top of page

What Makes A Good CISO?

  • Writer: Brainz Magazine
    Brainz Magazine
  • Oct 11, 2022
  • 3 min read

Updated: Feb 21, 2024

Written by: Anna London, Executive Contributor

Executive Contributors at Brainz Magazine are handpicked and invited to contribute because of their knowledge and valuable insight within their area of expertise.

ree

There have been multiple articles and opinions regarding what makes a good CISO? The question that we should be asking is what makes an effective CISO?

ree

Let’s start by differentiating between myth and truth.


Myth No.1: CISOs are required to have a technical background.

Truth: Most CISOs in positions today have never held a technical position where they have had to build and protect infrastructure as an engineer, analyst, developer or sysadmin.


Myth No.2: CISOs are required to have a technical degree in IT or Cyber Security.

Truth: Most CISOs in today’s positions in both commercial and government organziations have degrees in mathematics or business, not in information technology or cyber security.


Myth No.3: Industry Certifications like CCISO, CISSP, Security +, Network +, CEH et al. make you a subject matter expert.

Truth: If you are a good test taker, you can study for the exam and pass it. Many college and trade school boot camp grads learn how to study for exams and pass the test with little to no hands-on experience in cyber security or IT. These industry certifications do not make us experts ‒ only years of hands-on industry experience can do that.


Myth No.4: Having held a prior CTO/CIO/CISO position qualifies you as a cyber security expert.

Truth: Most positions at this level are given to a privileged set of men in a “good ol’ boy” network. It is not given based upon past performance qualifications in an actual technical position where the application of cyber security prevention mechanisms are paramount. It is who you know and clearly not what you know.


Myth No.5: Start up CTO’s are experts in cyber security and building secure applications.

Truth: This could be furthest from the truth. Most start up CTOs can barely spell or build (MVP) minimum viable product much less being able to secure the very applications they are putting out in the public domain irresponsibly through mobile app stores like Apple and Google. Security is an after thought with most start ups. VCs and Angel Investors want MRR and DAUs and are not measuring the quality of applications nor taking into account the security of the very applications they are investing in to ensure the data being processed, stored and transmitted through these platforms are secure and remain secure.


Myth No.6: Being a good visionary is all that is required for a good CISO/CTO/CIO.

Truth: I have witnessed many organizations where there is a good IT Strategic Vision with great ideas, but ideas are not enough. You have to know how to translate that vision into actionable and sustainable steps. This is the part that is lacking at many organizations so many great ideas never see the light of day because leadership lacks the skills to see them through.


CISOs/CTOs/CIOs are accountable and responsible for managing the resources (budgets, people, processes and technology) with regard to corporate and application security compliance. How on earth are we to expect adequate protection of data at organizations and corporations if the people at the top do not have a strong technical acumen in order to ask the right questions and manage resources effectively in order to implement strong defenses? Having a business background is not enough. It is analogous to a professor that has spent their entire life span in the classroom teaching MBA programs yet never owning a business themselves. Knowing theory and keywords is not enough to be an effective leader in the cybersecurity industry. Prior and current hands-on knowledge is the key to success here. You can “rely” on team resources all you want for answers as a leader. However, in today’s world, where imminent threats to data is paramount, you cannot replace theory with hands-on practice needed for leaders in IT/Cyber to be effective in reducing and/or eliminating data breaches. Proactive prevention is the key through hands-on knowledge on how to implement best business practices and manage your people, processes and technologies effectively. There is a business risk and a cyber risk. BOTH are equally important and BOTH qualifications should be taken in consideration when hiring a CISO/CTO/CIO for your organization.


Follow me on Instagram, and visit my website for more info!


ree

Anna London, Executive Contributor Brainz Magazine

Anna London is an US Army Veteran, Colon Cancer Survivor, Educator, Cyber Security Expert, Entrepreneur.

 
 

This article is published in collaboration with Brainz Magazine’s network of global experts, carefully selected to share real, valuable insights.

Article Image

Real Intimacy Begins in Presence – The Art of Being Seen Beyond Roles

In an age of constant connection yet quiet disconnection, we find ourselves surrounded by communication but starved for genuine presence. In a world where relationships are often filtered through...

Article Image

Lessons From Coaching 7-Figure Entrepreneurs – What Truly Separates the Top 1%

After coaching and mentoring hundreds of high performers across more than eighty industries and building multiple seven-figure companies of my own, I’ve seen a clear pattern emerge among those who...

Article Image

Custom GPTs – An Empowering Framework for Consistency (and Clients)

Running a business often feels like juggling a dozen roles at once. But what if you could replicate your voice, values, and message to stay consistent without burnout? Abbey Dyer-Amonette introduces...

Article Image

Oops, AI Just Snatched Your Voice, Face, and Cat Pics and Might Be Using Them Better Than You

AI isn't just a nosy roommate anymore it's more like a con artist wearing your hoodie, your face, and maybe even your LinkedIn profile. From apps quietly stockpiling your selfies to bots absorbing...

Article Image

Soul Purpose in 2025 – Why It’s Less About Finding and More About Feeling

In a world obsessed with defining success, chasing goals, and labelling identities, the idea of “purpose” can feel like another performance metric. But what if your soul's purpose isn’t something to find...

Article Image

Breakups Without Closure – Why Waiting for Answers Keeps You Stuck

Why did things end the way they did? Why did he leave? Why didn’t he stay and explain why he was walking away? You deserve answers, and you deserve to understand why. Heartbreak is painful enough at the...

How Alternative Financing Options Help Startups Avoid the Death Valley

A Tale of Two Brands & How to Rebrand Without Losing Your Soul

The Gut-Hormone Connection – Unlocking the Secret to Balanced Hormones Through Gut Health

Life Is Not a Race – Learning to Slow Down

How to Influence Everyone Around You

Your 50-Plus Fitness Program Balance Checklist

Divination Isn’t Dark, It’s a Path to the Light Within

The One-Night Stand Mindset – How to Have an Unforgettable One-Night Stand With Your Calling

Why Your Healthy Diet Might Be Keeping You Bloated

bottom of page