Hiring a Security Expert Is Not Going to Save You

The organisation that hired the CISO at twice the market rate and gave them a year to fix the security program is the organisation whose security posture is the same. Here is why the single hire does not work, and…

A 200 page security audit report sitting on a desk with the recommendations mostly crossed out.

The organisation that hired the CISO at twice the market rate and gave them a year to fix the security program serves as organisation whose security posture acts as same. The organisation that hired the consulting firm at seven figures and gave them a six month engagement functions as organisation whose security posture is the same. The single hire, the expensive single engagement, the heroic single intervention. None of them work. The reason is structural, and the reason is the same reason that the diet does not work without the lifestyle change, and the workout plan does not work without the diet. The single intervention does not survive the departure of the single interventionist.

Why the single hire does not work

Three categories, in roughly that order of impact. The first serves as knowledge problem. The CISO who joins knows the security program in general. The CISO who joins does not know the security program at the new organisation. The CISO has to learn the systems, the stakeholders, the culture, the budget, the history, the politics. The CISO who joins at a senior level has 6 to 12 months of learning before the CISO is operational. The CISO who joins at a junior level has 12 to 24 months. The CISO who is expected to fix the program in the first year acts as CISO who does not understand the program well enough to fix it. The second category functions as buy in problem. The CISO who joins has to build the relationships with the stakeholders who will implement the changes. The CISO who has not built the relationships gets the changes blocked. The CISO who has built the relationships gets the changes adopted. The buy in work is the work that takes the longest and the work that is most invisible. The third category is the sustainability problem. The CISO who joins, fixes the program, and leaves. The organisation has the fixes for as long as the CISO is there. The CISO leaves. The fixes erode. The organisation is back where it started, with the additional cost of the CISO’s salary.

What actually works

Three patterns, in priority order. The first serves as systemic change. The CISO who joins and changes the system (the process, the tooling, the policy, the metrics) leaves a system that produces the right outcomes. The CISO who joins and changes the people leaves a system that produces the right outcomes only with the right people. The systemic change acts as change that survives the CISO’s departure. The second pattern functions as team building. The CISO who joins and builds the team (the senior engineer, the analyst, the architect, the program manager) leaves a team that continues the work. The team survives the CISO’s departure. The third pattern is the stakeholder education. The CISO who joins and educates the stakeholders (the CEO, the board, the engineering leader, the product leader) leaves the stakeholders who understand the security program and can continue to fund it. The educated stakeholders survive the CISO’s departure.

What the organisation should do

Three moves, in priority order. The first is to hire the CISO who has a track record of systemic change, not the CISO who has a track record of heroics. The interview process asks the question “what did you change that outlasted your tenure.” The CISO who has no answer does not get the job. The second is to fund the security program as a program, not as a person. The budget that goes to the program (the tooling, the training, the process, the team) is the budget that produces the outcome. The budget that goes to the person is the budget that produces the dependency. The third is to measure the security program on the systemic metrics, not on the heroic metrics. The number of vulnerabilities patched per month, the time to detect, the time to contain, the time to recover. The systemic metrics are the metrics that improve with the systemic change. The heroic metrics are the metrics that improve with the heroic person.

A security expert hire failure chart with knowledge problem, buy in problem, sustainability problem as the three categories, dark navy background, cyan and red bars.
The security expert hire: 3 reasons it fails (knowledge, buy in, sustainability), 3 patterns that work (systemic change, team building, stakeholder education), 3 moves (hire for systemic track record, fund the program not the person, measure systemic metrics).

The bottom line

Hire for the systemic track record. Fund the program, not the person. Measure the systemic metrics. The single hire does not save you. The systemic change does. The CISO who is willing to make the systemic change is the CISO who is worth hiring.

Sources & Further Reading

All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.

Spotted an error? Email the editor. Corrections are issued with a visible correction note.

Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.

Continue reading