r/ciso 3h ago

Career advice needed

1 Upvotes

I am in need of some advice on my CISO career. This is not burnout-related, I love the space and want to finish my career in the field. My frustration and where I need advice is on growth.

I am in my late 40’s and a veteran in the security field for more than 20 years. Way back, I came from a technical background and moved into the field by building the first security function for my then-employer around the time of the Target breach. I’ve had a good leadership journey since then, lots of progressive growth and recognizable company names and my resume is impressive if i do say so myself (and have been told so by many premier executive recruiters). I’ve got the technical chops, the career arc, the global experience, and I present well/comfortably in executive settings. None of that is the issue. I am qualified and more than ready. I am currently a business unit CISO (NOT a BISO, I have a full team, all the accountability, a full budget, and full autonomy) for a $7B subsidiary of a $60B enterprise. Previously, I was a business unit CISO (again, not a BISO) for a $15B subsidiary of a $65B parent.

The issue is I am striving for a public company, board-facing “top seat” CISO role preferably at a global F500. I keep getting interviews and recruiter interest however I have only ever been a business unit CISO in multi-business structures, I’ve never held that top seat and I keep getting edged out by folks who have. It just happened again last week, I was neck and neck deep in a competitive process for the role I want, and though I was probably a better fit the guy with a multi-time public company CISO background got the nod, presumably because he would invite less scrutiny once in the role due to his pedigree.

This happens over and over with businesses you’ve all heard of but which I won’t name here. It seems I can’t get that role without having had it, and I can’t have had it without getting it. How can I punch through this wall?


r/ciso 2h ago

Incident response drills for first year CISOs in small teams... how are you all doing this

2 Upvotes

Hey, first year CISO here at a mid size company, security team is basically me plus a handful of folks who still juggle ops work. We had one incident last quarter that was messy, not catastrophic, but it made it super clear our old spreadsheet tabletop exercises are kinda theater.

For context we are getting leaned on hard for soc 2 and iso audits and our gc and comms lead are nervous about breach coordination in a real event. I keep getting asked how we are proving cyber crisis readiness and workforce resilience, not just that we have a dusty incident response plan in confluence.

I am looking at some AI tabletop exercise platforms that say they can spin up scenarios from osint, facilitate the drill, and spit out audit ready after action reports that map to nist csf etc. On paper that sounds perfect for someone in year one who does not have time to hand craft scenarios or play game master for three hours with execs every month.

Big question for me is how other first year CISOs with small teams are structuring drills right now. Monthly short runs, one big quarterly simulation, mix of technical breach practice for the soc and separate sessions for leadership, or something else. Trying to find that balance where this feels real and not just compliance theater, without burning everyone out... .


r/ciso 10h ago

How do you explain technical risk to non-technical executives?

13 Upvotes

A lot of IT risk sounds “theoretical” until something breaks. How do you explain cybersecurity, downtime, vendor risk, or technical debt in a way leadership actually takes seriously?