The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Director of Information Security / VP, Security Operations
5-7 years at this level before CISOSkills to master
- Managing large, multi-functional security teams, owning significant operational budgets, developing and executing security programmes, presenting to executive leadership, and handling major incidents.
You're ready to move on when
- Successfully led a major security transformation initiative across a large business unit.
- Consistently achieved 'Green' status on key security metrics and audit outcomes.
- Demonstrated ability to influence and gain buy-in from executive peers for security initiatives.
- Built and retained a high-performing security team, with clear succession planning in place.
- 2
Head of GRC (Governance, Risk, and Compliance)
7-10 years at this level before CISOSkills to master
- Deep expertise in global regulatory frameworks, managing enterprise risk registers, leading successful audit programmes, and translating compliance requirements into actionable security controls. This path often requires a strong understanding of legal and business operations.
You're ready to move on when
- Successfully navigated complex international regulatory audits with zero major findings.
- Developed and implemented an enterprise-wide GRC framework that is well-integrated with business processes.
- Demonstrated ability to communicate complex legal and compliance risks to the Board and executive team.
- Proven track record of building strong relationships with external auditors and regulatory bodies.
- 3
Principal Security Architect / Fellow
8-12 years at this level before CISO (often combined with leadership experience)Skills to master
- Deep technical expertise in security architecture across diverse domains (cloud, network, application), designing secure-by-default systems, evaluating emerging technologies, and providing technical leadership to large engineering organisations. This path often requires adding significant people and programme management experience.
You're ready to move on when
- Designed and implemented a major, enterprise-wide security architecture (e.g., Zero Trust, multi-cloud security).
- Recognised as an industry expert in a critical security domain, with publications or speaking engagements.
- Successfully mentored and guided multiple senior security engineers and architects.
- Demonstrated ability to translate complex technical challenges into strategic business risks and opportunities.