Security professionals want leaders who have already led their organization through a major cyber incident – regardless of how things turned out
Research from ISC2 reveals what makes for a good security leader
Cybersecurity professionals are less likely to trust a boss who's never been through the mill of managing a major security incident.
Data from antivirus vendor Sophos suggests that CISOs have a one-in-four chance of losing their jobs after an attack. But new research from ISC2 shows that three-quarters of security professionals reckon leaders are more credible if they've already led their organization through a major cyber incident – regardless of how things turned out. Just 9% disagreed.
Overall, the survey revealed that the most trusted security leaders are those who create confidence through transparency, consistency, and an ability to align security priorities with business outcomes. Those who can keep calm and carry on, demonstrating decisive leadership under pressure, are far more likely to earn lasting credibility with their teams and across the enterprise.
Unfortunately, though, cybersecurity bosses don't generally seem to be managing this.
Only 34% of cybersecurity professionals said they were very confident in their current cybersecurity upper leadership, with 15% extremely confident. Three-in-ten said they had moderate confidence, 15% were only slightly confident, and 6% said they had no confidence in their cybersecurity leaders at all.
Security staff are particularly keen on leaders who can communicate risk to senior leadership and boards, with 95% of respondents reckoning this as very important.
Other big pluses included a strategic and long-term cybersecurity vision, along with the ability to effectively work with senior leadership and boards to secure budget, and being transparent about decisions and actions.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Decision-making under pressure, building and leading high-performing teams, and technical cybersecurity expertise were all very important to more than eight-in-ten – more so than actual technical cybersecurity expertise, at 75%.
"The most important trait in a cybersecurity leader is the ability to align security strategy with business goals while earning trust through clear judgment, communication, and accountability," noted one respondent.
Bosses wanting to earn their staff's respect, said ISC2, need to be transparent about risks, priorities, and challenges. "Teams and executives are more likely to trust leaders who provide realistic assessments rather than overly optimistic narratives," the researchers said.
Keeping calm and carrying on in high-pressure incidents or periods of change also boosts a security leader's reputation, while there's much greater trust when leaders manage to create an environment where teams feel supported, heard, and accountable.
Strong cybersecurity leaders invest time in understanding business objectives and collaborating across departments, helping position security as an enabler rather than a blocker.
"For leaders who now find themselves in an environment where cybersecurity risk impacts every part of the organization, it is the ones who communicate clearly, empower their teams and demonstrate calm, decisive leadership under pressure that are far more likely to earn lasting credibility with their teams and across the enterprise," the researchers said.
"Ultimately, the most successful cybersecurity leaders are not simply those who protect systems and data, but those who create trust in their leadership when it matters most."
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Hospital cyber attacks are increasingly hitting patient careNews New research shows only 14% are confident they can lose access to health records for 72 hours without risk to patients
-
Russian sentenced to jail for his part in ransomware attacksNews Aleksei Volkov operated as an initial access broker, helping cybercrime groups, including the Yanluowang ransomware group
-
Google issues warning over ShinyHunters-branded vishing campaignsNews Related groups are stealing data through voice phishing and fake credential harvesting websites
-
Former NCSC head says the Jaguar Land Rover attack was the 'single most financially damaging cyber event ever to hit the UK' as impact laid bareNews Researchers said they place the UK financial impact of the attack on Jaguar Land Rover at around £1.9 billion.
-
Japan running super dry of its favourite beer as Asahi cyberattack continuesNews Production of Asahi beer, one of the country's favourite beverages, has been halted, and reserves are running low
-
A new 'top-tier' Chinese espionage group is stealing sensitive datanews Phantom Taurus has been operating for two years and uses custom-built malware to maintain long-term access to critical targets
-
Asahi production halted by cyberattackNews Yet another big brand suffers operational disruption following apparent hacking attack
-
Kido nursery hackers threaten to release more details – along with the personal data of 100 employeesNews The attack is the first to be claimed by the new threat group 'Radiant'


