For Elliott Franklin, one principle has remained consistent across more than two decades in technology and security leadership: people come first, followed by process, and only then technology. It is a perspective shaped by a career spanning highly regulated industries and organizations across reinsurance, financial services, hospitality, restaurants, and SaaS, and one that challenges the tendency to treat cybersecurity primarily as a technology problem.
Today, as SVP and CISO at Fortitude Re, Elliott leads information security, identity, cloud security, and AI governance across a global, multi-jurisdictional environment. Her experience is especially valuable for CISO Diaries, where the focus extends beyond security strategy to the people, habits, pressures, and decisions behind the role. In this conversation, Elliott brings a distinctly human perspective to security leadership, examining the impact of burnout, organizational culture, and the realities of leading teams in an industry where the tools may change quickly, but the people responsible for using them remain at the center of everything.
How do you usually explain what you do to someone outside of cybersecurity?
I tell them I’m an ethical hacker and that I try to keep the bad guys out of companies. Most people don’t expect that answer, and it usually starts a better conversation than a job title would. Honestly, I’m not even sure what my kids tell their friends I do. Probably that their dad is a technology geek, which is fair.
What does a “routine” workday look like for you, if such a thing exists?
It doesn’t exist. I check overnight alerts with my coffee, and after that the calendar is a suggestion. Some days it’s all one-on-ones with my team. Some days I’m in front of the board. Some days a single email blows up the whole plan. The one rule I hold myself to is that nobody on my team should be stuck at the end of the day waiting on a decision from me. Everything else is negotiable.
What part of your role takes the most mental energy right now?
- Employees are going to use these tools whether security approves them or not, so the job is building guardrails fast enough that people don’t route around us. Saying no is easy and useless. Finding a safe yes takes real work, and the ground shifts every day. That’s where my brain goes most days.
What’s one security habit or routine you personally never skip?
It’s not a technical one. I move my body every day, whether that’s a real workout or just a long walk, and I write in my journal. I learned the hard way that burnout is basically a denial-of-service attack you run on yourself. Early in my career I let this industry take everything, and my health and my family paid for it. The daily movement and the journal are how I stay ahead of that now. A burned-out defender protects nothing, so I treat those habits as seriously as any control on my network.
What does your own personal security setup look like?
I’m going to stay vague on purpose. A CISO listing his exact tools in an article is basically publishing a targeting guide, and I’d tell any security leader the same thing. Broad strokes: password manager, MFA, backups, auto updates, and credit freezes for the whole family. Nothing fancy. The boring stuff done every single time is what works.
What book, podcast, or resource has influenced how you think about leadership or security?
Two, actually, and neither is a security book. The Five Dysfunctions of a Team by Patrick Lencioni changed how I lead. Security programs don’t fail because the firewall was bad. They fail because people don’t trust each other, dodge hard conversations, and leave meetings without real commitment. I put my own leadership team through Lencioni’s framework at our last offsite and it changed how we argue. In a good way.
The other is Yeah, But… by Marc Wolfe. It’s about the excuses we make to ourselves, all the “yeah, buts” that keep us stuck. In a field where it’s easy to hide behind being busy, that book called me out. I’ve worked with Marc directly, and his stuff shows up in how I coach my team as much as anything technical ever has.
What’s a lesson you learned the hard way in your career?
That being the hero is actually a failure mode. For years I measured my worth by being the guy who handled everything. Every incident, every escalation, every 2 a.m. call — mine. I told myself I was protecting my team. What I was really doing was making myself a single point of failure and robbing good people of the chance to grow. The moment I started delegating the hard stuff and letting my team own outcomes, everything got better. They got stronger, I got saner, and the program got more resilient. Turns out the hero complex is just fragility with good PR.
What keeps you up at night right now, from a security perspective?
People getting conned, not systems getting hacked. Attackers call the help desk pretending to be an employee. They bomb someone with MFA prompts until the person taps approve just to make it stop. And now AI can fake a voice on a phone call well enough to fool a spouse, let alone a coworker. You can’t patch a human. Culture and verification habits are the defense, and those take years to build.
How do you measure whether your security program is actually working?
Not with blocked-email counts. Those numbers are for making slides look impressive. I watch how fast we detect and contain real issues, and whether that’s getting faster. I watch whether employees report phishing quicker than they click it. And my favorite signal isn’t a metric at all: do business leaders pull security into projects early, on their own? If they do, the program is working. If they hide projects from you, it isn’t, no matter what the dashboard says.
What advice would you give to someone stepping into their first CISO role today?
Listen and ask a lot of questions for your first ninety days. You’ll learn more about the real risks from those conversations than from any assessment. Meet your peers in legal, HR, and finance before you need them, because someday you’ll need them at 2 a.m. You were hired to manage risk, not eliminate it, and the fastest way to become irrelevant is to say no to everything. And watch your people for burnout. This industry chews folks up quietly, and no tool on your shelf fixes an exhausted team.
What do you think will matter less in security five to ten years from now?
Passwords. Passkeys are actually winning and I won’t miss the old world at all. The office network perimeter keeps mattering less every year. And I think “we passed the audit” is losing its power as a security answer. Boards are getting sharper and they’ve figured out that a clean checklist and an actual defense aren’t the same thing.
Looking ahead 10 years, what do you believe security teams will spend most of their time on that they don’t today?
Managing machines that act on our behalf. AI agents are going to hold credentials and take actions faster than any human team can review, so the job shifts from chasing alerts to setting the rules those systems have to live within and proving they do. The other one is authenticity. Proving a voice, a video, or a document is real is a side concern today. In ten years I think it’s a core function on every security team.

