The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Director/VP, Security Operations
5-10 years at this level before C-suiteSkills to master
- Deep operational security leadership, large team management, budget oversight (multi-£M), incident response at scale, strategic vendor management, cross-functional influence.
You're ready to move on when
- Successfully led a global SOC and incident response function through multiple major incidents.
- Consistently met or exceeded operational security KPIs (e.g., MTTR, vulnerability reduction).
- Built and retained a high-performing security operations leadership team.
- Demonstrated ability to present complex operational risks to senior leadership.
- 2
CISO of a Mid-Sized Enterprise
3-7 years as CISO before moving to a larger, more complex organisationSkills to master
- End-to-end security programme ownership, board reporting, enterprise risk management, regulatory compliance, strategic planning, team building and development.
You're ready to move on when
- Successfully built or transformed a security programme from the ground up in a previous CISO role.
- Demonstrated strong relationships and influence with the Board and executive team.
- Navigated significant security challenges (e.g., major breaches, regulatory audits) with positive outcomes.
- Managed a comprehensive security budget and demonstrated ROI on investments.
- 3
Head of Enterprise Risk Management (with strong cyber focus)
7-12 years at this level before C-suiteSkills to master
- Enterprise risk framework design, risk quantification, regulatory compliance, business continuity planning, strategic risk communication to the Board, cross-functional risk governance.
You're ready to move on when
- Developed and implemented an enterprise-wide risk management framework.
- Successfully integrated cyber risk into the overall business risk register.
- Demonstrated strong analytical skills in quantifying and communicating complex risks.
- Proven ability to influence business leaders on risk mitigation strategies.