Sooner or later somebody you managed or mentored will call to say they have been offered a CISO role, the first one of their career. The instinct is to congratulate them, and you should. But then you should encourage them to do a little digging before they answer.
I ran corporate security teams in a highly regulated environment for 15 years. Since then I have spent most of my time inside companies the size of the ones that make these first time CISO offers, often well before they make one. Here is what I would recommend.
Find out why the seat exists. If the company has never had a CISO, something specific opened it. A customer contract, an incident somebody is still angry about, a failed audit, an insurance renewal. Whatever it was is the real job for the first year at least. Either of the last two usually produces a documentation job with a leadership title on it. Ask which one it was.
If there was a predecessor, the question is why they are gone? Someone who left for a bigger seat should leave a program behind along with some goodwill. Someone who was pushed out leaves a board that has likely already made up its mind about the function, and a team that watched it happen. Your friend may inherit that view without anyone mentioning it in the interview.
Count the people who do the work. Ask how many will report to them. Then ask how many of those do security full time. At a mid-sized company the answer is often one, and that person usually handles a good deal of IT as well. That is workable as a starting point. Whether it is a starting point or a ceiling is the thing to find out, and the tell is what happens when the conversation turns to a second hire.
Check that the security budget moves with the technology plan. Don’t skip this one. Nearly every company I work with in this range has an AI initiative running or about to start. New tooling, data moving to places nobody has mapped, vendors to review, and a leadership team that wants it live this year. Ask what the security budget does over the same period. If the plan is growing and the budget is flat, your friend is the plan for closing that gap. They can spend a long stretch reviewing other people’s initiatives without the capacity to secure any of them.
A fair number of those companies never needed a CISO. They needed a competent IT lead and a few days a month of senior security judgment, and they wrote a manager job description with a CISO title instead. As a fractional CISO, that senior security judgment is the role I fill now, so weigh it accordingly.
The cost of a bad job is mostly theirs. A short, underpowered CISO tenure is hard to explain later. It looks like eighteen months in the seat and a program nobody can point to. The company moves on. Your friend is the one answering questions about it for a while.
When the basics hold, it is a good job. There should be real budget authority, even a modest amount. The reporting line should ideally run to the CEO or the general counsel rather than three
levels down inside IT. There should be at least one person who does the work. And whatever is driving the hire should still be there in six months. When those hold, a first CISO job at a mid sized company can be a better seat than a deputy role at a large one, because they will own the whole function. Tell them to go.
Most of this comes down to whether the company wants a security program or wants to be able to say it has one. Both are real answers, and the second one is not always a bad job. It is just a different job than the title suggests.
Bart Lane is the founder of P223 Consulting, a fractional CISO and security advisory practice serving mid-sized organizations in regulated industries. He spent 15 years in corporate security leadership, including five years as CISO for a Fortune 100 healthcare division. Now, he advises, builds and leads security programs for organizations without their own CISO. He also writes 'The Independent CISO' blog to support security leaders transitioning from corporate to independent roles. Bart is based in Nashville, TN. - https://theindependentciso.substack.com

