The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Director, Global Security Operations (from a large enterprise)
3-5 years as Director before CISOSkills to master
- Expanding from operational leadership to full enterprise security strategy, P&L ownership beyond operations, and consistent board-level engagement. You need to broaden your perspective from 'how we respond' to 'how we strategically protect the entire business'.
You're ready to move on when
- Proven ability to manage a multi-£M budget and justify significant security investments to executive leadership.
- Demonstrable experience in leading and recovering from major, enterprise-wide security incidents.
- Strong track record of building and developing high-performing security leadership teams.
- Consistent positive feedback from C-suite on strategic contributions and communication.
- 2
Head of Cyber Risk / Chief Risk Officer (from a regulated industry)
2-4 years in risk before CISOSkills to master
- Deepening technical understanding of security controls and operations, translating risk frameworks into actionable security programmes, and building a strong technical security team. You'll need to move from 'what are the risks' to 'how do we actually fix them'.
You're ready to move on when
- Demonstrated ability to translate regulatory requirements into practical security controls.
- Experience collaborating closely with security operations and engineering teams to implement risk mitigation strategies.
- Strong understanding of the technical nuances of various security domains (e.g., cloud security, application security).
- Proven capability to influence technical leadership without direct authority.
- 3
VP of Security Engineering / Architecture (from a tech-heavy firm)
3-5 years as VP before CISOSkills to master
- Broadening from security architecture and engineering to include governance, risk, compliance, and global security operations management. You'll need to understand the 'why' behind the 'what' from a business and regulatory perspective, not just a technical one.
You're ready to move on when
- Experience owning the security roadmap for a significant part of the enterprise's technology stack.
- Demonstrated ability to build and lead large, distributed security engineering teams.
- Strong understanding of business drivers and how security enables (or hinders) them.
- Proven capability to present complex technical strategies to non-technical executive audiences.