Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A CISO and CMO build trust before a cyber crisis by working together on real marketing decisions—not by waiting until an incident forces them into the same room. Regular contact, clear decision roles, agreed rules for sharing sensitive information, and jointly prepared customer and employee communications make it easier to act quickly without losing sight of security, business needs, or brand credibility.

Why marketing and security need a working relationship

Marketing depends on customer data and technology to understand audiences, personalize experiences, and run campaigns. Security leaders must help the organization manage the exposure that comes with collecting, storing, using, and exchanging that information. Those responsibilities can create friction, but they are not inherently opposed: responsible data use and protecting customer trust are shared business concerns.

A CMO Council and KPMG study of 256 North American marketing leaders across multiple industries found that 79% considered the marketing-security partnership very or extremely important for acquiring, maintaining, and securing customer data for competitive advantage. The same study reported that 33% of partnerships were not collaborating effectively. These are findings from that study, not estimates for every organization. CMO Council and KPMG study summary

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The gap matters before an incident, not just during one. In the same study, 32% of less collaborative partnerships communicated only during a crisis. The CMO Council also reported that 84% of marketing leaders said AI and machine learning initiatives posed a growing security threat. For a CISO and CMO, these figures point to practical discussion topics: how teams communicate, which initiatives need security input, and how decisions will be made when a customer-facing problem emerges. CMO Council and KPMG study summary

What to establish before an incident

Set a useful contact rhythm

Agree on recurring contact that fits the organization’s pace of marketing activity and security risk. The sources do not prescribe a universal meeting schedule, so choose a cadence that keeps the CISO informed about meaningful changes without turning every routine campaign into an escalation. Use the time to explain responsibilities, surface upcoming decisions, and resolve questions while there is room to deliberate.

The CMO Council and KPMG recommend more frequent, easier communication and training or education that clarifies roles and responsibilities. Their study does not establish a particular meeting frequency as best practice. CMO Council and KPMG recommendations

Discuss actual data uses and planned changes

Use concrete marketing activity as the agenda, rather than talking about risk in the abstract. Relevant prompts include:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • What customer or behavioral data will a campaign collect, and how will it be stored and used?
  • Will a new tool, AI or machine-learning initiative, or connected device change how data is handled?
  • What security questions should be addressed during a technology assessment, before a decision is made?
  • Who needs to review a material change, and when must that review happen?

The CMO Council and KPMG study identifies customer behavior data, AI and machine learning, and Internet of Things initiatives among marketing activities with security implications. Bringing planned data practices and assessments into routine discussion lets each leader explain constraints and business goals early. CMO Council and KPMG study summary

Define roles and escalation decisions

Agree who identifies and assesses a suspected incident, who can pause or change a campaign, who approves external statements, and how unresolved disagreements reach the executives with authority to decide. Also distinguish technical findings from business choices: security can explain what is known about exposure and uncertainty, while marketing can explain audience expectations, brand consequences, and the practical effect of a proposed response.

Write down the handoffs and decision owners in terms people can use under time pressure. Role clarity is a recommendation supported by the CMO Council and KPMG’s call for education on responsibilities; the study does not prescribe a single governance model for all organizations. CMO Council and KPMG recommendations

Agree how sensitive information is shared

Trust does not require unrestricted access. It requires a shared understanding of what information is needed, who may receive it, how it can be distributed, and how it must be protected during an exchange. Set boundaries that let marketing understand relevant risks while limiting unnecessary exposure of sensitive security or customer details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

NIST SP 800-150 recommends establishing information-sharing goals, defining the scope of sharing, and setting rules for publishing and distributing threat information. NIST SP 800-47 Rev. 1 advises organizations to identify information exchanges and protect information before, during, and after the exchange, with agreements tailored to organizational needs. These are general information-sharing practices, not a CISO-CMO-specific standard. NIST SP 800-150; NIST SP 800-47 Rev. 1

Map business and brand consequences

For important marketing activities, discuss what a disruption or data exposure could mean for customers, employees, campaigns, and operations. The point is not to turn every security issue into a brand emergency. It is to help security explain the possible impact in business terms, and to give marketing enough context to avoid minimizing a technical risk or making claims the organization cannot support.

That shared understanding can also clarify priorities: which audiences need information first, what service or campaign changes may be necessary, and what facts must be confirmed before communicating. The CMO Council’s executive director, Donovan Neale-May, described the connection directly: “A strong marketing-security partnership preserves brand reputation in an environment rife with privacy concerns, proving a strong security commitment can also help build the brand.” CMO Council and KPMG release

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Prepare communications for a cyber incident

A joint crisis communications plan should connect verified security facts with the needs of each audience. Before an incident, decide how the CISO and CMO will coordinate, who owns approval, and how updates will be handled as facts change. Preparing these decisions in advance reduces the chance that teams will improvise conflicting messages under pressure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Build a usable plan

  • Define audiences: Identify who may need updates, such as affected customers, employees, or other stakeholders, based on the organization and the incident.
  • Assign responsibilities: Set out who validates technical facts, drafts audience-specific messages, approves them, and issues updates.
  • Set message principles: Make communications clear, timely, accurate, and appropriate to the audience. State what is known, what remains uncertain, and when the organization expects to provide an update, if that timing is established.
  • Plan for changing facts: Establish how corrections and follow-up messages will be handled so that an early statement does not become a source of avoidable confusion.
  • Identify communication contingencies: Determine what alternative channels are available if normal telecommunications or service systems are disrupted.

CISA’s September 2, 2026 guidance for service providers and critical infrastructure owners and operators emphasizes clear, timely, accurate, audience-appropriate communication, along with clarity, accountability, and transparency. It also advises planning for disrupted or unreliable telecommunications and backup communication methods. That guidance is useful context for organizations whose services may be affected, but it is not a universal requirement for every company. CISA guidance on communicating service outages

Practice decisions, not just scripts

A tabletop exercise can help the CISO, CMO, and other decision-makers test who does what when facts are incomplete, a campaign is live, or a normal communication channel is unavailable. Use a realistic scenario to walk through escalation, approvals, audience priorities, and updates as new information arrives. Treat the exercise as a practical way to rehearse the plan—not as a proven guarantee of trust or better incident outcomes.

The available guidance supports advance role education and communication planning, but it does not establish that one exercise format produces a quantified improvement. Adapt the scenario and participants to the organization’s operations and responsibilities. CISA outage communications guidance; CMO Council and KPMG recommendations

Keep the partnership practical

The relationship is useful when it changes how decisions are made: security hears about meaningful marketing plans early enough to advise, marketing understands relevant risks and escalation paths, and both can coordinate communications without confusing technical uncertainty for confirmed fact. The cited studies and guidance support these practices, but do not prove that an alliance alone creates trust, prevents incidents, or improves outcomes by a measurable amount.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.