A lack of connection to the executive committee or an ill-defined reporting structure are among the warning signs that should prompt a CISO to avoid a position.
Applying for a Chief Information Security Officer (CISO) position means accepting a major challenge: fulfilling your duties under constant pressure, which can include overwhelming workloads, limited budgets, a shortage of staff, and the fear of a major incident. Not to mention that many CISOs face a lack of understanding regarding their role. The latest study by the Club of Information Security Experts (Cesin) on CISOs’ stress, published in 2024, demonstrates this. It indicates that 70% of CISOs feel anxious and 73% perceive a significant gap “between their capabilities and their organization’s expectations regarding protection against attacks and risk management.” Even though 85% of them “enjoy the adrenaline rush of the job,” it is important to perform this role in organizations that value it appropriately. To ensure this, they must identify certain unmistakable warning signs during the recruitment process.
Insufficient cyber maturity
“During a recruitment process, the biggest red flag is excessive technical debt,” states unequivocally François Ehly, a member of CESIN, CISO, and senior manager at Almond. “This technical debt refers to all the vulnerabilities accumulated due to information system management practices, business operations, and so on. It’s system obsolescence, with applications that haven’t been updated, and in-house applications that we’re dragging around like dead weight.”
During the recruitment process, when the CISO realizes such a debt exists, François Ehly advises them to dig deeper into the issue “by asking questions that help identify its scope and causes. You have to conduct a sort of audit: ask questions about the budget allocated to security, for example, and adopt a listening stance to piece together the different parts of the problem. If you sense that the organization doesn’t really have the will—that it views this as a cost it would rather avoid—then it’s mission impossible: there’s no point in working for them.”
However, if the company demonstrates a willingness to catch up in this area, then it can be worthwhile for a junior professional to take on this challenge, notes Olivier Daloy, CISO at Zscaler: “For a junior with a maximum of five years of experience, this can be exciting! It’s even desirable. They’ll be able to reshape everything in their own way and learn a lot. But with ten years of experience, doing what you already know how to do is frankly not interesting.”
An Inappropriate Reporting Structure
As a general rule, a CISO reports to the Chief Information Officer (CIO). The CISO role originated within the CIO’s department and very often depends on its budgets and resources (tools, human resources, etc.). However, it sometimes happens that the CISO is offered a position reporting to a Chief Technology Officer (CTO) responsible for internal infrastructure, or to an infrastructure manager, especially in startups and SMEs. These individuals are in charge of the technical foundation that enables the information system to function (servers, cloud, operating systems, etc.). Olivier Daloy advises against accepting such a proposal.
“When a CISO is required to report not to the IT department but to a CTO or an infrastructure manager, it means that they are not considered fully responsible for information security, but merely as an IT security manager. In this case, security is viewed solely from an operational perspective, without business implications and without a broader understanding of information security as a whole. In short, the scope is very limited: the CISO will do nothing regarding information security policy, compliance, user guidelines, etc. They will just configure the antivirus, endpoint detection and response, the firewall, etc.” This can, however, be beneficial for a junior-level role, “so they can gain hands-on experience with the highly operational aspects of security, such as equipment configuration and the like, and understand the ins and outs of this very technical side of things.”
At the other end of the spectrum, CISOs are sometimes asked to report directly to the company’s CEO. Aside from those who want this—”often for ego reasons”—Olivier Daloy strongly advises against it: “I know CISOs who reported directly to the CEO and had to resign because he didn’t understand their role at all. Plus, the CEO isn’t often reachable and can drop the CISO more easily. On top of that, in this setup, the entire IT department can declare war on the CISO. So it’s really not worth it.”
An IT Director Without Vision
When reporting to the CIO, the CISO must ensure that the CIO is “visionary, a driver of organizational transformation, and a partner to the business units. In that case, the CIO will influence the CISO to maintain the appropriate level of information protection,” says Olivier Daloy. If that is not the case, then the CISO may find themselves in a precarious position. “If the CIO does not understand the company’s business challenges, then the CISO reporting to him will be perceived as the one deploying security measures that hinder business operations and prevent them from functioning. The organization’s business units will then turn to shadow IT to escape the troublesome CISO.”
A Non-Existent Relationship with the Executive Committee
“For a CISO, it is important to have visibility and the ability to go to the executive committee in case obstacles are put in their way for every project. “That is why the CISO must be wary if they sense they will have no connection to the executive committee. Because, in that case, an unscrupulous CIO—as sometimes happens—may assume the right to suppress the CISO’s requests, take credit for the CISO’s successes, undermine the CISO, and so on,” observes Olivier Daloy. “During the hiring process, a CISO may realize that they won’t have a relationship with the executive committee if they only meet with the HR manager and the CIO during their interviews,” explains François Ehly. “However, it’s not unusual for a junior CISO to be accompanied by the CIO when meeting with the executive committee and the CEO,” adds Olivier Daloy.
A budget that’s too limited
Another thorny issue for CISOs: the budget. During the recruitment process, the CISO must ensure that the budget is sufficient to meet the objectives the organization expects of them. “However, you have to be reasonable about the budget, ask for what is necessary, and be able to accept a certain amount of frustration, especially in a company that is still relatively immature but eager to improve. For a junior, it can even be a challenge to start with a small but reasonable budget. On the other hand, if the organization is expected to be mature given its size, yet promises a small budget, then it’s best to avoid it because the mission cannot be fulfilled properly,” warns Olivier Daloy.
“During recruitment, it becomes clear fairly quickly when the organization lacks the willingness to allocate an adequate budget. You can tell when the CISO is expected to be a jack-of-all-trades. This means the budget won’t be sufficient to provide the necessary human resources, and the CISO will have to be, all at once, a security solutions administrator, a governance expert, a compliance specialist for every possible standard, and who knows what else,” explains François Ehly.
A Compliance Showcase
With the accumulation of regulations such as NIS 2 or DORA, many organizations must hire CISOs to comply with them. However, some of them only want to hire them to appear compliant and reassure their customers. They therefore expect the CISO to serve merely as a window dressing for compliance.
“This happens very frequently,” warns François Ehly. “When a CISO senses, during the hiring process, that they’re just a box to check, they should run away. I know CISOs who are in this situation, who therefore can’t really fulfill their mission, and who wear themselves out by repeating the same things over and over: they end up burned out,” observes Olivier Daloy. “On top of that, even though they can’t take action, such a CISO will be singled out in the event of an incident and will end up depressed,” adds François Ehly. “To ensure the organization isn’t just hiring you as a compliance figurehead, you should ask the recruiters this question: ‘What keeps you up at night?’” advises Olivier Daloy. If silence follows, then he advises the CISO to run away.
Impossible Training Opportunities
Finally, since the nature of incidents and cybersecurity solutions evolve very rapidly, the CISO must ensure they have access to training and opportunities to exchange ideas with peers. If the recruiter does not allow this, then Olivier Daloy advises walking away: “The role of CISO is changing so rapidly that if the company doesn’t give them enough time to update their knowledge, attend events, and connect with colleagues to stay current on new threats, then it’s dangerous for them. Because to perform their duties effectively, they need access to information sharing,” he concludes.