Meta has appointed a new Chief Information Security Officer (CISO), bringing to an end a leadership gap left by the departure of longtime executive Guy Rosen in June 2026. The move restores executive oversight of one of the company's most critical functions at a time when cyberattacks, AI-enabled threats, and increasing regulatory scrutiny are reshaping the cybersecurity landscape. While Meta has not publicly disclosed extensive details regarding the transition, the appointment signals that cybersecurity governance has once again become a board-level priority for the company.
Guy Rosen originally became Meta's first-ever CISO in June 2022 after nearly a decade leading the company's integrity and product safety initiatives. Before assuming the CISO position, Rosen was responsible for combating misinformation, coordinating influence operations, addressing election interference, and addressing platform abuse—areas that became increasingly important following criticism of Facebook's role in multiple global elections. His appointment in 2022 reflected Meta's recognition that security extended beyond traditional infrastructure protection to include platform integrity, user trust, and digital safety.
Why the Vacancy Raised Concerns
Unlike many Fortune 500 companies that maintain a permanent and highly visible CISO, Meta reportedly operated for several months without a publicly identified security chief after Rosen's departure. Although internal security teams continued functioning, the absence of a named executive responsible for enterprise cybersecurity raised governance concerns among analysts and investors.
The CISO role at Meta oversees several high-risk domains, including:
- Enterprise cybersecurity
- Cloud and infrastructure security
- Protection of billions of user accounts
- Incident response and threat intelligence
- Regulatory compliance
- Security architecture for AI systems
- Insider risk management
- Coordination with governments and law enforcement during major cyber incidents
Given Meta's massive global footprint—including Facebook, Instagram, WhatsApp, Messenger, Threads, Quest VR and AI platforms—even a short leadership gap attracts attention from regulators and institutional investors.
Cybersecurity Challenges Facing Meta
The appointment comes during one of the most challenging cybersecurity environments the company has faced.
1. AI-driven cyber threats
Generative AI has significantly lowered the barrier for cybercriminals. Attackers now use AI to generate convincing phishing emails, deepfake audio and video, malware variants, and automated reconnaissance tools. Large technology companies must defend not only their own infrastructure but also the billions of users they serve against increasingly sophisticated attacks.
2. Massive data protection responsibilities
Meta stores enormous volumes of personal information, including:
- User identities
- Private communications
- Business messaging
- Payment information
- Location data
- Advertising profiles
This makes the company one of the world's most attractive targets for nation-state hackers, financially motivated cybercriminals, and insider threats.
3. Increasing regulatory pressure
Meta continues to face regulatory oversight from authorities worldwide, including:
- EU General Data Protection Regulation (GDPR)
- Digital Services Act (DSA)
- Digital Markets Act (DMA)
- U.S. Federal Trade Commission (FTC)
- Various state privacy laws, such as California's CCPA/CPRA
The CISO plays a critical role in demonstrating compliance with security and privacy obligations.
4. Infrastructure security
Meta operates one of the world's largest private infrastructures, comprising:
- Global data centres
- Custom AI hardware
- Large-scale networking systems
- Cloud platforms
- Content delivery infrastructure
Protecting this infrastructure against ransomware, supply-chain attacks, zero-day exploits, and nation-state campaigns requires continuous investment and executive oversight.
Broader Industry Trend
Meta's appointment reflects a wider trend across the technology sector, where organisations are strengthening cybersecurity leadership in response to escalating threats. During 2026, several major technology companies—including GitLab, Infoblox, Coinbase, Uber, and others—appointed new CISOs with expertise in cloud security, AI governance, and cyber resilience.
Security leadership is evolving beyond traditional IT protection. Modern CISOs are increasingly responsible for:
- AI security governance
- Third-party and supply-chain risk
- Cloud-native security
- Regulatory compliance
- Cyber resilience planning
- Board-level cyber risk reporting
- Business continuity and crisis management
Why This Appointment Matters
Although the appointment may appear to be a routine executive change, it carries broader strategic significance. Cybersecurity has become a core business function rather than solely a technical responsibility. For Meta, whose platforms serve billions of users and support global digital communications, a dedicated CISO is essential for maintaining trust, ensuring regulatory compliance, and protecting critical infrastructure.
The new CISO will be expected to integrate security across Meta's expanding AI initiatives, safeguard user data, and strengthen the company's defences against increasingly complex cyber threats. As governments worldwide tighten cybersecurity regulations and AI introduces new attack vectors, strong executive security leadership will remain central to Meta's long-term strategy.
A Chief Information Security Officer (CISO) is the senior executive responsible for an organization's overall information security and cybersecurity strategy. The CISO's primary objective is to protect the organisation's information assets, technology infrastructure, employees, customers, and reputation from cyber threats while enabling business growth.
Key Roles and Responsibilities of a CISO
1. Develop Cybersecurity Strategy
- Define the organisation's cybersecurity vision and long-term security roadmap.
- Align security initiatives with business objectives.
- Establish cybersecurity policies, standards, and governance frameworks.
2. Protect Information Assets
- Safeguard sensitive data, including customer information, intellectual property, financial records, and employee data.
- Implement data classification, encryption, backup, and access control policies.
- Ensure data confidentiality, integrity, and availability (CIA Triad).
3. Risk Management
- Identify and assess cyber risks across the organisation.
- Conduct regular risk assessments and vulnerability analyses.
- Recommend mitigation strategies and prioritise security investments.
4. Security Operations
- Oversee Security Operations Centres (SOC).
- Monitor networks for suspicious activities.
- Manage endpoint, cloud, network, and application security.
- Coordinate incident detection and response.
5. Incident Response and Crisis Management
- Lead the organisation's response to cyberattacks, ransomware incidents, and data breaches.
- Coordinate with legal, communications, executive leadership, and law enforcement.
- Conduct post-incident investigations and implement lessons learned.
6. Regulatory Compliance
Ensure compliance with applicable laws and industry standards, such as:
- ISO/IEC 27001
- NIST Cybersecurity Framework
- PCI DSS
- GDPR
- HIPAA
- SOC 2
- India's Digital Personal Data Protection (DPDP) Act (where applicable)
7. Security Architecture
- Approve secure system and network designs.
- Guide the adoption of Zero Trust Architecture.
- Secure cloud environments, APIs, and enterprise applications.
8. Identity and Access Management (IAM)
- Implement least-privilege access.
- Oversee multi-factor authentication (MFA).
- Manage privileged access and identity governance.
9. Third-Party and Supply Chain Security
- Assess vendors and partners for cybersecurity risks.
- Review contractual security requirements.
- Monitor supply chain vulnerabilities.
10. Employee Security Awareness
- Promote a culture of cybersecurity.
- Conduct phishing simulations and awareness training.
- Develop policies for secure remote work and acceptable use.
11. Business Continuity and Disaster Recovery
- Develop disaster recovery and business continuity plans.
- Ensure systems can recover quickly after disruptions.
- Regularly test recovery procedures.
12. Executive and Board Reporting
- Present cybersecurity risks and performance metrics to executive leadership and the board.
- Translate technical risks into business terms.
- Justify security budgets and investments.
13. Emerging Technology Security
- Secure AI, machine learning, IoT, blockchain, and cloud technologies.
- Evaluate risks associated with new digital initiatives before deployment.
Essential Skills of a CISO
Technical Skills
- Network security
- Cloud security (AWS, Azure, Google Cloud)
- Application security
- Identity and Access Management (IAM)
- Threat intelligence
- Digital forensics
- Malware analysis
- Security architecture
- Penetration testing concepts
- Vulnerability management
Business Skills
- Leadership
- Strategic planning
- Risk management
- Budgeting
- Vendor management
- Governance
- Communication
- Negotiation
- Decision-making
- Change management
Soft Skills
- Crisis leadership
- Problem-solving
- Team building
- Public speaking
- Executive communication
- Stakeholder management
Typical Reporting Structure
The CISO may report to:
- Chief Executive Officer (CEO)
- Chief Information Officer (CIO)
- Chief Operating Officer (COO)
- Chief Risk Officer (CRO)
- Board of Directors or Audit Committee (in some organisations)
In mature organisations, the CISO often has direct or independent access to the board to ensure cybersecurity risks receive appropriate oversight.
Common Teams Reporting to a CISO
- Security Operations Centre (SOC)
- Incident Response Team
- Threat Intelligence
- Governance, Risk & Compliance (GRC)
- Identity & Access Management
- Cloud Security
- Application Security (AppSec)
- Security Engineering
- Vulnerability Management
- Digital Forensics
- Security Awareness & Training
Key Performance Indicators (KPIs)
A CISO commonly tracks:
- Mean Time to Detect (MTTD)
- Mean Time to Respond (MTTR)
- Number of critical vulnerabilities remediated
- Patch compliance rate
- Phishing simulation success/failure rates
- Multi-factor authentication adoption
- Security audit findings
- Regulatory compliance status
- Third-party risk assessments completed
- Security incidents by severity
- Ransomware resilience and recovery time
Importance of the Role
The CISO has evolved from being primarily a technical security leader to a strategic business executive. Modern CISOs help organisations:
- Protect customer trust and corporate reputation.
- Reduce financial losses from cyber incidents.
- Meet legal and regulatory obligations.
- Enable secure digital transformation and AI adoption.
- Strengthen resilience against increasingly sophisticated cyber threats.
In organisations such as Meta, Google, Microsoft, or Amazon, the CISO's responsibilities extend beyond protecting internal systems—they also include safeguarding platforms used by billions of people, defending against nation-state threats, ensuring the security of AI technologies, and maintaining compliance across multiple jurisdictions.

.jpg)