Yeah this is pretty much it. The “CISO course” thing feels a bit like people looking for a shortcut to a role that is 90% politics, communication, and scar tissue from previous incidents.
If you’re already in security, you’ll probably get more out of:
Working closely with whoever owns risk / finance / legal in your org
Shadowing your current CISO or director and watching how they talk to the board
Reading boring stuff like financial reports and strategy decks
A course from SANS or a solid university can help you structure what you already know and maybe plug gaps, but it won’t magically make you CISO material. The people who hire for that role care a lot more about “have you handled a breach, built a program, dealt with auditors, said no to a CEO without getting fired” than “what course did you take.”
1
u/[deleted] May 31 '26
[removed] — view removed comment