Do you have any tips for new CISOs struggling to navigate corporate politics? What has helped you develop this skill yourself?

308 views3 Comments
Sort By:
Oldest
CISO in Softwarea month ago
The book: The Art of Influence
1
CISO in Manufacturinga month ago
A mentor who knows the company thoroughly and is well connected internally
1
lock icon

Please join or sign in to view more content.

By joining the Peer Community, you'll get:

  • Peer Discussions and Polls
  • One-Minute Insights
  • Connect with like-minded individuals
CISO in Energy and Utilities9 days ago
There's a significant gap in university education regarding corporate politics. People often enter companies unaware of the existing culture and politics, whether good or bad, yet understanding and navigating this landscape is crucial. While technical skills are important, the ability to maneuver through corporate politics and build strong relationships defines a successful CISO.

One of my first commercial CISO roles was in Paris, where I started as the sole security professional in a company of 100,000 people spread across 70 countries. My experience with the military and NATO had given me some pre-training in politics, but I was fortunate to have an assistant who had been with the company for 30 years. She candidly told me, "I will show you and tell you things you won't believe. If you listen to me, you'll survive. If you don't, you won't last six months." I took her advice to heart and not only survived but thrived for five years, leaving only when I was ready for the next challenge.

Corporate politics play a huge role, whether we like to admit it or not. But there's a way to engage in politics ethically. Understand the game's rules and operate within the moral boundaries of what is right. Building alliances and maintaining open lines of communication are essential. Every time I join a new company, I find that the security team is often perceived as a black box. To counter this, I make it a point to over-communicate and be transparent. This approach builds trust, which is the bedrock of a CISO's role.

1

Content you might like

Director of IT in IT Services4 days ago
Implementation of Zero trust architecture, its modules across the organisation is a priority for us. So, we will be implementing zero trust strategies in IAM, inline with overall strategy.
1.4k views1 Comment

Implementation complete23%

Implementation in progress54%

Planned within the next 12 months12%

Not planned7%

Not enabling O365 on mobile2%

View Results
2.4k views2 Upvotes

Account deletion19%

Personal data (PII) deletion from a company's own data warehouses.55%

Personal data (PII) deletion from both a company's own data warehouses and connected SaaS tools.18%

Account deletion and PII deletion from both a company's own data warehouses and connected SaaS tools.7%

View Results
1.5k views2 Upvotes