* [![perspectives](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/02/prespective-icon.png)](https://www.paloaltonetworks.com/perspectives)
* The Keys to CISO Role Success---Part One: Entering a New Role

# The Keys to CISO Role Success---Part One: Entering a New Role

![The Keys to CISO Role Success—Part One: Entering a New Role](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2022/05/the-keys-to-ciso-role-success-part-one-entering-a-new-role.jpg)  
**By [Ed Harris](https://www.paloaltonetworks.com/perspectives/author/ed-harris/ "Posts by Ed Harris")** | **7 min read** |  
![share icon](https://paloaltonetworks.com/content/dam/pan/en_US/cxo-perspectives/images/cxo-share.svg)

* LinkedIn button ![linkedin-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-linkedin.svg)
* Twitter share button ![twitter-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-twitter-x-black.svg)
* \[Email share button ![email-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-email.svg)\](mailto:?subject=The Keys to CISO Role Success—Part One: Entering a New Role\&body=Check out this article https%3A%2F%2Fwww.paloaltonetworks.com%2Fperspectives%2Fthe-keys-to-ciso-role-success-part-one-entering-a-new-role%2F "Share in Email")
* ![copy-icon](https://www.paloaltonetworks.com/perspectives/wp-content/themes/csp2025/dist/images/icons/icon-share.svg)
  [](https://www.paloaltonetworks.com/perspectives/the-keys-to-ciso-role-success-part-one-entering-a-new-role/?pdf=download&lg=en&_wpnonce=9bd0cf6f31 "Click here to download") MEET THE AUTHOR  
  ![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2025/02/panw_master-twitter-profile-pic-400x400-1.png)  
  Ed Harris is Global Director of Information Security at Mauser Packaging and a fellow at the Institute for Critical Infrastructure Technology....

[Learn more](https://www.paloaltonetworks.com/perspectives/author/ed-harris/)

## IN THIS ARTICLE

A couple of years ago, there was a survey that tallied the average tenure for a chief information security officer (CISO) as only 26 months. That means many of us CISOs will have to hit the ground running more than once in our careers as we shift into new organizations and opportunities. It helps to have some keys to success. As a 30-year veteran of cybersecurity and a still-practicing, still-learning CISO, I have some guidance to share that has helped me over the decades, and it can support other CISOs too.

In this first article, I'll examine two keys to success when entering a new CISO role: Things you can do to make the most of your opportunity when entering a new role. In the [second part of this series](https://www.paloaltonetworks.com/cybersecurity-perspectives/the-keys-to-ciso-role-success-elevating-your-stature/?ts=markdown), I'll share two additional key factors that I've found to be invaluable in elevating the CISO role---extending well beyond that 26-month window.

Together, the two articles provide guidance to achieving greater visibility for the security function and engendering support from both the C-suite and the board. They're designed to put the job of today's CISO in perspective, and make the work more interesting, more fulfilling, and, hopefully, more fun.

## My Guidance for Brand New CISOs

The skills that helped you climb the ranks to become a CISO have clearly done well for you along the way. In today's world, the path to CISO can start in many places. For me, it was IT. For many others, it is in the cybersecurity department. But, over the past few years, we've also seen CISOs come from diverse areas such as the business side or auditing.

Whatever your background, the reality is that being a CISO is probably unlike any other job you've had before. The knowledge and skills that got you to this point are not necessarily the knowledge and skills that will make you a successful CISO. So, one of my main points is to learn to be comfortable with being somebody you are not---at least not yet.

It requires a shift in mindset. Most people thrust into the CISO role probably have a strong knowledge of cybersecurity technology, or perhaps specialized knowledge in other areas, such as enterprise IT, regulatory compliance or auditing. The point is, once you become a CISO, your responsibilities are instantly broader and more diverse. You can't be the one testing the latest cybersecurity point products or writing audit reports. You must be a leader, mentor, teacher, motivator. You must learn to speak the language of business. You must inspire trust and respect, not just among your team, but throughout the entire organization.

## The Keys to Succeeding in a New CISO Role

### Key \#1: Hire Smart People

My first bit of practical advice when entering any new CISO role is simple: Hire people that are smarter than yourself. There's a famous quote from Steve Jobs: *"It doesn't make sense to hire smart people and tell them what to do. We hire smart people so they can tell us what to do."*

A common pitfall among new managers, CISOs included, is to think that hiring smarter people means that those people are going to gun for their jobs. The reality is just the opposite: Hiring smart people and giving them the leeway to do their jobs well will benefit the company and benefit you as a leader.

One of the factors I consider when I look for smart people to hire is whether the person has the mentality of a teacher. There is a tremendous value in hiring someone with a teacher mindset. They can be mentors to others on your team. They take pleasure in watching the light bulb go off in other people.

Two of the other qualities I look for: Passion and heart. For example, if someone is just out of college, I will ask about extracurricular activities. Were they involved in the cyber club at school? Were they president of the cyber club? Did they teach cyber safety at a local elementary school? How can the person show me they have the passion and heart for cyber? After all, this job is too challenging not to love cybersecurity and have deep curiosity for the field. Spending time eating, sleeping, and breathing cyber is a great early indicator of future success.

I also consider practical knowledge. I'm one of those people that love certifications. It shows that an independent third-party has evaluated and validated the skills and knowledge of that person. It's part of the dialogue in an interview. You can often hear in their language, or see in their body language, whether they truly understand the work. So those kinds of validations should hold weight when considering candidates. I also understand that there are leaders who do not like certifications. I get it. Not everyone tests well. And the converse is that some can read the material and pass any test (lacking practical application of the knowledge). There will always be the outliers. Whether you like certifications or not, understanding a candidate's practical knowledge is necessary in helping a CISO build a successful team.

### Key \#2: Create Visibility Everywhere

When it comes to the role of the CISO, there are different types of visibility to consider. First, is the visibility across the organization into potential gaps or weaknesses in cybersecurity protection.

For example, most companies use Office 365 to handle email. Depending on the size of the organization, just this one application alone could be generating millions of logs each day. How do you parse through this with the visibility to determine what are the highest priority threats, the ones that require immediate action? Perhaps you need to work with a managed services provider for your Security Operations Center (SOC) or create other new processes to ease the burden for threat hunting and analysis on your teams. Perhaps the technologies and processes you incorporate for an app such as Office 365 can be extended across all of your enterprise applications.

Creating visibility is a perpetual action that every CISO needs to be involved in. When COVID hit, we had to support workers at home. We needed visibility, so we hired a third-party provider with an application that puts an agent on all of our endpoints. It doesn't matter if the user is at home, in an office, or at a coffee shop. That little agent creates visibility for our organization, reporting everything to the SOC in near real time.

Beyond the visibility into your cybersecurity risk environment, there is also the need for CISOs to create visibility about their role and how their cybersecurity teams and investments are protecting the organization. For example, in the event of a geopolitical crisis, the CISO must be in a position to communicate the level of threats to business leaders and to provide details on how threats are being continuously monitored and assessed.

As CISOs, we have to create a certain level of awareness of what we do and how we are doing it. That means building relationships with your executive team and peers across the organization and using those connections to create new clarity around security needs and solutions.

## What's Next to Succeed as a CISO?

What else can you do as a CISO to succeed in your role and make the job more fun and fulfilling? Check out the second article in this series [***The Keys to CISO Role Success ---Part Two: Elevating Your Stature***](https://www.paloaltonetworks.com/cybersecurity-perspectives/the-keys-to-ciso-role-success-elevating-your-stature/?ts=markdown) for guidance on two more important actions you can take to make the most of our challenging and rewarding security profession.

*** ** * ** ***

*Ed Harris is Global Director of Information Security at Mauser Packaging and a fellow at the Institute for Critical Infrastructure Technology.*

* [Cyber as a Boardroom Topic](https://www.paloaltonetworks.com/perspectives/all-articles/?cat=cyber-as-a-boardroom-topic)

## Related Content

![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/03/AdobeStock_704394220-16x7-1-scaled.png) BLOG

### AI

**Is Your Enterprise Architecture Ready for the Agentic Workforce?**

Exploring autonomous, agent-to-agent risk: Why your security needs governed...

[Anand Oswal](https://www.paloaltonetworks.com/perspectives/author/anand-oswal/ "Posts by Anand Oswal")
[](https://www.paloaltonetworks.com/perspectives/is-your-enterprise-architecture-ready-for-the-agentic-workforce/)  
![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/02/New-Economics-of-Cyber-Resilience-featured.jpg) BLOG

### AI

**From Insurance Policy to Growth Engine: The New Economics of Cyber Resilience**

Security is not a shield. It is a sensor for business velocity....

[Ben Hasskamp](https://www.paloaltonetworks.com/perspectives/author/ben-hasskamp/ "Posts by Ben Hasskamp")
[](https://www.paloaltonetworks.com/perspectives/from-insurance-policy-to-growth-engine-the-new-economics-of-cyber-resilience/)  
![](https://www.paloaltonetworks.com/perspectives/wp-content/uploads/2026/01/CEO-Doppelgangers-featured.jpg) BLOG

### AI

**CEO Doppelgängers: When Identity Becomes the New Attack Surface**

Explore why authenticity is the new currency of trust....

[Amy Blackshaw](https://www.paloaltonetworks.com/perspectives/author/amy-blackshaw/ "Posts by Amy Blackshaw")
[](https://www.paloaltonetworks.com/perspectives/ceo-doppelgangers-when-identity-becomes-the-new-attack-surface/)  
STAY CONNECTED

## Connect with our team today

Job Level  
Sign me up to receive news, product updates, sales outreach, event information and special offers about Palo Alto Networks and its partners.  
By submitting this form, I understand my personal data will be processed in accordance with Palo Alto Networks [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) and [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown).  
This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.
Reach out  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense?ts=markdown)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses?ts=markdown)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy?ts=markdown)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence?ts=markdown)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond?ts=markdown)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown)

* [Customers](https://www.paloaltonetworks.com/customers?ts=markdown)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown)

* [Communities](https://www.paloaltonetworks.com/communities?ts=markdown)

* [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications?ts=markdown)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown)

* [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown)

* [Documents](https://www.paloaltonetworks.com/legal?ts=markdown)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language
