The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
VP, Global Security Operations
16-20 years experienceSkills to master
- Deep expertise in managing large-scale, 24/7 security operations centres, incident response, and threat intelligence programmes across multiple regions. Proven ability to lead and scale security teams.
You're ready to move on when
- Successfully managed a global security operations budget of £5M+.
- Led the response to multiple significant security incidents with positive outcomes.
- Built and retained a high-performing security operations leadership team.
- 2
Director of Information Security / Head of Security
16-20 years experienceSkills to master
- Comprehensive understanding of all security domains (governance, risk, compliance, architecture, operations). Experience building and running an entire security function for a large business unit or smaller enterprise.
You're ready to move on when
- Accountable for the security posture of a significant business unit or company.
- Regularly reported on security risk to the executive committee.
- Successfully implemented major security programmes (e.g., ISO 27001 certification).
- 3
Chief Information Officer (CIO) or Chief Technology Officer (CTO)
Transition from CISO after 5+ yearsSkills to master
- Expanded focus on overall IT strategy, digital transformation, infrastructure, and application development. A CISO moving to CIO/CTO brings a security-first mindset to technology leadership.
You're ready to move on when
- Demonstrated strong business acumen beyond security.
- Successfully partnered with IT/Tech leadership on major initiatives.
- Exhibited leadership capabilities across broader technology domains.