Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Why do CISOs only Stay with you for 18 Months?
Articles

Why do CISOs only Stay with you for 18 Months?

ISBuzz TeamBy ISBuzz TeamDecember 29, 20156 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Why do CISOs only Stay with you for 18 Months?
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Are you an IT security specialist dreaming about being something more? Does your career have a ceiling?

What is a CISO?

In the past, businesses were run by a small senior management team headed up by a managing director who reported to a president or board of directors. In addition, there were line managers who had a thorough knowledge of their own area, but little else. These were often seen as narrowly focused specialists. Today, however, the business landscape looks different. The top leadership has senior level deputies who are experts in their specific fields while at the same time understanding the business development strategy. This is how the C-suite was born, including, in many organisations a position of Chief Information Security Officer (CISO).

A CISO is responsible for establishing and maintaining processes in an organisation that ensure information assets and technologies are protected and IT risks are reduced. Over the past decade, the presence of a CISO has become standard in business, government and not-for-profit sectors. Today’s evolving number of cyber-threats and targeted cyber-attacks has led to growing demand for CISOs in companies around the world. At the same time, there is an increasing amount of media attention devoted to security breaches in international corporations. These not only lead to financial losses, but, more significantly – to reputational damage.

The cyber-threat landscape has emphasised the CISO’s importance, raising the role to a new level. Many organisations now include their CISO on the board of directors and give them the authority to make important decisions.

Challenges faced by CISOs

When CISOs are part of the board of management, their challenges fall broadly into two areas: the first – which we can call ‘lost in translation’ – is a result of the language difference between the CISO and the rest of the board. Technical people usually have a technological mindset; they are focused on their specialist tasks and processes. Before reaching board level they have often lacked the opportunity for true business engagement, even if they have experience as IT generalists. However, the role of CISO requires a strong balance of entrepreneurial understanding, business acumen and technical knowledge.

The CISO is a relatively new role and does not yet have a professional map. Today they manage a wide range of areas: security strategy, IT risk management, threat management, identity and access management, security performance management, IT compliance management, third-party security, and security architecture.

A CISO’s second challenge lies in choosing appropriate vendors for solutions to help manage these areas. The market is overflowing with security vendors, solutions and specialists and it is not easy for an organisation to select those that satisfy its exact business needs. It is essential to pay attention to the integrity of security solutions and their ability to protect complex corporate infrastructure: having ‘just anti-malware’ is not enough; there should be multi-layered protection with flexible centralised control. The protection should be ready to provide additional security measures beyond anti-malware, such as application control and data encryption. Given the diversity of corporate IT infrastructure, mobile and virtualised endpoints also need protecting. Moreover, it is not only a specialised solution that should be implemented. Expert services and support are also a very important part of corporate IT security. Given the complexity of the task, the more vendors and solutions that are involved, the harder it is for the CISO to develop and execute a truly dependable IT security strategy.

The latest research shows that people hold a CISO position for an average of 18 months* and there is an obvious reason for that. This period coincides with the complete cycle of one IT solution procurement and implementation process, the results of which could demonstrate whether the CISO made a strategically correct decision or not. So choosing the right partners appears to be crucial for the survival of the CISO.

A few pieces of advice for CISOs

If your career goal is to become a CISO, the following steps should help you:

  • Remember to negotiate a security budget. The procurement decision of a security solution should not be based on costs alone, but on a qualitative analysis of the company’s needs, regulatory compliance, the cyber-threat landscape and IT risks.
  • Become a trusted advisor in your company. Be aware of security risks to company data, and be able to identify and follow industry trends. Make strategic decisions: you cannot be focused on just a few problem-solving issues; you need to have a bird’s-eye view of all problems, at the same time. This also involves choosing an appropriate IT vendor, one that provides solutions, not just products.
  • Bear in mind that your organisation is a target. It’s likely, not just probable, that it will be attacked. You need a comprehensive security strategy in place. This should cover the whole corporate infrastructure, contemplate necessary changes to that infrastructure over time and leverage expert security intelligence to provide an effective defense.
  • Be prepared to find common ground with board members. You will need to communicate effectively on matters concerning IT risks and how they may affect the business, considering the bigger picture and the business’s strategic direction. Have an open mind and gain cross-functional knowledge and skills. Stop talking to the board in technical language and start using business language.
  • Be human. Build relationships inside your organisation and earn credibility. You have to lead your workforce on the way to a secure future. Remember that technologies cannot work without appropriate human behaviour so it is important to have your staff on your side when you make changes, or implement new procedures. If employees are resistant, be sure to educate them about your policies, to bring them on board. Importantly, the process of strengthening security should not have a negative impact on employees or prevent them from working efficiency, so listen to their concerns and implement processes to help them.

[su_box title=”About Kaspersky Lab” style=”noise” box_color=”#336588″]Kaspersky LabKaspersky Lab is one of the world’s fastest-growing cybersecurity companies and the largest that is privately-owned. The company is ranked among the world’s top four vendors of security solutions for endpoint users (IDC, 2014). Since 1997 Kaspersky Lab has been an innovator in cybersecurity and provides effective digital security solutions and threat intelligence for large enterprises, SMBs and consumers. Kaspersky Lab is an international company, operating in almost 200 countries and territories across the globe, providing protection for over 400 million users worldwide.[/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}