bloguniverse

The CISO role has become a revolving door

A CISO stays in the job for an average of 18 months – as shown by the ongoing monitoring of the market that we at the Cyber ​​Security Agency do. The CISO role has thus become one of the biggest revolving door functions of our time.

Why that?

Are CISOs opportunistic career climbers, chasing the next pay increase in a market where salaries are skyrocketing (22% over the last 2 years) – and thus cynically exploiting the vast lack of skills and experience?

The answer is no. Most CISOs are anything but that. They are responsible people with a high degree of morality, driven by making a difference – namely, making society a safer place for both businesses and citizens. A responsibility they take on despite the challenges that the role entails and despite the fact that it is a function where you never have any time off.

What makes the CISO role so thankless that many quit after a short time? In our dialogue with CISOs, we hear the following explanations:

Lack of resources: It is a well-known and discussed issue that there is a lack of resources and competencies within IT security. It is a struggle for CISOs to attract the necessary specialists. The number of headcounts allocated to the area is also often vanishingly small. At the same time, many SMEs in Denmark are of a size where it is not justifiable to have a department of 3-4 people, which is often the level needed to cover the various specialties within the area. The CISO will therefore spend a disproportionate amount of time securing resources, recruiting, training and losing his employees again.

Alone in the role: In most SMEs in Denmark, a CISO will be alone in the responsibility and function – i.e. alone in handling all tasks from operational security, to supplier management, compliance and governance. When the CISO's role becomes so broad, it goes without saying that it is difficult to deliver and ensure quality – and thus be successful.

Many first-time CISOs are unprepared for the scope of the role: they have limited experience by nature. They are often strong in a subset of the professional disciplines, but run into a wall in terms of getting their agenda across to management. It comes as a surprise that they not only have to fight against unfamiliar external resistance and old
technologies, but also have an internal battle with management and the board.

Management wants quick fixes that don't cost money: A challenge that many CISOs face is that management has no idea of ​​the scope of the task combined with the fact that they prefer the quick and cheap solution rather than investing in something that can ensure a basic and more long-term level of security in the organization. Manufacturing companies in particular often carry a heavy technology debt from old legacy systems, and when you have to keep up with developments at the same time - the task becomes enormous.

Race against time – you never have time off: When working with IT security, you are up against an external adversary that you do not know, that never sleeps, and that can hit you without you being a conscious target. As a CISO, you are up against a threat landscape that is constantly changing, which requires that you and your team are constantly at work.
Focus on reporting on business premises: The role has evolved from being a technical task that required technical skills to being a management task that requires focus both upwards, downwards and in breadth. To succeed, as a CISO, you must be able to report based on financial and business-oriented KPIs, as well as be good at and spend energy on stakeholder management. It is no longer enough to propose the best possible technical solutions – a CISO must be equipped to be able to convince based on financial arguments and KPIs.

Limiting factor for development: IT security is an area of ​​great concern and attention, but at the same time, as a CISO, you must not limit the development, which mostly involves digitalization. And YES – when you say digitalization, security is included in the equation, although considered a limitation rather than a basic necessity. Security is rarely involved from the start of development projects and often has to be fought for. If problems with security arise later, the CISO is the one to blame. Ergo, the everyday life of a CISO is filled with battles with engineers, creatives, business developers and IT development, which is always moving.

Area of ​​secrecy: Companies do not want to be exposed for their weaknesses and vulnerabilities, which means that it is difficult for CISOs to share experiences and seek sparring based on the specific issues. The exchange of experience thus remains in general terms.

Tangible and tangible consequences: As a CISO, you have to live with the constant fear of being the next company to be hit by a breach. All companies are subject to attempted attacks – and will you be the next one to be exposed in the media, with the major financial consequences that come with a breach? No matter what, the CISO will always be seen as the one who failed to do his job well enough.

The list is undoubtedly longer, but the above statements from the CISOs we at Cyber ​​Security Agency interview already give a good insight into why it is in many ways a thankless role. In addition to an intangible external threat, you struggle with internal agendas, access to resources, powers, technology debt and a management that "does not want to face reality" and probably much more.

IT security has clearly become a top priority for management and boards, and in the media spotlight, but it doesn't seem to have made being a CISO any easier. Quite the opposite. It has simply added a new dimension to the role that most people, neither professionally nor personally, are equipped for – or have the time to handle.

The consequence, as we see it, is that many choose a freelance career, among other things because they neither can nor want to guarantee and live up to the responsibilities of the CISO role. This means that we do not get the necessary learning environment in this country, where CISOs develop with the management task – which in turn means that when we fill CISO roles, we are forced to look abroad to find candidates with the necessary experience.

Maybe this is (also) something for you?