CISO Tribune

Analysis

How to hire a CISO: a guide for CEOs and boards

How to run a CISO search: defining the mandate before the spec, the interview questions that reveal judgment, and the offer terms serious candidates expect.

By CISO Tribune Editorial · Published June 23, 2026 · 2 min read

TL;DR: CISO searches fail at the definition stage, not the candidate stage. Decide the mandate first — builder, fixer, scaler, or diplomat — because they're different people. Interview for judgment through narratives, check references on the worst day rather than the best, and expect serious candidates to negotiate structure, not just compensation: the ones who ask hard questions about reporting lines and D&O are the ones who understand the job.

What are you actually hiring?

Four distinct mandates hide under one title. The builder: first real security leader; needs breadth, tolerance for scrappiness, and the ability to hire. The fixer: post-incident or post-audit; needs incident scar tissue, regulator fluency, and speed. The scaler: program exists, company is growing; needs org design and executive polish. The diplomat: heavily regulated or trust-branded business; needs board presence and external credibility, backed by strong operational deputies. Write the mandate in three sentences before anyone writes a spec — every later disagreement about candidates is usually an undisclosed disagreement about the mandate.

How do you interview for the real skills?

The role's core skills — judgment under uncertainty, risk translation, and organizational influence — don't show in technical quizzes. Use narratives: walk me through the worst incident you've run, decision by decision. Listen for calm sequencing, honest mistakes, and communication upward. Tell me about a time the business overrode your recommendation. The revealing answers involve a documented risk acceptance and a preserved relationship; the alarming ones involve either capitulation or martyrdom. What did you decide not to fund, and why? — the question that distinguishes risk managers from tool collectors. Then put them in front of the board or audit committee for twenty minutes: can they make a director smarter without slides? That session predicts more than every technical round combined.

What diligence actually matters?

Reference the worst day, not the résumé: ask former CEOs and GCs how the candidate behaved in the incident, the budget cut, the disagreement. Verify the claimed scope — "ran a team of 60" sometimes means "was in an org of 60." And let the candidate diligence you: strong ones will ask about the reporting line, the last CISO's exit, board engagement, and what happens on the worst day. Treat those questions as a positive signal; their absence as a negative one.

What does a credible offer include?

Beyond compensation: the reporting line and board cadence in writing; budget authority; D&O coverage confirmation and indemnification (post-Uber, post-SolarWinds, sophisticated candidates check); and decision rights during incidents — who calls disclosure, who can take systems down. A company that resists putting structure in writing is answering the candidate's real question: whether the role has authority to match its accountability. The searches that end well are the ones where both sides negotiated the job, not just the pay.

Frequently asked questions

What should a company decide before starting a CISO search?
The mandate: what problem this hire solves (build, fix, scale, or represent), the reporting line, the budget envelope, and board access. Searches that start with a spec instead of a mandate produce mis-hires — the same title describes four different jobs.
What are good CISO interview questions?
Ask for narratives, not knowledge: walk me through an incident you ran and what you'd do differently; tell me about a risk the business overrode you on and what you did; how did you decide what not to fund last year. Judgment shows in stories; frameworks can be memorized.
What do strong CISO candidates negotiate?
Reporting line and board access, budget authority, D&O coverage and indemnification, and clarity on incident-day decision rights. Candidates who ask these questions are demonstrating competence, not difficulty.

CISO Tribune Editorial

Editorial Desk

The CISO Tribune editorial desk reports on security leadership: who holds the role, who is leaving it, and what the moves mean. Every appointment entry is verified against a primary source before publication.