#1753887: We Strongly Value Your Willingness to Accept Less

Description: More companies are under pressure to hire CISOs to build a security department, lead a team, and report to the board. But being forced to hire a CISO doesn't necessarily mean the company is ready to provide the authority and pay that traditionally goes with the title. Could this be why we see so many CISO job listings are looking to hire CISOs with no CISO experience?

Patching won't evict a squatter
Patching a system an attacker already controls doesn't evict them. CISA's new directive replacing CVSS with a stakeholder-specific scoring model is built around that exact problem. Chris H. of Zenity points out the directive only binds federal agencies, but two of its four risk factors deserve a much wider audience. Whether exploitation can be fully automated, and at what level of control an attacker gains from a given vulnerability. Imagine CVSS itself scoring those two questions instead of an abstract worst-case number. Getting closer to local context beats waiting for the next federal mandate to force the issue.

Boards accept risk by saying nothing
Most boards think having a CISO means the risk is covered. That assumption is exactly what Ross Brouse of Continuous Networks, LLC pushes back on, arguing that governing risk means someone owns the consequences long before ransomware hits at 2 am. If a board hasn't formally approved decision rights and risk tolerance, it is already accepting risk by default. That's why organizations need to determine when a CISO has the authority to accept loss and pause operations. The CISO needs to feel empowered to use this authority. Without that clarity on both sides, boards find out where they stand the hard way.

Fast enough to hide the damage
Moving fast enough can turn any team into a very resilient catastrophe machine. That's the pattern Mitchell Hashimoto, co-founder of HashiCorp, calls AI psychosis, and he sees it spreading fast. It's a replay of the old argument between mean time between failures and mean time to recovery from the early cloud era, except now the belief is that shipping bugs is fine because agents fix them faster than any human could. But bug reports can drop while risk builds underneath, and test coverage can climb while nobody understands what the system is doing anymore. Change moves so fast that architecture can decay before anyone notices. A system that looks healthy and one that is healthy are no longer the same thing.

Job posting for a unicorn
The hiring bar for CISO roles keeps shifting. Ironically, the latest requirement is asking for no CISO experience. That's the pattern Andy Ellis discovered after talking to recruiters and hiring teams. It signals something about the business hiring. Are they looking for the talent, but not willing to offer the pay? Do they want to give the title so they'll talk to the board, but not the authority? This new job-listing pattern for CISOs echoes the babysitter job posting that made the rounds, which asked for impossible and demanding qualifications paired with embarrassingly low pay. Two red flags like that rarely show up alone. Calling it out during the hiring process beats discovering it after the offer is already signed.
More info: https://www.linkedin.com/pulse/we-strongly-value-your-willingness-accept-less-cisoseries-ktgjc

Date added Sept. 15, 2026, 11:57 p.m.
Source LinkedIn
Subjects
  • PodCasts / Webcast / Webinar / eSummit / Virtual Event etc.
  • Security Management/Strategic Security/ROI/ROSI - CISO and Higher Level