Cybersecurity leadership has evolved far beyond protecting networks. Today's most effective CISOs are helping organizations navigate business strategy, AI governance, trust, and resilience. Drawing from the Cyber Means Business interview series, this collection explores the ideas reshaping the role of the modern security leader.
Twenty years ago, CISOs were primarily responsible for protecting networks, responding to incidents, and reducing technical risk. Today, they sit alongside CEOs, boards, legal teams, finance leaders, and business executives, helping organizations navigate artificial intelligence, regulatory pressure, digital trust, supply chain complexity, and enterprise risk. As cyber threats have become business threats, the role of the CISO has expanded well beyond technology.
That evolution has fundamentally changed what organizations expect from security leaders. Today's most effective CISOs are measured by how well they prevent attacks but also in how they influence business strategy, communicate with boards to manage enterprise risk, enable innovation without sacrificing governance, strengthen organizational resilience, and build trust with customers, employees, and partners.
The conversations featured throughout Cyber Means Business reflect this transformation. While each interview examines a different challenge facing today's enterprises, together they tell a broader story about the future of cybersecurity leadership. Whether discussing AI governance, third-party risk, organizational culture, board communication, or workforce development, these leaders consistently return to the same idea: security creates the greatest value when it helps organizations move forward with greater confidence rather than simply slowing them down.
The following collection offers practical perspectives from some of today's most respected security executives on what leadership looks like as cybersecurity becomes inseparable from business strategy.
From Gatekeeper to Business Strategist
For decades, many security leaders were viewed as the people who slowed projects down. Their job was to identify risk, enforce controls, and, when necessary, say no. As organizations accelerated digital transformation and AI adoption, however, that approach became increasingly untenable. Business leaders needed security executives who could help them innovate safely, not just point out what could go wrong.
That shift is at the heart of Matt Hillary's philosophy. The CISO of Drata , an AI-native platform that centralizes governance, risk, compliance, and trust management, argues that security teams must move beyond serving as the "Department of No" and instead become the "Department of Know," helping business leaders understand risk well enough to make informed decisions. Rather than attempting to eliminate every threat, modern CISOs should focus on enabling the business to take the right risks responsibly.
As Hillary explains, that also requires security leaders to change the way they communicate. Boards and executive teams aren't looking for detailed discussions about vulnerabilities or security tools. They want to understand how cyber risk affects customer trust, operational resilience, revenue, and long-term business objectives. Security becomes more valuable when it's framed as a business enabler rather than a technical function.
Nick Kathmann, former chief information security officer at governance, risk and compliance provider LogicGate, echoes that
idea from the boardroom perspective. In his view, one of the biggest mistakes CISOs make is assuming directors want technical details. Instead, boards are responsible for setting the organization's risk appetite and making strategic decisions about where to invest, grow, and accept uncertainty. Effective security leaders help boards understand whether cyber risk aligns with those broader business objectives.
When security is presented in terms executives already use to evaluate the business, it becomes easier to secure investment, earn credibility, and influence decision making, Kathmann says.
Taken together, these conversations illustrate one of the defining changes in modern cybersecurity leadership. The most effective CISOs no longer measure success by how many initiatives they stop. They measure it by how confidently they help the business move forward.
Trust Has Become the Ultimate Security Metric
Technology alone doesn't determine whether an organization is secure. The decisions people make, the relationships they build, and the confidence they inspire often have just as much influence on business outcomes. As organizations become increasingly interconnected, trust has emerged as one of the most valuable assets security leaders are responsible for protecting.
Dr. Margaret Cunningham, vice president of security and AI strategy and field CISO at Darktrace, a cybersecurity company that uses AI to detect, prevent, and respond to cyber threats, believes that trust starts with understanding human behavior. Drawing on her background in behavioral science, security research, and organizational dynamics, she argues that security outcomes are shaped less by technical controls than by how people perceive risk, communicate under pressure, and make decisions in uncertain situations. Organizations that rely solely on policies or compliance programs often miss the underlying factors that influence secure behavior.
Instead, Cunningham advocates designing security programs that reflect how people actually work. Open communication, and workflows that support rather than hinder employees help organizations make better decisions, strengthen resilience, and maintain customer confidence. They provide employees the psychological safety to make prudent decisions. She also notes that digital trust can often be measured by engagement. When employees or customers stop using systems they once relied on, it may signal that trust has begun to erode.
Ross McKerchar, chief information security officer at Sophos, extends that conversation beyond an
organization's own workforce to the broader ecosystem of vendors and business partners. Having led the company's response to a sophisticated nation-state attack targeting Sophos firewall products, McKerchar argues that trust must be earned not only through strong security practices but also through transparency and accountability when incidents occur.
His experience underscores an important reality: every vendor, including those in cybersecurity, introduces risk. Organizations must evaluate security partners with the same rigor they apply to any critical supplier, recognizing that customer trust depends as much on how companies communicate and respond during a crisis as on the technical protections they provide. In McKerchar's view, openness carries risk, but silence often carries far greater consequences.
| Read more: When Security Vendors Become the Risk |
The discussions illustrate how trust has become a defining measure of effective security leadership. Whether fostering cultures that encourage better decision-making, strengthening customer confidence, or building transparent relationships across complex supply chains, today's CISOs recognize that trust is not simply a byproduct of good security. It is one of the most important business outcomes security programs are designed to achieve.
Governing AI Without Slowing Innovation
Few technologies have reshaped the role of the CISO more quickly than generative AI. As organizations race to integrate AI into products, operations, and decision-making, security leaders face a difficult balancing act: protecting the business without stifling innovation. Increasingly, the answer lies not in restricting AI, but in building governance models that allow organizations to adopt it responsibly.
Jim Routh, chief trust officer at Saviynt, an identity security company, and a veteran CISO whose leadership experience includes Aetna, MassMutual, and JPMorgan Chase, believes security leaders must abandon the idea that AI can simply be controlled through blanket restrictions. Instead, organizations should focus on governance frameworks that encourage responsible experimentation while applying appropriate safeguards based on each business use case.
Routh advocates a collaborative, cross-functional approach that brings together security, legal, privacy, finance, and business leaders to evaluate AI initiatives. Rather than creating one-size-fits-all policies, organizations should assess individual use cases, identify potential risks, and implement controls that enable innovation to move forward safely. In his view, effective governance isn't about saying "no." It's about creating an environment where the business can confidently embrace new technology without compromising its values or exposing itself to unnecessary risk.
Malcolm Harkins, former CISO of Intel and current chief security and trust officer at HiddenLayer, shares
that philosophy while focusing on another critical aspect of AI adoption: protecting the systems themselves. As organizations increasingly rely on AI to generate revenue, improve efficiency, and support business decisions, Harkins argues that securing those systems has become a board-level responsibility.
He warns that ethical AI principles alone are not enough. Organizations also need runtime protections, clearly defined privilege boundaries, and governance models that manage AI throughout its lifecycle. Just as businesses have long protected their financial systems and critical infrastructure, AI platforms require continuous monitoring, access controls, and oversight to ensure they remain trustworthy as they evolve.
| Read more: Why GenAI Security Is a Boardroom Imperative |
These interviews highlight an important shift in security leadership. The question is no longer whether organizations should embrace AI, but how they can do so responsibly. For today's CISOs, governance has become less about restricting innovation and more about creating the guardrails that allow it to flourish.
Building Organizations That Can Adapt
No organization can eliminate every cyber threat. Today's security leaders recognize that resilience comes from building organizations that can anticipate change, respond effectively to disruption, and recover quickly when incidents occur. That requires looking beyond technology to the people, partnerships, and culture that shape long-term business performance.
Bob Maley, chief security officer at Black Kite, a third-party cyber risk management company, and former security executive at PayPal and the Commonwealth of Pennsylvania, argues that one of the greatest sources of business risk lies outside an organization's own walls. Modern enterprises depend on thousands of vendors, suppliers, cloud providers, and service partners, creating a web of interconnected relationships where a single weak link can have far-reaching consequences.
Rather than treating third-party risk as a compliance exercise, Maley encourages organizations to quantify its potential financial and operational impact. He advocates focusing resources on the vendors that matter most, continuously monitoring critical relationships, and helping boards understand how supplier risk can affect revenue, resilience, and business continuity. As organizations become more interconnected, managing external relationships has become an essential part of enterprise strategy.
Resilience also depends on the people inside the organization. Gary Brickhouse, CISO at GuidePoint
Security, a cybersecurity consulting and services company, believes the cybersecurity talent shortage should be viewed not as an HR challenge but as a business risk with direct implications for operational resilience and customer trust. Organizations that lack experienced security professionals often struggle to respond quickly to incidents, manage critical vulnerabilities, and sustain long-term security programs.
Brickhouse argues that boards should evaluate investments in cybersecurity talent the same way they assess other enterprise risks, recognizing that workforce development, retention, and training directly contribute to business resilience. Strong security teams don't simply reduce technical risk—they help organizations remain agile and prepared in the face of disruption.
Andy Ellis, former chief security officer at Akamai Technologies and founder of the management advisory firm Duha, extends that conversation by focusing on organizational culture. He argues that resilient organizations are built on trust, collaboration, and shared ownership of security rather than fear or rigid enforcement. When security teams position themselves as partners who help colleagues succeed instead of gatekeepers who create friction, they strengthen both business performance and security outcomes.
Ellis believes that inclusive leadership, open communication, and a culture that encourages employees to raise concerns and solve problems together create organizations that are better equipped to navigate uncertainty. In that environment, resilience becomes more than an incident response capability. It becomes part of how the business operates every day.
These thought leaders reinforce a common lesson: resilience isn't built through technology alone. It emerges from trusted partnerships, capable people, and organizational cultures that can adapt as threats, technologies, and business priorities continue to evolve.
The Business of Security Leadership
The conversations collected here reflect a profession in transition. While the technologies and threats continue to evolve, the defining challenge facing today's CISOs is increasingly consistent: helping organizations navigate uncertainty without slowing progress.
Whether advising boards on enterprise risk, building cultures rooted in trust, governing AI responsibly, strengthening third-party relationships, or developing the next generation of security talent, today's most effective security leaders are expanding their influence far beyond the security organization. They are becoming strategic advisors, business partners, and architects of resilience.
As cybersecurity becomes inseparable from business strategy, the role of the CISO will continue to evolve. These conversations offer a window into that transformation—and the leadership principles that will shape the next generation of security executives.
Written by Joan Goodchild
Joan Goodchild is a veteran journalist, editor, and writer who has been covering business technology and cybersecurity for more than a decade. She has written for several publications and previously served as editor-in-chief for CSO Online.