The First CISO Seat

Related

Solana Foundation Appoints Michael Coates as CISO

What happened Michael Coates has joined the Solana Foundation as...

Philip Martin Joins Uber as Chief Information Security Officer

What happened Philip Martin has joined Uber as Chief Information...

Socure Appoints Mark Carter as Chief Information Security Officer

What happened Socure appointed Mark Carter as its Chief Information...

SolarWinds Appoints Justin Henkel as Chief Information Security Officer

What happened SolarWinds appointed Justin Henkel as its Chief Information...

Share

Sooner or later somebody you managed or mentored will call to say they have been offered a  CISO role, the first one of their career. The instinct is to congratulate them, and you should. But  then you should encourage them to do a little digging before they answer. 

I ran corporate security teams in a highly regulated environment for 15 years. Since then I have  spent most of my time inside companies the size of the ones that make these first time CISO  offers, often well before they make one. Here is what I would recommend. 

Find out why the seat exists. If the company has never had a CISO, something specific opened  it. A customer contract, an incident somebody is still angry about, a failed audit, an insurance  renewal. Whatever it was is the real job for the first year at least. Either of the last two usually  produces a documentation job with a leadership title on it. Ask which one it was. 

If there was a predecessor, the question is why they are gone? Someone who left for a bigger  seat should leave a program behind along with some goodwill. Someone who was pushed out  leaves a board that has likely already made up its mind about the function, and a team that  watched it happen. Your friend may inherit that view without anyone mentioning it in the  interview. 

Count the people who do the work. Ask how many will report to them. Then ask how many of  those do security full time. At a mid-sized company the answer is often one, and that person  usually handles a good deal of IT as well. That is workable as a starting point. Whether it is a  starting point or a ceiling is the thing to find out, and the tell is what happens when the  conversation turns to a second hire. 

Check that the security budget moves with the technology plan. Don’t skip this one. Nearly  every company I work with in this range has an AI initiative running or about to start. New  tooling, data moving to places nobody has mapped, vendors to review, and a leadership team that  wants it live this year. Ask what the security budget does over the same period. If the plan is  growing and the budget is flat, your friend is the plan for closing that gap. They can spend a long  stretch reviewing other people’s initiatives without the capacity to secure any of them. 

A fair number of those companies never needed a CISO. They needed a competent IT lead and a  few days a month of senior security judgment, and they wrote a manager job description with a  CISO title instead. As a fractional CISO, that senior security judgment is the role I fill now, so  weigh it accordingly.  

The cost of a bad job is mostly theirs. A short, underpowered CISO tenure is hard to explain  later. It looks like eighteen months in the seat and a program nobody can point to. The company  moves on. Your friend is the one answering questions about it for a while. 

When the basics hold, it is a good job. There should be real budget authority, even a modest  amount. The reporting line should ideally run to the CEO or the general counsel rather than three 

levels down inside IT. There should be at least one person who does the work. And whatever is  driving the hire should still be there in six months. When those hold, a first CISO job at a mid sized company can be a better seat than a deputy role at a large one, because they will own the  whole function. Tell them to go. 

Most of this comes down to whether the company wants a security program or wants to be able  to say it has one. Both are real answers, and the second one is not always a bad job. It is just a  different job than the title suggests.

Bart Lane
Website |  + posts

Bart Lane is the founder of P223 Consulting, a fractional CISO and security advisory practice serving mid-sized organizations in regulated industries. He spent 15 years in corporate security leadership, including five years as CISO for a Fortune 100 healthcare division. Now, he advises, builds and leads security programs for organizations without their own CISO. He also writes 'The Independent CISO' blog to support security leaders transitioning from corporate to independent roles. Bart is based in Nashville, TN. - https://theindependentciso.substack.com