What the CISO Role Actually Requires
My path into cybersecurity leadership was not planned. It started in the US Army, where I worked as a systems administrator on IBM mainframes. After my service, I spent years accumulating roles in IT, working as a system admin, business analyst, and project and program manager while putting myself through an MBA program and then law school at the same time.
When I finally passed the bar and started practicing law, I hated it so much that I went back to IT within two years.
What I did not realize at the time was that the combination I had stumbled into, technical foundation, business acumen, legal and regulatory fluency, and negotiation experience, was exactly what the CISO role requires and almost nobody actually has. It was a fortuitous accident rather than a deliberate plan.
What Most People Get Wrong About the CISO Career
The CISO job is about strategy and risk. Understanding how the business makes money, where the risk lives, and how security decisions affect the organization are at least as important as understanding the technical controls in place. The security program exists to protect the business, which means you have to understand the business well enough to know what you are protecting and why.
The CISO role and senior technical security roles are different jobs that require different skills and different orientations. Recognizing which one you are building toward makes the career decisions along the way considerably easier.
What a vCISO Actually Does Day to Day
The advantage of the vCISO model is that patterns become obvious fast. When I step into a new environment the first thing I notice is almost always tooling redundancy. Organizations buy tools when they need them, tools evolve, and three years later they have three products that do the same thing, all under contract, all being maintained, with nobody auditing the overlap because nobody owns the audit.
At AssuredPartners I saved over a million dollars in a single quarter doing exactly this work. Every tool in the stack deserved a conversation about whether it still earned its place, and a surprising number did not. Every contract in your environment should be renegotiated regularly because what you bought three years ago may already be covered by something else you own, and the vendor market moves fast enough that the conversation is worth having more often than most organizations think.
Why Security Programs Stall
Security is a relationship role, and the programs that move forward are the ones where security communicates well with the rest of the organization, with engineering, finance, and the people who actually run the systems being protected.
Most security teams do good work and tell nobody about it. Leadership eventually wonders what the security team actually does, the budget conversation gets harder, and the cycle continues. If you fixed a vulnerability last week that could have cost the company two million dollars, say so in plain language to the people who make budget decisions. Accountability requires visibility, and visibility requires communication.
What Security Leaders Get Wrong About New Technology
Saying no to new technology. I understand the instinct, because new technology means new attack surface, new unknowns, and new things to audit. But the organizations that reflexively block everything new do not actually become more secure. What they become is invisible to the people building the products, who find workarounds outside the security team’s view. Shadow IT is what happens when security is perceived as a blocker rather than a business function, and the risk you were trying to avoid walks in through the side door.
Why I Recommend Improv to Anyone in Security Leadership
I powerlift, do improv, and sing barbershop, though not usually at the same time. I would actually recommend improv to anyone going into security leadership because the core skill is learning to respond to what is actually happening rather than what you expected to happen, which is most of this job. It’s also a great way to develop that communication muscle I spoke of above.
One Piece of Advice for Anyone Building a CISO Career
Be honest with yourself about what kind of security work you want to do. Some people want to do strategy, sitting in executive meetings, thinking about risk at the program level, and translating security into business language. Others want to own technical security operations. Both are legitimate paths that require different skills and lead to different roles and knowing which one you are building toward makes the career decisions along the way considerably easier.
I built mine accidentally, which worked out, but I would not necessarily recommend it as a strategy.
Hadas Berkowitz | Principal Consultant, SideChannel
Hadas Berkowitz is a Principal Consultant at SideChannel, where she works with organizations across financial services, healthcare, and enterprise manufacturing on security program leadership, compliance, and risk management. She has previously served as CISO at M1 Finance and AssuredPartners and began her career as a systems administrator in the US Army.
