governance, quality, classification, access policy, and the conditions that make analytics and AI usable.
- Business or mission owner: Defines the outcome users need, owns the product or service after launch, and is accountable for business decisions and accepted residual risk.
- CEO, COO, or transformation sponsor: Resolves priority conflicts that the functional leaders cannot settle and ties investment to enterprise outcomes.
Make the model concrete with a shared strategic backlog, joint prioritization for major initiatives, common outcome measures, early architecture reviews, explicit decision rights, and a defined escalation route. Keep executive alignment regular enough to resolve material choices, but do not turn it into a status-meeting ritual.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Choose a pilot that exposes the seams
A useful pilot has a real user outcome and forces infrastructure, data, and security decisions to meet. It should be important enough to reveal silo friction, bounded enough to deliver within a defined period, and sponsored by an executive who can remove blockers. A technical demo with no user value is unlikely to change how leaders work.
Potential pilots include a secure AI assistant using sensitive internal information, identity modernization for a hybrid workforce, real-time fraud or threat analytics, a regulated cloud workload, or a secure data-sharing service across business units. Define the outcome and baseline before work begins; the pilot is a way to test the operating model, not automatic proof that it will scale.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Make security by design a set of early decisions
“Security by design” should change architecture and product requirements before implementation—not merely add a review meeting. At the start of a pilot, agree on:
- Data classification, handling, retention, lineage, and residency constraints.
- Which people, devices, services, and third parties need access, and how least privilege and privileged access will work.
- Threat scenarios and the preventive, detective, and recovery controls needed to address them.
- Logging, monitoring, incident response, availability, and recovery expectations.
- Regulatory, contractual, privacy, and intellectual-property constraints.
- Security and data acceptance criteria for release, plus automated policy checks in build and deployment pipelines where practical.
- An exception process naming an accountable owner, the rationale, and an expiration or review date.
The CISO should be able to raise risk independently; “early involvement” does not mean unanimous security approval for every decision. The business owner should accept business risk within delegated authority, with material risks escalated through the organization’s established governance.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →NIST’s SP 1800-35 describes example zero-trust implementations supporting secure access to distributed on-premises and cloud resources for hybrid users and partners. Its implementation project documentation covers 19 example implementations developed with commercial technology collaborators. These are implementation resources, not evidence that buying a product or adopting a label resolves organizational fragmentation.
Connect executive roles to zero trust
Zero trust is a useful way to connect governance choices to technical work, but Ewbank’s account does not establish that the CIA pilot formally used a zero-trust framework. CISA’s maturity model groups capabilities into five pillars and three cross-cutting areas:
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
| Digital C-suite concern | Related zero-trust work |
|---|---|
| CIO: infrastructure and platforms | Devices, networks and environments, applications, and workloads |
| CISO: risk and control strategy | Identity policy, enforcement, monitoring, and response |
| CDO: data governance | Data classification, access, lineage, and protection |
| Shared leadership | Governance, visibility and analytics, and automation and orchestration |
CISA’s Zero Trust Maturity Model describes four maturity stages: Traditional, Initial, Advanced, and Optimal. Use it to identify gaps and sequence work, not as a mandate to buy a particular product or to create a particular executive structure. Microsoft’s zero-trust adoption overview also frames security as a shared business responsibility involving executive and operational stakeholders.
Measure the joint outcome, not just departmental activity
Agree on a small scorecard before the pilot starts. Department-specific measures such as patch counts, uptime, or catalog entries may be useful locally, but they cannot show whether a cross-functional service became safer and more usable. Select measures that fit the initiative and establish baselines rather than promising universal targets.
Recommended Free Tools
- Delivery and user value: Time from approved concept to production; time from data collection to authorized analytical use; user adoption and task completion; availability and recovery performance.
- Rework and readiness: Share of initiatives defining security and data requirements before build; late architecture changes; rework tied to security, privacy, or data quality.
- Security posture: Phishing-resistant MFA coverage; privileged access under just-in-time or just-enough controls; significant-incident detection and containment times; critical assets with an owner; overdue high-risk vulnerabilities; logging coverage; count and age of exceptions.
- Data health: Critical data products with owners and quality thresholds; lineage and classification coverage; duplicate sources resolved; time to approve legitimate access; AI use cases with documented provenance, access, and retention controls.
- Governance: Decisions made within agreed service levels; unresolved escalations; strategic initiatives with one accountable executive; overlapping platforms or controls consolidated; participation in cross-functional staffing or rotations.
Not every metric belongs in every pilot. Choose a handful that reveal whether users receive the intended capability, risk is controlled, and teams are making decisions earlier.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Use AI to test the partnership, not to assume away risk
AI can be a demanding shared initiative because it combines compute and infrastructure choices with data quality, access, privacy, intellectual property, identity, application security, vendor dependencies, monitoring, and business accountability. Executive alignment improves the chance that risks are identified early and assigned; it does not eliminate them.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- CIO: Determine whether the infrastructure can scale and be supported.
- CDO: Establish whether the data is fit for purpose, governed, and appropriately accessible.
- CISO: Assess identities, data flows, models, applications, suppliers, monitoring, and response needs.
- Business owner: Define the value, acceptable risk, users, and accountable product owner.
- All parties: Agree on release gates, exception handling, and post-deployment monitoring.
Develop leaders who can translate across functions
Ewbank says the CIA encouraged officers to rotate across the digital directorate, helping technical specialists understand security constraints, security professionals see operational urgency, and data specialists encounter infrastructure realities. For other organizations, rotations can build translators without replacing specialist expertise.
Start with roles where adjacent knowledge improves decisions: product managers, architects, security engineers, data stewards, and operations leads. Set a defined rotation period long enough for practical exposure, preserve specialist career paths, and recognize cross-functional work in promotion decisions. Respect access restrictions in sensitive environments. Measure whether rotations reduce handoff delays, improve decision quality, or lower avoidable rework rather than treating participation itself as success.
Where the model can fail
- Relabeling without changing behavior: A “digital C-suite” name has little value without joint priorities, decision rights, and shared measures.
- Committee creep: Use the shared backlog and architecture review to make decisions; avoid adding a meeting that only reports status.
- Blurring accountability: Shared delivery does not mean nobody owns the product, the data, or accepted risk. Name the accountable decision-maker.
- Weakening CISO independence: Partnership should not subordinate risk escalation to delivery pressure or make the CISO responsible for every technology choice.
- Over-restricting data: Governance should enable legitimate analytics through clear access rules, not become a blanket barrier.
- Tool-led integration: Consolidating security or cloud platforms can reduce duplication, but can also increase vendor concentration and switching costs. Decide ownership and interoperability needs before procurement.
- Scaling too broadly too soon: Start with a bounded initiative; trying to integrate every program simultaneously can overwhelm specialists and slow delivery.
Where the main gap is portfolio coordination, a transformation office may help; an enterprise architecture board can address technical consistency; a product operating model can embed specialists with durable delivery teams; and federated governance may suit autonomous business units. A CIO–CISO partnership may be enough where data governance is decentralized or no CDO role exists. None substitutes for clear ownership, common standards, and an escalation path.
Quick Recap
A 90-day starting sequence
Days 1–30: Set the mandate
- Inventory major initiatives and identify recurring friction among technology, security, and data teams.
- Name the CIO, CISO, and CDO counterparts, the business owner, and an executive sponsor.
- Agree on a short charter, decision rights, risk-acceptance authority, and escalation route.
- Select one bounded pilot with a meaningful user outcome and baseline measures.
Days 31–60: Design together
- Run a joint architecture and risk review before the build is underway.
- Map critical data, identities, applications, dependencies, and relevant constraints.
- Set data and security acceptance criteria, release gates, and exception ownership.
- Put the work in a shared backlog and document who resolves conflicts.
Days 61–90: Evaluate and decide
- Deliver a defined production milestone rather than treating a demo as proof of success.
- Compare results with baseline measures for delivery time, rework, access friction, user value, and control coverage.
- Review open exceptions, unresolved ownership, and lessons from cross-functional handoffs.
- Decide which practices should become standard and share the scorecard with executive leadership.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

