The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From Information Security Manager (L5) in a larger organisation
3-5 years as an L5 ManagerSkills to master
- Scaling an ISMS across multiple teams, managing larger budgets, developing a strategic vision beyond day-to-day operations, and honing executive communication skills for Board-level interactions.
You're ready to move on when
- Successfully led a major ISO 27001 recertification with zero Major NCs for a significant business area.
- Managed a team of 10+ people, including other managers, with strong performance reviews.
- Presented strategic security initiatives to senior leadership (e.g., SVP, C-1 level) with positive outcomes.
- Managed a security budget of at least £500K-£1M, demonstrating effective resource allocation.
- 2
From Head of GRC or Lead Internal Auditor (L4) in a very large enterprise
5-7 years at L4/L5 equivalentSkills to master
- Transitioning from a programme-focused role to a broader strategic leadership role, owning the entire security posture for a business unit, and managing a more diverse set of security functions beyond just GRC/audit.
You're ready to move on when
- Acted as the primary point of contact for external auditors for multiple full audit cycles, managing all responses.
- Successfully built and managed a GRC platform implementation or a large internal audit programme.
- Demonstrated strong influencing skills with senior business leaders to drive compliance initiatives.
- Experience with strategic vendor management and third-party risk assessments at scale.
- 3
From CISO in a smaller, rapidly growing company
2-4 years as a CISOSkills to master
- Adapting to the complexities and political landscape of a larger, more established organisation, managing a significantly larger budget and team, and navigating more formal governance structures.
You're ready to move on when
- Successfully built and scaled an information security programme from scratch or significantly matured one in a high-growth environment.
- Directly reported to the CEO/Board and managed all aspects of security for a company.
- Experience with M&A security due diligence and integration.
- Proven ability to attract, hire, and retain security talent in a competitive market.