Analysis
How to hire a CISO: a guide for CEOs and boards
How to run a CISO search: defining the mandate before the spec, the interview questions that reveal judgment, and the offer terms serious candidates expect.
TL;DR: CISO searches fail at the definition stage, not the candidate stage. Decide the mandate first — builder, fixer, scaler, or diplomat — because they're different people. Interview for judgment through narratives, check references on the worst day rather than the best, and expect serious candidates to negotiate structure, not just compensation: the ones who ask hard questions about reporting lines and D&O are the ones who understand the job.
What are you actually hiring?
Four distinct mandates hide under one title. The builder: first real security leader; needs breadth, tolerance for scrappiness, and the ability to hire. The fixer: post-incident or post-audit; needs incident scar tissue, regulator fluency, and speed. The scaler: program exists, company is growing; needs org design and executive polish. The diplomat: heavily regulated or trust-branded business; needs board presence and external credibility, backed by strong operational deputies. Write the mandate in three sentences before anyone writes a spec — every later disagreement about candidates is usually an undisclosed disagreement about the mandate.
How do you interview for the real skills?
The role's core skills — judgment under uncertainty, risk translation, and organizational influence — don't show in technical quizzes. Use narratives: walk me through the worst incident you've run, decision by decision. Listen for calm sequencing, honest mistakes, and communication upward. Tell me about a time the business overrode your recommendation. The revealing answers involve a documented risk acceptance and a preserved relationship; the alarming ones involve either capitulation or martyrdom. What did you decide not to fund, and why? — the question that distinguishes risk managers from tool collectors. Then put them in front of the board or audit committee for twenty minutes: can they make a director smarter without slides? That session predicts more than every technical round combined.
What diligence actually matters?
Reference the worst day, not the résumé: ask former CEOs and GCs how the candidate behaved in the incident, the budget cut, the disagreement. Verify the claimed scope — "ran a team of 60" sometimes means "was in an org of 60." And let the candidate diligence you: strong ones will ask about the reporting line, the last CISO's exit, board engagement, and what happens on the worst day. Treat those questions as a positive signal; their absence as a negative one.
What does a credible offer include?
Beyond compensation: the reporting line and board cadence in writing; budget authority; D&O coverage confirmation and indemnification (post-Uber, post-SolarWinds, sophisticated candidates check); and decision rights during incidents — who calls disclosure, who can take systems down. A company that resists putting structure in writing is answering the candidate's real question: whether the role has authority to match its accountability. The searches that end well are the ones where both sides negotiated the job, not just the pay.
Frequently asked questions
- What should a company decide before starting a CISO search?
- The mandate: what problem this hire solves (build, fix, scale, or represent), the reporting line, the budget envelope, and board access. Searches that start with a spec instead of a mandate produce mis-hires — the same title describes four different jobs.
- What are good CISO interview questions?
- Ask for narratives, not knowledge: walk me through an incident you ran and what you'd do differently; tell me about a risk the business overrode you on and what you did; how did you decide what not to fund last year. Judgment shows in stories; frameworks can be memorized.
- What do strong CISO candidates negotiate?
- Reporting line and board access, budget authority, D&O coverage and indemnification, and clarity on incident-day decision rights. Candidates who ask these questions are demonstrating competence, not difficulty.
CISO Tribune Editorial
Editorial Desk
The CISO Tribune editorial desk reports on security leadership: who holds the role, who is leaving it, and what the moves mean. Every appointment entry is verified against a primary source before publication.