Sony’s absence of a CISO does not mean the company failed to have security professionals managing this function. Industry experts say Sony has historically addressed information security at its multitude of business units, not at headquarters. Sony has acquired more than three new businesses a year since 1983. Having a corporate CISO isn’t just the best option – it’s the only one, experts say. Having one improves the company’s ability to manage the risk, and if breached, more effectively respond, expert says.”]
Source: https://www.inforisktoday.com/blogs/how-could-sony-have-ciso-p-941

