The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Director/VP of Information Security & Compliance
5-10 years at this level before CISOSkills to master
- Enterprise programme management, multi-million-pound budget ownership, managing diverse security domains (GRC, SecOps, AppSec), significant Board interaction, and leading large teams (50-100+).
You're ready to move on when
- Successfully led a major security transformation programme across a business unit.
- Consistently delivered security programmes on budget and on time, with measurable risk reduction.
- Proven ability to influence executive leadership and gain buy-in for strategic security initiatives.
- Managed a significant security incident from end-to-end, including external communications.
- 2
Chief Risk Officer (CRO) or Head of Enterprise Risk
3-7 years in a CRO role before CISO (less common, but possible)Skills to master
- Holistic enterprise risk management (beyond just cyber), financial risk, operational risk, regulatory risk, and integrating security risk into the broader ERM framework. Strong board-level reporting on aggregated risk.
You're ready to move on when
- Demonstrated ability to manage and report on all categories of enterprise risk to the Board.
- Successfully integrated information security risk into the overall enterprise risk framework.
- Proven track record of driving risk-aware decision-making across the organisation.
- 3
Chief Technology Officer (CTO) / Chief Information Officer (CIO) with Security Focus
5-10 years in a CTO/CIO role before CISO (often a lateral move)Skills to master
- Broad IT leadership, technology strategy, infrastructure, software development, and a deep understanding of how security integrates into the entire technology stack. Managing large technology budgets and teams.
You're ready to move on when
- Successfully led a major digital transformation initiative with security embedded from the start.
- Proven ability to balance innovation with security and resilience in technology delivery.
- Demonstrated strong relationships with security teams and a clear understanding of cyber risks.