The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Director of End-User Services (Internal Promotion)
3-5 years at Director levelSkills to master
- Mastering the full scope of end-user technology strategy, managing large departmental budgets, building strong relationships with business unit leaders, and demonstrating exceptional people leadership across a significant team.
You're ready to move on when
- Consistently exceeding performance targets for your department, delivering measurable improvements.
- Successfully leading major departmental initiatives (e.g., a company-wide collaboration tool rollout, major hardware refresh).
- Identified as a key succession candidate by current VP/CEO, with a clear development plan in place.
- Demonstrated ability to influence and collaborate effectively across other IT and business functions.
- 2
Head of Infrastructure & Cloud Operations (External Hire)
15-20 years total IT experience, with 5-7 years leading large infrastructure teamsSkills to master
- Deep expertise in enterprise-scale cloud architecture, data centre operations, network engineering, and a proven track record of managing critical infrastructure with high availability requirements.
You're ready to move on when
- Successfully managed a significant cloud migration or hybrid cloud environment, optimising performance and cost.
- Reduced infrastructure costs while improving performance and resilience, demonstrating strong financial acumen.
- Led a major incident response for critical infrastructure, showing calm under pressure and effective problem-solving.
- Demonstrated strong vendor management skills for key infrastructure partners.
- 3
Chief Information Security Officer (CISO) (External Hire or Internal Transition)
15-20 years total IT/Security experience, with 5-7 years in senior security leadershipSkills to master
- Expert knowledge of cybersecurity frameworks, risk management, compliance, and extensive experience building and leading security operations teams and incident response.
You're ready to move on when
- Successfully implemented enterprise-wide security programmes, significantly improving the organisation's security posture.
- Managed major security incidents, demonstrating effective crisis leadership and communication.
- Effectively communicated complex security risks to executive leadership and the board, influencing strategic investment.
- Proven ability to balance security needs with business enablement, finding practical solutions.