✅ A good CISO is an executive who manages technological risk.
❌ A bad CISO is an IT manager who simply manages security tools.
✅ A good CISO defines a clear strategy: how to beat the adversaries.
❌ A bad CISO confuses a list of projects and vendors with a strategy.
✅ A good CISO builds mechanisms that generate value over time (a flywheel).
❌ A bad CISO puts out fires, always in emergency mode.
✅ A good CISO ensures that bad news travels fast.
❌ A bad CISO is the last one to find out.
✅ A good CISO actively manages vendors, software, and supply chains.
❌ A bad CISO just keeps buying new security products.
✅ A good CISO invests in long-term relationships with long-term people.
❌ A bad CISO has a purely transactional approach.
Translation and adaptation from an article by Phil Venables and Mike Aiello (philvenables.com – September 20, 2025).
In a modern organization, an effective security program is one of the most powerful levers for enabling innovation, building resilience, and creating lasting trust with customers and partners. However, the role of the Chief Information Security Officer (CISO) is often misunderstood and undervalued.
After decades spent building and observing security programs in various contexts, Phil Venables and Mike Aiello have reached a clear conclusion: the difference between a good CISO and a bad CISO is not a matter of budget or technology, but of mindset, strategic vision, and accountability.
Just as there are good and bad product managers, there are good and bad CISOs. Here is how to recognize them.
Executive mindset, not technical
A good CISO is, first and foremost, an executive. They act like the CEO of the security program, taking full responsibility for outcomes and measuring themselves in terms of business impact. They understand the company’s business model, its culture, and its priorities. They don’t just “manage security”; they build and lead a risk management strategy consistent with business goals.
Conversely, a bad CISO has a more reactive and limited approach: they manage tools, collect excuses, and feel hindered by users, developers, executives, and budgets. They never take full responsibility and tend to view problems as external to their perimeter.
Clear strategy vs. task list
A good CISO knows that an operational plan is not a strategy. They define a coherent vision on how to win against adversaries and build resilience over time. Their strategy is generative: it inspires other functions, creates useful work, and simplifies choices. They clearly define the “what,” leaving flexibility on the “how.”
A bad CISO, on the other hand, presents long lists of projects, initiatives, and purchases, but fails to explain a unified direction. Their operations are consuming: they waste team energy, wear down internal relationships, and burn political capital without generating value.
From craftsmanship to industrial scale
A good CISO builds virtuous, self-reinforcing mechanisms: processes that reduce the unit cost of control, scalable solutions, and environments where the secure path is also the easiest one. They transform security from a craft-based job into an industrial capability. They know how to anticipate systemic risks and build sustainable solutions.
A bad CISO always works in emergency mode. They run from one incident to the next, measure productivity in closed tickets, and live in a constant state of crisis. Their approach is reactive, inefficient, and always leaves structural problems unresolved.
Strategic vendor management
A good CISO doesn’t just buy security tools; they select products that are secure by design. They use their purchasing power to positively influence vendors and build more robust supply chains. They work to reduce the demand for reactive solutions by acting on the cause, not just the effects.
A bad CISO sees every new tool as a panacea. They react to sales pressure, rely on vendor promises, and consider technology as an automatic answer to process or people problems.
Effective communication
A good CISO speaks the language of business: risk, capital, opportunity. They are able to quantify risks and disseminate clear, structured documents (white papers, FAQs, position papers) to scale their communication and build consensus. They know that the perception of risk is just as important as the risk itself. They are narrative builders.
A bad CISO communicates in technical jargon, relies on confusing metrics, and complains about not being heard. They only speak verbally, avoid taking written positions, and remain blindsided when small incidents trigger large reactions from stakeholders.
Technical competence used with empathy
A good CISO has a solid technical foundation, but uses it to understand operational constraints, facilitate dialogue with engineers, and build realistic solutions. Their competence generates trust, not authoritarianism.
A bad CISO may not have enough technical competence to talk to colleagues, or if they do, they use it as leverage to impose solutions. They hinder innovation, create friction, and isolate themselves.
Feedback culture
A good CISO wants to know about problems before anyone else. They create a climate of trust where people feel free to tell the truth, even when it is uncomfortable. They foster transparency, accountability, and widespread awareness.
A bad CISO is often the last to know things because they have built an environment where reporting problems is risky. They remain trapped in the bad news filter.
Team empowerment
A good CISO builds an autonomous team, values emerging leaders, and distributes responsibility through federated models like “security champions.” They are not a bottleneck, but a multiplier.
A bad CISO centralizes everything, makes all decisions, and makes themselves indispensable. This makes them a single point of failure.
Relationship with the board
A good CISO helps the board govern better. They teach them what questions to ask, turn reporting into strategic dialogue, and build shared accountability.
A bad CISO just “gives updates” and only tries to get more budget. They do not help the board grow in their understanding of risk.
Network and collaboration
A good CISO invests in the long term, builds relationships based on trust, and contributes to their network as much as they receive. They work for the success of the organization and create the conditions for speed and autonomy.
A bad CISO is opportunistic: they activate their network only when they need something, ask without giving, and want control but not sharing. By doing so, they slow down the entire system.
Good CISOs are technical, practical, and business-oriented figures. They inspire teams, collaborate with stakeholders, and take real responsibility for change. They know how to balance strategy and tactics without letting one crush the other.
Bad CISOs simply do none of this. Or they do it too late. For organizations that do not yet have a figure of this caliber internally, relying on a Virtual CISO service can be the most concrete way to bridge the gap without waiting to find the right profile on the market. To learn more about the role and responsibilities of this figure, the guide on what a Virtual Chief Information Security Officer does is also useful.
Frequently Asked Questions
- What is the main difference between a good CISO and a bad CISO?
- The difference does not lie in the budget or the tools available, but in the mindset: a good CISO acts like an executive, takes responsibility for results, and builds a strategy consistent with business goals. A bad CISO manages tools and reacts to events without ever addressing structural problems.
- Can a company without an internal CISO still have effective security governance?
- Yes. Many organizations, especially medium-sized ones, use an external Virtual CISO to obtain the same strategic guidance without the costs and time of a market search. The model works well when the vCISO has direct access to the board and can act with full responsibility for the security program.
- How do you recognize a good CISO during a selection or evaluation process?
- A good CISO knows how to explain their strategy in terms of risk and business impact, not just in technical terms. They talk about scalable mechanisms, how they built a feedback culture in the team, and how they managed the relationship with the board. Those who only respond with lists of adopted tools or obtained certifications are likely still in an operational, not strategic, mindset.
Protect your organisation with Virtual CISO.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
