The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Director of Cloud Security / VP of Information Security
5-10 years in these roles before CISOSkills to master
- Managing multi-million-pound budgets, leading large security teams (50+), presenting to executive leadership, developing and executing strategic security roadmaps, and handling major incidents.
You're ready to move on when
- Successfully led a significant security transformation programme.
- Consistently delivered on strategic security objectives, reducing enterprise risk.
- Built and retained a high-performing security team.
- Demonstrated strong executive presence and communication skills in high-stakes situations.
- 2
Head of GRC (Governance, Risk, and Compliance)
8-12 years in GRC leadership before CISO (often combined with other security roles)Skills to master
- Deep expertise in regulatory compliance, enterprise risk management frameworks, audit management, and communicating compliance posture to boards. You'd need to layer on more technical and operational security leadership.
You're ready to move on when
- Successfully navigated complex regulatory audits with clean results.
- Established a robust enterprise risk management framework.
- Consistently advised executive leadership on compliance obligations and risks.
- Developed a strong understanding of technical security controls and operations.
- 3
Chief Technology Officer (CTO) or Chief Information Officer (CIO) (with a strong security background)
Variable, depending on prior security focusSkills to master
- Broader IT strategy, infrastructure, and operations management, coupled with a deep understanding of security's integration into all technology functions. This path typically involves a lateral move or a return to a dedicated security role.
You're ready to move on when
- Successfully managed large IT organisations, including security functions.
- Integrated security into the entire technology lifecycle (DevSecOps).
- Demonstrated strong strategic leadership across diverse technology domains.