Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceSecurity Education & TrainingCybersecurity News

CISOs are changing their ways amid their toughest environment ever

By Robert R. Ackerman Jr.
test
September 2, 2021

Perhaps the most talked-about job in the information technology world these days is that of the chief information security officer (CISO) – the man or woman responsible for an organization’s data security and privacy. And for a good reason – nothing gets more attention in the IT world than the endless attacks on big corporations and government entities, which, on average, result in a price tag of roughly $4 million when they are successful.

So it’s hardly surprising that a triumphant CISO is primarily a leader, a manager and a communicator.


They are a technologist as well, but this typically gets less attention as a universal given. Under pressure, the horizons of CISOs are broadening. Now their top priority is to play their part in contributing to the overall success of their employer.


Those who don’t understand or meet business requirements and expectations or don’t effectively communicate don’t last, especially at public companies, dedicated by nature to build shareholder value. For this and other reasons, such as the inadequate security of far more remote workers and the explosion in phishing and ransomware attacks, this is the most challenging time ever for CISOs, and that is saying something in a perpetually stressful occupation. The average CISO stays on the job only two to three years, and a Ponemon Institute study has found that a sizable percentage of surveyed CISOs would prefer to ultimately find a job outside of IT security. This – plus the fact that more companies are hiring CISOs for the first time amid the increasing need to improve protection for IoT devices and in the cloud – is sparking a growing shortage of them.


“The market for CISOs has become very competitive,” says Michael Elmore, a CISO at global GSK Consumer Healthcare, who is typically approached for a job once or twice monthly and says his CISO friends and acquaintances tell him much the same thing.


To succeed, CISOs need all the help they can get, especially at the start of their employment, and I’ll address that momentarily. It’s noteworthy that helpful measures benefit organizations and enterprises in general, not merely individual CISOs. Given the growing CISO shortage, it’s in the interest of most organizations to keep the security leader around as long as possible. This is the case even though they are still often held in lower regard by their colleagues. Other C-suite executives do not infrequently think their relatively narrow skillset makes them insufficiently fluent in business.


To better fit into corporate environments, less multi-faceted CISOs must move beyond monitoring, repelling and responding to cyber threats to become leaders who help create an organizational culture that liberally shares cyber risk ownership. They also need to manage information risk more strategically and, as already mentioned, better integrate security cybersecurity with the business overall.


As is the case in many professions, CISOs have to lead the charge to broaden their acumen themselves – and they’re best off doing so from the get-go. Their first 90 days on the job, in particular, provide a window of opportunity for establishing their credibility and earning a vote of confidence from leadership. This requires, among other things, thoroughly assessing a corporation’s organization, technology, governance, and the processes it embraces.


Here are the steps a newly hired CISO should take:


1. Don’t wait until your first day on the job to prepare. 

Learn what you can about colleagues and staff. Try to set up meetings ahead of time with your team and key business and IT leaders, showing that relationship development is a top priority. Don’t make the mistake of approaching your new role with ad hoc communications and plans. Every company’s culture is different, and you have yet to learn it. 


2. In the first 30 days on the job, develop an understanding of your new business environment. Meet individually with the organization’s leaders and staff. Immerse yourself in the company’s geographic locations, its business partners and stakeholders, and financial and operational performance.

In addition, go out of your way to identify and engage key stakeholders, such as board members and other strategic leaders, in individual discussions to obtain additional insights and perspectives about the business. Technical staff members should be included on the list because important insights often come from all levels of the organization.


Lastly, CISOs need to familiarize themselves with current and future strategic targets to help determine areas in which security-related initiatives best meet the needs of the enterprise. All of these steps help make the new CISO a more valuable asset. In addition, talking to a multiplicity of qualified employees enhances the breadth of a cybersecurity program because a successful one almost always requires buy-in among most employees.


3. In the second 30 days on the job, independently assess the current state of cybersecurity practices. This helps identify existing cybersecurity strengths, weaknesses and threats and enables the CISO to determine the most cost-effective course of action to improve things.


4. By the start of the final 30-day period, you should have a firm grasp of the cybersecurity environment and be poised to make some changes. You can now begin designing and developing an improved strategy for IT governance and security-- one focused on resolving the identified risks and setting the stage for better risk mitigation down the road.


As more months go by, a thorough and seasoned CISO is in an excellent position to sidestep or at least mitigate cyber breaches. Sometimes the response is painful but the best option. Take a ransomware attack, for example. Should an organization pay hackers to resolve it? Law enforcement says no. But it depends. It’s costly but often less than the cost of data loss, and downtime irritates customers.


An enlightened CISO is the most qualified to weigh the pros and cons of such a decision and make the right call to mitigate trouble. This is a lot better than the wrong call. And in a world replete with chronic attacks and breaches, it’s probably the most any organization can ask for.


This article originally ran in Today’s Cybersecurity Leader, a monthly cybersecurity-focused eNewsletter for security end users, brought to you by Security Magazine. Subscribe here.


KEYWORDS: Chief Information Security Officer (CISO) cyber security organizational resilience risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Bob ackerman

Robert R. Ackerman Jr. is founder and managing director of AllegisCyber Capital and co-founder of cyber startup foundry DataTribe. He was the first investor to create a venture fund focused exclusively on cybersecurity and data science and has been investing in cybersecurity for more than 15 years in the U.S. and select international markets. 

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Security Leadership and Management
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Education & Training
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Opened padlock on computer keyboard

10 Data Breaches to Know About (April 2026)

Laptop with desktop screen showing

Research: Microsoft Edge Loads Stored Passwords in Cleartext

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Glowing police siren

Security Isn’t a Commodity. Neither Is Off-Duty Law Enforcement

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

SEC 2026 Benchmark Banner

Events

June 3, 2026

The Role of AI and Video in Measuring Health, Safety, and Security Standards

OSHA fines grab headlines, but most compliance issues start with everyday operational gaps: missed protocols, unsecured areas, or slow response. Learn how emerging technologies & AI can be leveraged towards a more proactive model of compliance.

June 10, 2026

Applying Agentic AI in Security Operations for Faster Decisions & Better Outcomes

Security teams have never had more visibility. We’ll explore how a new decision layer is helping security teams move from detection to decision. Turn alerts into decision-ready context, reducing reliance on manual triage and enabling faster action.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


The Role of AI and Video - Free Webinar - June 3, 2026

Related Articles

  • Hallway with dark wooden office doors

    66% of CISOs are worried cybersecurity threats surpass their defenses

    See More
  • Blank check UNSPLASH

    25% of CISOs in tech are not satisfied with their compensation

    See More
  • Notebook, laptop, and mug on desk

    How CISOs are grappling with budgets, burnout, and resource constraints

    See More

Related Products

See More Products
  • Hospitality Security: Managing Security in Today's Hotel, Lodging, Entertainment, and Tourism Environment

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing