Winging It · Implausible Deniability
Nobody grows up wanting to be a CISO. I'm reasonably confident of this. I've had this conversation with roughly two hundred of them, across multiple continents, at conferences and in boardrooms and in hotel bars where the truth comes out more easily, and not one of them has ever said "I planned this." What they say, almost without exception, is some version of "I sort of ended up here," followed by a pause, followed by a drink.
I sort of ended up here too. I started doing IT security for the SAS, where all the users were trained to kill people but still couldn't remember their passwords. If that doesn't prepare you for a career in security leadership, nothing will.
But my route is unremarkable. Everyone's route is unremarkable. That's the point. The career path into security leadership does not exist in any meaningful sense. There is no degree, no graduate scheme. What exists is a series of accidents. Someone leaves. Someone gets promoted sideways. A regulation lands and suddenly the organisation needs a person who can talk about risk to people who don't want to hear about risk. You are in the room. You get the job.
I once sat next to a CISO at a conference dinner who started in facilities management. Facilities. He'd been responsible for building access, which someone decided was close enough to information access, and before he knew it he was presenting to a board about threat landscapes. He told me this over his third glass of wine with the expression of a man who'd been carried downstream and washed up somewhere unexpected. "I used to worry about fire exits," he said. "Now I worry about everything else."
He is not unusual. I have met CISOs who started in help desk support. CISOs who started in software development. A CISO who started as a network engineer and still, fifteen years later, looked slightly startled to be in the room. One told me she'd been an accountant. An accountant. She said the jump to security made perfect sense because both jobs involve staring at spreadsheets and telling people things they don't want to hear. I couldn't argue with that.
The thing they all have in common, every single one, is the moment they realised the job isn't technical. This comes up in every honest conversation I've had with a CISO, usually after the first drink. They arrived thinking they'd be making decisions about architecture and tooling and threat detection. What they actually do is sit in meetings. So many meetings. Meetings about risk appetite. Meetings about budget. Meetings scheduled to discuss why last week's meeting, which was scheduled to discuss why the meeting before that hadn't achieved anything, hadn't achieved anything.
One CISO I know, an engineer who'd spent a decade building things before taking the role, described her first month as "the longest PowerPoint of my life." The explaining never stopped. "I used to build things," she said. "Now I produce slides explaining why the things other people built aren't finished yet."
A CISO I met at a conference bar, a man who once built firewall rules for a living, told me he now spends eighty percent of his time producing slides about risk for people who will look at the slides, nod, and ask "so are we safe?" He said this with the quiet fury of a surgeon being asked to summarise an operation using only traffic lights.
The board presentation comes up in every conversation. Every CISO has a version of this story. One told me he'd prepared forty slides for his first board meeting. Forty. He got through three. The chair cut him off and asked for a single number that represented their security risk. He made one up on the spot. "I said seventy-two," he told me. "Out of what, I have no idea. But they loved it. They put it on the quarterly report. I've been making up that number ever since." He paused. "I've started to believe in it myself, which is when I knew I'd been in the job too long."
Another told me the worst part wasn't the board. It was the Tuesday morning leadership meeting where someone from sales would casually mention they'd promised a client something that required security sign-off, and the sign-off was needed by Thursday, and nobody had told her until that moment. "I used to solve problems," she said. "Now I find out about problems three days after everyone else has already committed to a solution."
The loneliness comes up late in the evening, when the conference bar is thinning out. A CISO I'd been drinking with for two hours, a man who ran security for a company most people would recognise, told me about his Sunday night ritual. He'd open the risk register on his laptop. Look at the items that had been sitting there for two years with a status of "in progress" the way a stopped clock says the time. Close the laptop. Pour a glass of cooking sherry, which he admitted was what happened to be nearest. And think about the five things he couldn't tell the board because saying them out loud would either cause a panic or create a liability, and he hadn't yet worked out which was worse. "Every Sunday," he said. "For about forty minutes. Then I go to bed and try not to think about Monday."
Every CISO I've spoken to honestly, after the professional guard drops, says some version of the same thing.
"I didn't plan this. I don't always know what I'm doing. And I can't tell anyone."
Then they order another drink. And I order one too. And somewhere, a risk register gets another day older.
— Chris
