The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Director of Governance, Risk & Compliance (GRC)
3-5 years at this level before CISOSkills to master
- Deepen enterprise risk management, master board-level reporting, build cross-functional executive relationships, and gain experience managing a diverse GRC team.
You're ready to move on when
- Successfully led significant enterprise-wide compliance programmes (e.g., GDPR, SOX, ISO 27001 recertification).
- Consistently delivered clear, concise risk reports to the Board's Audit Committee.
- Demonstrated ability to influence and align senior business unit leaders on risk mitigation strategies.
- Built and mentored a high-performing GRC team.
- 2
Head of Information Security / VP Security
3-5 years at this level before CISOSkills to master
- Gain broad experience across all security domains (operations, architecture, incident response), manage large security budgets, develop strategic vendor relationships, and lead major security transformation initiatives.
You're ready to move on when
- Successfully designed and implemented major security programmes (e.g., Zero Trust, cloud security migration).
- Managed and scaled a large security operations centre (SOC) or security engineering function.
- Led the response to multiple significant cyber incidents with positive outcomes.
- Demonstrated strong leadership and development of security talent.
- 3
Chief Privacy Officer (CPO) / Head of Data Protection
5-7 years at this level before CISO (often requires broader security experience)Skills to master
- While focused on privacy, you'd need to broaden your understanding of technical security controls, incident response, and enterprise risk management beyond privacy-specific risks. The CISO role requires a wider lens.
You're ready to move on when
- Successfully built and managed an enterprise-wide data privacy programme.
- Navigated complex regulatory interactions with data protection authorities.
- Demonstrated ability to balance privacy requirements with business innovation.
- Developed a strong understanding of the technical underpinnings of data security.