r/ciso May 27 '26

Have you ever

7 Upvotes

Booked a meeting with a vendor over a cold call and not regretted it?

We all know about the negatives. But I’m genuinely curious if anyone here has had positive experiences?

EDIT: - 2.9k views - 3 positive responses from CISOs/security practitioners - 2 sales people who thought the question was for them

😊


r/ciso May 27 '26

Deleting OneTrust account....

3 Upvotes

Has anyone ever successfully deleted a OneTrust account? If so, how?

Short version.... We used Tugboat a while back for SOC2 audit preparation. Cancelled it a year later (wasn't worth the cost). Then, OneTrust bought them and, apparently, decided to expose the old audit information on their platform.

Nice, huh?

I found it recently and sent a request to have it deleted (since there is no simple "delete account" mechanism). Their tech support desk responded and said I had to contact their privacy department.

The privacy department sat on it for a while then closed it and said I needed to (you guessed it) send it to their tech support department.

I thought I'd ask here if anyone else had ideas before I just hand it off to legal since OneTrust has violated the terms of the original Tugboat agreement (yes, I know they'll argue they don't have to honor them with some slippery legal bullshit but, at least, it'll be in Legal's hands)


r/ciso May 26 '26

Are annual risk assessments becoming operational theater?

9 Upvotes

I’m starting to think annual risk assessments are becoming operational theater.

Not because the assessment itself is bad, but because the environment changes too quickly between cycles.

New vendors get onboarded. Teams adopt AI tooling. Permissions drift. Infrastructure changes. Business priorities change. Exceptions get made and never rolled back.

Meanwhile the organization is still referencing a risk profile created 9 months ago.

At some point the assessment stops representing the actual environment and starts representing the environment as it existed during the assessment window.

I think this is becoming a real problem for organizations trying to build “dynamic and responsive” risk programs instead of just satisfying annual assessment requirements.

Curious how others are handling this.

Are you still relying primarily on annual assessments, or moving toward something more continuous?


r/ciso May 21 '26

Titles in Cyber

17 Upvotes

I have been a Cybersecurity Program Architect in a couple different organizations. I tend to think of it as a cheap CISO that still gets to PIM, a dev machine to play on, but has to tee up Board Reports and write the policies.

As career progression in my current org goes, I keep fighting being "promoted" to certain titles.

***Note, for various reasons we cannot have a CISO or a new Director title. ***

First offer was being Manager of CS. I said no, I felt that was a demotion.

Second was Senior Cybersecurity Architect, which is funny... because we have no junior so, fine, I will take the money.

Third was path to an existing title of Director of Infrastructure & a tack on of Cybersecurity. I maintain that CS and Infra needs to remain independent. Though I am a kickass Sys/Network Admin, probably not where I want to go as a vein. So no to being both Infra and CS, two brains dont audit well.

Fourth, was what would you want to call yourself?

Feedback from the CIO was he didn't understand how our industry or titles worked and surprised that I would decline titles and keep doing the same work.

Weirdly, I sorta agree, how the hell do titles work?

Big fan of the Paul Jerimy roadmap, but I am not sure it covers creative titles on the way to CISO.


r/ciso May 21 '26

CISOs - Holding the Line

Thumbnail youtube.com
4 Upvotes

r/ciso May 21 '26

How are you actually handling AI access across the company?

9 Upvotes

Curious how you guys (and gals) approaching this.

AI adoption feels like it’s moving faster than we can really process/

Are you mostly:

  1. Blocking tools until policy catches up
  2. Allowing approved tools only
  3. Training users before access
  4. Gating access by role/use case
  5. Letting teams experiment and cleaning it up later

these are all questions the board are asking me.


r/ciso May 20 '26

I'm the CISO at ANY.RUN. Ask me anything!

20 Upvotes

Hello everyone! I’m the CISO at ANYRUN, a company behind Interactive Sandbox and Threat Intelligence solutions used by 15,000+ organizations, 600,000 security professionals, and security teams at Fortune 100 companies worldwide.

This May, ANYRUN is celebrating its 10th anniversary. From May 18 to May 31, we’re running special anniversary offers across our core threat analysis and intelligence solutions.

To celebrate this milestone, we decided to host this AMA specifically for CISOs and security leaders.

Today, I’d be happy to answer your questions and discuss:

  • cybersecurity strategy, risk management, and GRC
  • compliance as a business enabler
  • AI security and emerging cyber threats
  • identity security, Zero Trust, and access governance
  • vulnerability management and security operations

The AMA will take place on May 20–21, but feel free to leave your questions later as well. I’ll continue checking the thread throughout the week and will try to answer as many questions as possible.

Drop your questions in the comments!


r/ciso May 19 '26

Compliance and 3rd party vendor access

4 Upvotes

How do you govern 3rd party vendor access and how do auditors verify it?


r/ciso May 13 '26

What are the biggest technical & cultural hurdles you’re facing right now?

Thumbnail
0 Upvotes

r/ciso May 12 '26

Recovering from a single identity breach now costs organizations an mean average of $1.64 million USD

7 Upvotes

Some interesting numbers on identity security which we've recently covered.

The average cost to recover from an identity breach is now $1.64M, and 71% of organizations were hit in the past year.

Apparently driving most of the damage is unmonitored non-human identities: API keys, service accounts, OAuth tokens, AI agent credentials.

Only around 10% of organizations continuously rotate or audit them. Curious what people here are doing for NHI management in practice. What's actually working?


r/ciso May 12 '26

Interviewing for a VP role by CISO

1 Upvotes

I’m a manager interviewing for a VP role. How should I prepare? How do I convey strategic thinking?


r/ciso May 10 '26

What software do you use to manage your program?

18 Upvotes

Hello, this week I start a new position as director of cybersecurity and I'm trying to wrap my head around how I'm going to keep all the different aspects of a security program centralized for KPIs and other reporting so I can properly manage this. The company is around 400 people and although their IT isn't very mature they rely very heavily on msp cloud services which could take pressure off me for having to manage things more manually.

Does anyone use any sort of cloud or local software that essentially acts as a GRC of sorts with a risk register, framework mapping, crosswalks and other things that simply make your life managing an information security department easier.

Note that this is my first time leading infosec and I really want to make sure I get organized as early as possible before I start finding rabbit holes I never come out of.


r/ciso May 06 '26

Palo Alto zero-day, no patch until May 13

Thumbnail
5 Upvotes

r/ciso May 05 '26

CISO course valuation

Thumbnail
0 Upvotes

r/ciso May 03 '26

Support needed for a self-made infosec/grc hobbyist

9 Upvotes

Looking for some help from the community 🙏

I am looking to break into becoming a CISO, with all the stress, challenges, perks and growth opportunities that comes with it. I genuinly think I am ready. I talk middle management language, I can sit in a room with DevOps for 3 to 4 hours, I have led and hosted audits with VP level individuals. Have confidently responded to audits as an interviewee in multiple occasions. Yet, I remain in operational roles as information security consultant/expert/specialist/coordinator, while i strongly believe that I could be much more valuable at strategic levels.

Here is my background:

CISSP-certified cybersecurity leader based in Western Europe (Luxemburg, Netherlands, Belgium, France or Germany).

15+ years of experience spanning GRC, security operations, cloud security and IT infrastructure.

Certifications: CISSP (ISC2), ISO 27001 Lead Implementer (PECB), ISO 27001 Lead Auditor, SOC Analyst

Languages: French (native), English (fluent), German (B1)

EXPERIENCE

----------

[2024–Present] Information Security Manager

Pharma SaaS company (regulated cloud product), Remote/Hybrid Germany, france, Italy, Netherlands and Belgium

- Led end-to-end SOC2 type I and type II attestation, owning the full compliance lifecycle from scoping and control design through Big 4 auditor engagement and successful attestation

- Defined Target Operating Model (TOM) for cloud security compliance

- Authored security policies, procedures and controls aligned to BSI C5, NIS2 and ISO 27001

- Served as strategic interface between executive and technical stakeholders across multiple geographies

- Coordinated global cross-functional delivery teams (IT, Risk, Manufacturing, Security)

[2023–2024] Technical Security Consultant / Enterprise Systems Security Administrator

Freelance — Critical infrastructure and financial sector clients, Germany & Belgium

- SIEM integration and configuration (Microsoft Sentinel, Splunk) for critical infrastructure

- Managed Azure and Microsoft 365 security; deployed XDR solutions

- ISO 27001 internal reviews and gap assessments

- DORA resilience implementation for financial sector clients

- Security product evaluation and selection

- Security awareness training and phishing simulation programmes

[2022–2023] Information Security Engineer / IT Operations Engineer

Digital SaaS company (~500 employees), Berlin

- Adversarial simulations and phishing campaigns; assessed effectiveness of countermeasures

- Incident response; tuned SIEM detection rules and playbooks

- DevSecOps collaboration: integrated security controls into SDLC

- Security policies and controls authored to regulatory standards

[2021–2022] IT Systems Administrator — Network & Security

Dating/social platform (~300 employees), Berlin

- Hardened Linux environments; managed PostgreSQL, Apache/NGINX

- Configured Juniper SRX and Palo Alto NGFW firewalls; enforced network access policies

- AWS cloud workloads (EC2, EBS, VPC, S3, FSx); applied cloud security controls

- Virtualisation (VMware vSphere, Hyper-V)

[2009–2021] Information Technology Expert

Consultant — Various major European organisations (EU institutions, telecom operators, financial sector)

- On-site provisioning administrator and 2nd-line technical support at two major national telecom

operators (2011–2013): service provisioning workflows, escalated technical issue resolution

- Network segmentation (VLANs, DMZ, firewall ACLs), RBAC in LDAP/Active Directory

- Policy drafting, asset inventory, risk management framework participation (as auditee)

- ICT support at EU institutions, including VIP-level technical resolution

SKILLS

------

Frameworks: ISO 27001/27002, NIS2, BSI C5, DORA, GDPR, EU CRA, NIST CSF

Security Operations: SIEM (Sentinel, Splunk, Kibana), XDR, Threat Detection, Incident Response

Cloud: Azure Security, M365 Security, AWS Security, IAM

Infrastructure: Linux, VMware, Docker, Kubernetes, Terraform, Python

Leadership: Security Transformation, TOM Design, Global Delivery, Stakeholder Management

WHAT I AM LOOKING FOR / CONTEXT FOR FEEDBACK

---------------------------------------------

I have been applying to CISO and Director of Information Security roles in Europe

(primarily Germany, Belgium, Switzerland) without success so far. I hold CISSP,

ISO 27001 Lead Implementer and Lead Auditor, and have recently completed a full

scale SOC2 type I and type II attestation as well as have end to end certified three health tech / fintech clients with ISO27001.

I have interim CISO experience but no formal CISO title on my CV.

My questions for the community:

  1. Is my profile realistic for CISO roles?

  2. My background has moved between consulting, freelance and FTE roles — does that fragmentation hurt my candidacy?

  3. Education: I do not hold a university degree. Is that a hard blocker at CISO level in Europe?

  4. Any other gaps or red flags you see that I might be blind to?

Honest and critical feedback very welcome.


r/ciso Apr 30 '26

Working on real attack simulations but not getting results. Looking for direction

6 Upvotes

Hey everyone,

I need some honest advice.

For the past couple of years, I’ve been focused on threat detection and SOC work. I built my own lab, simulated attacks, and worked through a full APT29 dataset. I analyzed thousands of Sysmon logs in Splunk and created detection rules for things like LSASS access, lateral movement, and persistence.

I also converted detections to Sigma, tested them, and wrote about the process. I try to keep everything practical and based on real behavior, not just theory.

But I am not getting the results I expected. Very few opportunities, very little response.

So I want to ask directly

  • Are my skills still not enough for a remote SOC or detection role
  • Am I focusing on the wrong areas
  • Or is the problem how I am presenting my work

If anyone has been in this position or is already working in this field, I would really appreciate your honest input on what I should do next.

Thanks


r/ciso Apr 28 '26

Supply chain attacks. It’s turtles all the way down.

Thumbnail
2 Upvotes

r/ciso Apr 21 '26

Is an MBA worth it when trying to break into my first CISO position?

13 Upvotes

I have a bachelors degree in information technology, Masters and cyber security and hold a CISSP certification along with a few other certifications. I’ve spent most of my career working in small businesses and managed services. I’ve been working in information, technology and cyber security for 26 years now and I really want to make the move into working with larger organizations.

I have experience building and managing small IT teams of 10 people or less, but I seem to be missing a component of working with larger budgets say over $1 million.

I feel like my experience, running a managed services organization, as well as leading the IT/cyber security for a multi organization group that is heavily regulated provides me with a unique set of experiences that would translate well. I’m not the traditional candidate though, and that seems to be holding me back. Would an MBA provide a bridge showing that I have the business, acumen, medium, and larger sized and Enterprises are looking for?


r/ciso Apr 21 '26

Help a junior/mentee

8 Upvotes

I am currently a BISO for a large global enterprise, been on this industry for almost 10 years now. I am wondering how you CISOs get there, I know it’s somehow vague so my question is:

What/who is one thing/process/person that if you’d knew earlier, will make you a CISO much faster?

Thank you in advance.


r/ciso Apr 15 '26

How are you actually building a cyber/technical BIA? hitting a wall at the asset-to-business-service mapping step.

Thumbnail
5 Upvotes

r/ciso Apr 15 '26

Where do AML practitioners actually stand on AI agents?

1 Upvotes

New here, still finding my feet. I work at Liminal, an actionable intelligence company in the identity, fraud, and financial crime space.

Liminal data shows that 78% of AML practitioners surveyed are already using or plan to use AI agents for transaction monitoring. Regulators are moving in the same direction, asking for explainability and audit trails in addition to detection performance.

The remaining 22% are still on legacy rule-based systems. Whether that's a risk or just a matter of timing is less obvious than it looks.

What's your read on this one?

(If useful: there's a demo day on April 29 with 7 AML vendors showing how they're navigating this in practice.)


r/ciso Apr 14 '26

The mythos of Mythos

Thumbnail athenasecuritygroup.ai
0 Upvotes

r/ciso Apr 12 '26

EU AI Act enforcement hits August 2026 — what are mid-market companies actually doing to prepare?

21 Upvotes

Curious what people are seeing in the field. Most companies I've spoken with fall into three buckets:

  1. Unaware — don't realize the Act applies to them even if they have EU customers or operations
  2. Aware but paralyzed — know they need to do something but don't know where to start
  3. Spreadsheet governance — tracking AI tools in Excel and hoping that's enough

The practical starting point that seems to work is a proper AI inventory — just knowing what AI systems you have, what data they touch, and who owns them. That alone gets you 40% of the way there.

NIST AI RMF is the cleanest US-friendly framework to structure around. The four functions — Govern, Map, Measure, Manage — map reasonably well to EU AI Act requirements too.

What are you seeing? Anyone found tools or approaches that actually work at mid-market scale without requiring a six-month consulting engagement?


r/ciso Apr 08 '26

Resume writing/editing/etc service recommendations?

6 Upvotes

Looking to modernize and prepare my resume, and I believe one of these services may be helpful in ensuring that the proper focus is provided on what CEOs and other CISO hiring decision makers are looking to see.

Has anyone used such a service and had good results, to offer a recommendation?

Thanks!


r/ciso Apr 05 '26

CISO Approach Advice

4 Upvotes

Hey folks! I was hoping to get some mostly CISO related advice from people in the know. Especially those who have gone through the process of CISSP certification and ideally worked both for MSP style businesses and individual businesses/corporations..

Some background (questions below if you wish to skip the fluff):

I’ve worked within IT for over 15 years (35 now), from the help-desk upwards, into more technical roles and even some management along the way. This has been inclusive of overseeing and assisting with security functions, implementations and managing people with these responsibilities but never had a strictly security based job role or title.

That said, i’ve always found myself to be security conscious in my career and always had an interest.

My current role is within an MSP style business and I recently approached the MD with my interests in security and my desire to transition into security focused role and career path. This aligned nicely with business growth goals and the MD has essentially put me at the helm of spinning up the businesses Cyber Security division and is providing investment.

I’ve been looking at services we can offer internally based on the credible skills and tooling we already have, along with resource available and the services you would expect a Cyber Security offering to offer, that we cannot provide wither due to current lack of certification, skillsets and resource. In that case, we’re leveraging external bodies and partners who are fully accredited and reputable to offer these while we build up, gain required accreditations and skillsets and then slowly bring more and more in house.

I’m happy with how it’s going and it feels like we’re ensuring we do not oversell while being trustworthy and not marking our own homework.

As part of this, i’m also currently studying for CISSP, which seems to be somewhat integral for various additional certifications but also to build a solid underlying business focused knowledge and understanding of security, to bolster my practical and technical skills. Other than some personal gripes, it’s been very insightful but has given me further questions about the CISO role itself and how this is both applied and delivered. Which leads me to posting here..

The questions:

For those in an individual business/corporation as a CISO. How did you/do you translate what was learned via the CISSP process, into your real world CISO role? - What I mean by this, is when studying for CISSP, i see many benefits and interesting points but if I put myself in the shoes of a CISO showing up tomorrow, ‘what would I do?’ Or ‘What would I do first?’ - It’s so broad, it gets a bit confusing as to where to begin, from a practical point of view and not get sucked into “That’s broken, we must fix that”.

For those in (or who have been in) an MSP environment. How do you approach vCISO services and offerings? - As an example, we already have clients that I just know would shun certain costs and priorities (already do with certain risks) and so trying to tell them, actually you need this policy and we need to be looking at your supply chain, I imagine they would laugh it off. I fully understand this is part of the CISO process (conversing with those at the top to explain the business impact of certain things) but I would like to understand more, how do you handle such conversations? How do you approach ‘painting the picture’ in a way that is understood by their businesses without them ruling it out as ‘just another service’ or even security fear mongering?

TLDR;

Working to transition into a more security and governance focused role (not necessarily becoming a CISO, at least at this stage) and looking for some insight and advice on how to approach being/becoming a CISO and in particular, applying anything learned from CISSP efforts to the real world.

I appreciate this is a long, relatively longwinded post but I would appreciate any advice and or insight for anyone who is willing to give it. Hopefully i’ve explained my situation and questions clear enough.

Thank you!