The First 12 Months as a CISO
Brett Price shares what security leaders should prioritize during their first year, from building executive relationships and understanding the business to identifying critical assets, quantifying risk, and delivering early wins.
Effective security leadership begins with understanding the business, earning organizational trust, and translating technical findings into measurable business impact.
Episode Chapters & Full Transcript
Select any chapter or transcript timestamp to begin watching from that exact point in the episode.
Full Transcript
Welcome to Conversations with CISOs, Security Leaders and Technology Executives, where we sit down with the leaders shaping cybersecurity and enterprise technology. Today I'm joined by Brett Price to discuss what security leaders should focus on during their first twelve months. Brett, thank you for joining me today. To get started, could you introduce yourself and tell us a little bit about your background and your current role?
Sure. My name is Brett Price. I've been in the business for about twenty-five years, maybe a little more. I started out swapping printers and fixing PCs, then gradually moved into systems administration, network administration, routers, and switches. I worked at a healthcare organization for about seven years, and routing and switching started to get a little redundant, so I decided to take on the security world. I got mostly into Cisco and earned a number of certifications, including the MCSE, CCNA, CCNP, and CCDA. I then worked for Verizon Enterprise Security Solutions for another seven years as a senior engineer, mostly working on Cisco firewalls and proxies, along with Check Point and a few other vendors. I was managing firewalls for large Fortune 50 organizations. After that, I moved into an advisory role at Verizon as a senior security advisor, again primarily working with Fortune 50 organizations. I did that for a couple of years and then moved to the vendor side, taking a role at Qualys as a technical account manager. I worked there for five and a half years and eventually became a regional vice president of sales. From there, I joined a cybersecurity consulting firm, where I built the vCISO program, NIST assessment program, and programs around CMMC and ISO. One of my engagements was serving as the virtual CISO for a global public company out of Charlotte, North Carolina. There was a lot of work around GDPR, ISO certification, Sarbanes-Oxley, and PCI. In January of this year, they hired me full time as their global CISO.
Excellent. Seeing as you just became the CISO this year, this question should be pertinent. What do you believe the first ninety days should look like as a CISO?
In the first ninety days, one of the most important things is starting to build relationships and understand the culture and leadership. A lot depends on where you sit in the hierarchy. Are you reporting to the CEO or the CIO? I report directly to the CEO. Regardless, building those relationships and understanding the culture is critical. At the same time, you're learning how the business operates, identifying the crown jewels, and assessing the risks around them. You're interviewing people about their part of the business and how they manage it. From there, you identify the most critical systems and data, meaning the things that would have the greatest impact on the business if they were shut down. Whether they're in the cloud or on-premises doesn't really matter. Then you identify the top risks and look for quick wins, especially obvious gaps in the security posture that you can mitigate or remediate within those first ninety days. You also want to document everything, including your top risks. When I say risk, I'm talking about what could have the greatest quantitative impact on the business. How much would it hurt the business if a critical system were taken offline? What would the reputational damage be? What would it cost to bring in a forensic investigation team? What could potential fines or litigation from lost data cost? Within those first ninety days, you should also start putting together an incident response plan. It doesn't have to be extremely detailed at first, but you need to understand who the key players are, including the CEO, CFO, chief legal counsel, and HR. You should also begin developing relationships with your local FBI cyber special agent and understand your reporting obligations in the event of an incident, whether that's to the Department of Homeland Security, the Department of Health and Human Services, or a data privacy authority in the UK for GDPR. Finally, start developing your metrics.
Got it. What would you say is the biggest mistake new security leaders make during their first year?
One of the biggest mistakes is not building relationships, and I emphasize this a lot. The worst thing for a CISO is pushback. If you don't understand the culture and haven't built the relationships, you're going to get negative responses to some of the things you're trying to accomplish. Another major issue is not being able to articulate technical findings in business language that the organization can understand. So I would say those are the two biggest mistakes.
You've talked a lot about building relationships within your first ninety days. What does a good relationship between a CISO and the rest of the executive team look like?
First, it's a mutual understanding. Second, it's being able to communicate in business terms. The CEO wants to build revenue and avoid risks related to the business, not necessarily think in terms of cybersecurity risks. If you can have business-focused conversations about cybersecurity, it helps a lot. You want to convey that you're there to improve processes, procedures, efficiency, and effectiveness in ways that can support revenue generation. Those are the better relationships.
As far as presenting risk in business terms and focusing on supporting the business's goals, what are some effective ways CISOs can communicate that?
I try to incorporate quantitative risk by building metrics. Obviously, you're going to have metrics around MTTR, MTTD, vulnerability management, and security awareness training, but really trying to quantify those top five risks and include them in those metrics helps. A lot of it is education, and often it takes baby steps. You have to pick and choose. If you're coming in as a first-time CISO or as the company's first CISO, chances are senior leaders aren't going to understand cybersecurity, and they certainly aren't going to understand the technical language. You need metrics that communicate the risk in a way they can understand.
Over the course of your first ninety days as a CISO, you're building relationships and learning how to communicate risk to business stakeholders. If you identify areas you want to change, at what point do you know you've earned enough trust to start driving bigger changes and getting executive buy-in?
It depends on the level of risk. Buy-in may take a long time. It may take a year to build the level of trust where you can say, “I have an issue here that I need to mitigate. I need this solution,” and get approval without a lot of explanation. But if it's a top risk, you have to communicate it in business terms. If the organization can't mitigate or remediate the issue, you need to make sure senior leadership completely understands the risk they're accepting and formally signs off on that risk.
When a CISO comes into a new organization, there are vulnerabilities, compliance requirements, technical debt, and strategic projects all competing for attention. As CISOs identify these different risks and scenarios that can impact the business, how do they determine what deserves focus first?
I would say exploitability. Threat intelligence has a lot to do with it, and I monitor threat intelligence every day. For instance, if a competitor has just been breached because a threat actor exploited a specific vulnerability, and you have that same vulnerability, it should be at the top of your list. The same applies to wide-open exposures. If you have an S3 bucket with public access, that's critical to address immediately. Prioritize based on that level of risk.
That makes sense. After your first year as a CISO, what outcomes would tell you that you've made meaningful progress in risk reduction?
Because we build metrics and a strategic plan, one measure is whether we've addressed some of those top risks, including exploitable issues and things like publicly accessible S3 buckets. Success is also reflected in your level of communication with the business. Is the business still open to communicating freely with you? Are you making progress with the CEO and executive leadership team? Are they more educated than they were before? Have you implemented a security awareness training program that the organization actually adopts without pushing back? Are people adhering to and accepting your policies? You can get a sense of how well the security program is being accepted through policy adherence, policy acceptance, security awareness training, reducing exploitable vulnerabilities, and helping the business adapt to things like artificial intelligence. Those are big wins.
After your first twelve months, if you look back and see that some of these areas aren't improving, perhaps security awareness training hasn't been widely adopted, vulnerabilities aren't being reduced at the rate you'd like, or you're having problems with AI adoption, what could CISOs change during their next twelve months to address those issues?
I was immediately going to say, “Get a new CISO,” but I think it comes down to communication. If those things aren't working, then you probably didn't start at the top and get executive leadership buy-in and support. There may be a gap in how you're presenting to the leadership team. You may be too technical or putting too much emphasis on the bigger picture instead of being specific. Changing how you present to executive leadership, communicate with the business, and interact with the organization is probably going to be key moving forward.
For our last question, and I think I know what your answer is probably going to be: if you could give a new security leader one piece of advice for their first year, what would it be?
Simplify the technical language. Learn to speak in business terms, and start adopting quantitative risk. I've been saying this for years: more and more CEOs and executive leaders are being held accountable for data breaches, so they're paying much closer attention to cybersecurity. With that, they're going to expect more. In the past, you could say, “This is a high-severity issue that needs to be mitigated,” and when they asked why, you could say, “Because I'm the CISO and I've been doing this a long time.” Nowadays, that doesn't fly. You have to explain what it means to the business and what the impact would be if the risk materialized.
Thank you very much. It sounds like every CISO in their first ninety days needs to focus on building relationships and quantifying risk. Thank you, everybody, for watching. If you enjoyed this conversation, be sure to like, subscribe, and leave a comment. Thanks again to Brett Price for joining us, and we'll see you in the next episode.
Thank you.
Conversations With CISOs, Security Leaders & Technology Executives
Hear practical conversations with the executives responsible for protecting complex organizations. Each episode explores leadership, risk management, infrastructure, incident response, governance, and the decisions security leaders make every day.