top of page

CISO Version 2.0 

  • Phil Venables
  • Jun 12
  • 4 min read

Everyone, no doubt, has an opinion on how many versions of the CISO role we have gone through since its inception. There has been a constant evolution from what was essentially an IT security manager, to cyber-defense leader, compliance director, technology risk manager, and beyond.  


However, I would argue the incarnation of the CISO role up until recently has been CISO Version 1.0 albeit with some “point releases” on the way. This is simply because version 1 of the role is a mode where most CISOs have been confined to deal with what they have and play permanent catch-up with that. What they have is the environment IT happens to deliver, the businesses that executives decide to pursue and the operations that best fit other non-security goals. CISOs bolt security onto that. Some have done this very well and have exhibited an immense track record of defending their organizations and customers. 


CISO 1.0 dealt with what they have. CISO 2.0 shapes what they have. 

The CISO 2.0 Essential Characteristics

However, in recent years, many leading organizations and their CISOs have subtly and then dramatically shifted to CISO 2.0 which has three emblematic characteristics. These amount to a profound shift from just dealing with what they have to actively shaping their organizations to be more inherently defensible. 




  1. CISO 2.0 are Business Executives. They act as the “CEO” of their security program. They are measured by business outcomes and work as a peer of other executives to know and shape the company's strategy and culture. They fully integrate security, resiliency and other risk mitigation into the fabric of the organization in its processes, operations, supply chains, and technology. They build mitigation in - not simply bolt it on. They work hand-in-hand with peer executives to deliver business outcomes in secure and resilient ways and in doing this they deliver adjacent business benefits and commercial outcomes beyond just security. 


  1. CISO 2.0 has Technical Empathy. They and their team have deep technical knowledge and engineering capacity to partner with technology teams and suppliers to build an inherently defensible technical environment. They collaborate with and show empathy with technical teams to not just deliver a secure technical environment on which the business can run but in doing so they help realize other goals like agility, efficiency, cost-effectiveness and more. 


  1. CISO 2.0 are Long Term Players. They recognize doing these things and building the credibility of a true executive takes time. They view “no” as only temporary and work to build a base of support, with other peers, to shift the culture of their organization to be broadly focused on the long term. These CISO 2.0 long term players have experienced push back, have had challenging budget conversations, and have dealt with disappointment. But, they don’t leave for the next job at the first hurdle. Instead, they persevere to success and they and their organizations are the better for it. 



The CISO 2.0 Path to Execution 

These characteristics are simply the foundation of CISO 2.0. The real differentiation as ever is in execution. This is all about moving from “building firestations” to “building flywheels”. 




CISO 2.0 defines a crisp strategy. They know the difference between plans vs. strategy as a coherent theory of winning. They work to scale their team and the whole organization by building or finding and amplifying flywheels. Like improving software and infrastructure reproducibility tooling which reduces the cost of vulnerability mitigation which frees up resources to further improve tooling, and so on. 


CISO 2.0 creates a culture where bad news travels fast and escalation is considered a service which in turn empowers the edge of their organization to be more motivated and able to fix things without having to be told. They apply the same principles across their supply chain and hold vendors to progressively higher standards. 


Finally, CISO 2.0 is not a passive target of an inquisitive Board. Rather, they actively shape the Board dynamics so that the Board becomes a tool for them to use to drive organization outcomes. 



The CISO 2.0 Factory 

CISO 2.0 is obsessed with creating more leaders in their own and other teams. They do this by becoming a “CISO Factory”, locking in the foundations for excellence such as federated security teams or BISO roles that provide platforms for executive development, support leadership rotations and mentoring, coupled with a relentless focus on the operational mastery of their activities. 




What Next - Two Divergent Paths?

More organizations and more CISOs are looking like CISO 2.0. We are also seeing the emergence of CISOs picking up wider responsibilities in infrastructure management, business risk management, or both. 


First we have CISO as “Chief Technology and Security Officer”. This is the combination of CISO and CTO. This has come about in a few organizations where the CISO has pushed aggressively for infrastructure modernization (so security can be built in not just bolted on) and the rest of the C-suite or Board have asked the CISO to permanently, or in transition, also be the CTO to drive this change. CISOs are increasingly adept at this given the technical, leadership, and wide scale organization transformation skills they’ve already exhibited. 


Second is CISO as “Chief Digital Risk Officer”. The deployment of AI in every part of an organization's operations is highlighting a set of risks, beyond security, that need managing. These risks like safety, model validation, compliance, privacy, reliability, accuracy and many more don’t fall naturally into existing organizations. Some industries like finance have well developed and operationally-oriented risk, compliance and privacy teams. But for others the C-suite and Board are turning to the CISO to manage these risks. Again, the CISO and team have the knowledge, skills, organizational connectivity, and often the credibility to pick up this responsibility.




Bottom line: CISO 1.0 dealt with what they had. In some cases amazingly well. CISO 2.0 shapes their organization in partnership with other executives. They are the “CEO” of the security program. From this vantage point they are additionally becoming one or both of the Chief Digital Risk Officer or Chief Technology and Security Officer. Exciting times. 

Recent Posts

See All

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
Subscribe for updates.

Thanks for submitting!

© 2020 Philip Venables. 

bottom of page