The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Director of Information Security / VP, Security
5-7 years at this levelSkills to master
- Mastering enterprise-wide security programme management, building and leading multiple teams, managing significant budgets, and consistently presenting to executive leadership. You'll need to demonstrate a shift from tactical to strategic thinking.
You're ready to move on when
- Successfully led a major security transformation programme (e.g., Zero Trust implementation).
- Consistently delivered security programmes on time and within budget, with measurable risk reduction.
- Built and retained a high-performing security leadership team.
- Regularly engaged with business unit leaders, embedding security into their operations.
- Proven ability to influence decisions at the executive level without direct authority.
- 2
Head of GRC (Governance, Risk, and Compliance)
7-10 years at this level, often after a technical security backgroundSkills to master
- Deep expertise in regulatory compliance, enterprise risk management frameworks (e.g., ISO 27001, NIST CSF), and translating compliance into actionable security controls. You'll need to develop strong legal and financial acumen and exceptional stakeholder management skills across the business.
You're ready to move on when
- Successfully guided an organisation through major regulatory audits (e.g., GDPR, PCI-DSS).
- Implemented a comprehensive enterprise risk management programme with quantified risk reporting.
- Demonstrated ability to influence legal, finance, and business unit leaders on risk posture.
- Built a strong understanding of cyber insurance and its relationship to GRC.
- Proven ability to manage complex policy frameworks and ensure organisational adherence.
- 3
Chief Technology Officer (CTO) / Chief Information Officer (CIO)
Variable, often 5-10 years in a CTO/CIO role with a strong security focusSkills to master
- This path requires a broader remit beyond security, encompassing overall IT strategy, infrastructure, and often product development. You'd need to demonstrate strong business leadership, P&L ownership, and a deep understanding of how technology drives business value, all while maintaining a strong security-first mindset.
You're ready to move on when
- Successfully managed large-scale IT operations and digital transformation initiatives.
- Demonstrated strong financial acumen and P&L ownership for technology budgets.
- Proven ability to build and lead diverse technology teams (not just security).
- Deep understanding of how technology strategy aligns with and enables overall business strategy.
- Maintained a consistent focus on security and resilience within broader technology leadership.