Analysis
Who gets the CISO job: 2026's appointments by prior role
Of the 61 CISO appointments on the Wire where the prior role is on record, more than half went to people who already held a top security title. The exceptions are the interesting part.
The top security seat mostly goes to people who already have one. Of the 105 appointments on the Wire so far in 2026, 61 have the appointee's previous role on record. Of those, 32 were already a CISO, chief security officer or head of security somewhere else. The job is filled laterally far more often than it is filled by promotion.
That is a narrower market than the headline shortage of security talent suggests. The shortage is real at the practitioner level. At the top, organizations are largely trading a known pool of sitting CISOs among themselves.
How do the 61 break down?
| Prior role | Appointments | Share |
|---|---|---|
| CISO, chief security officer or head of security | 32 | 52% |
| Deputy CISO | 3 | 5% |
| Other security, risk or governance role | 14 | 23% |
| Title outside security | 12 | 20% |
The lateral moves span every sector on the Wire. Naina Bhattacharya went from Danone to Coats. Geoff Belknap went from Microsoft to HubSpot. Daniel Dubowski went from Hertz to Marriott. Brian Harrell went from Avangrid to FirstEnergy, and Bertrum Carroll went from the insurer Employers to the State of Nevada. Security vendors hire the same way: 7AI, Kai and UltraViolet Cyber all brought in sitting CISOs.
Where do promotions come from?
Deputy-to-CISO promotions are rarer than the org chart would suggest: three in 61. Connie Devine moved up inside Phillips 66. Iain Mulholland and Chris Jones were deputies elsewhere, at Google Cloud and Cisco, before taking the top job at Salesforce and Axonius.
The larger internal pipeline runs through adjacent security and risk roles. Gleb Reznik came from American Express's own technology risk and information security leadership. Kailash Gaonkar was head of governance and vulnerability management at IIFL Finance before the board made him CISO. Michael Tetto was Eversource's director of information security. These are people who ran a piece of the function and were handed all of it.
Who came from outside security?
Twelve appointees held titles outside security immediately before. That group needs care, because a title can hide a security background:
- Several came from technology leadership at security companies. Michael Sikorski was CTO and VP of engineering at Palo Alto Networks before joining Coinbase.
- Some bring an earlier security career under a broader title. Mike Marshall, California's new state CISO, was an acting information officer and earlier an agency information security officer.
- A few are genuine crossovers. Christian Winward moved from chief information officer at FirstBank to CISO at PNC. James Wilkinson was running his own company before Dallas named him CISO.
The CIO-to-CISO move is the one worth watching. For years the argument has been that the CISO should not report to the CIO. A bank handing the security seat to a former CIO suggests some boards now value the operating executive's view of the whole technology estate over a pure security pedigree.
What does this mean for a board running a search?
The candidate pool is mostly sitting CISOs, which means most searches are competing for the same people. That is one reason, as our look at 2026's departures found, that seats opened without a successor stay empty for months.
The organizations that avoided that wait tended to have someone ready inside: a deputy, a governance lead, a technology risk executive. Building that bench is slower than hiring laterally, and it is the only reliable way to avoid a vacancy.
What the record cannot tell us
Forty-four of this year's 105 appointments do not have the prior role on record, usually because the announcement did not state it. If those skew toward internal promotions, which companies tend to announce with less detail, the true share of lateral hires is lower than 52%. The pattern here is a strong indication, not a census.
CISO Tribune Editorial
Editorial Desk
The CISO Tribune editorial desk reports on security leadership: who holds the role, who is leaving it, and what the moves mean. Every Wire entry is verified against its cited source before publication.
The Briefing
Every verified CISO move of the week, in your inbox Friday.
Every verified CISO move and one piece of analysis, weekly.
Unsubscribe any time. See the privacy policy.