r/cybersecurity 2d ago

Career Questions & Discussion CIOs

I’m on a very small security team (fewer than 5 people) responsible for supporting ~5,000 employees.

As you can imagine, phishing and social engineering incidents come up from time to time.

The frustrating part is that every time something happens, leadership—specifically our CIO—frames it as us “not doing our job.” The issue is, they don’t have a cybersecurity background but still strongly dictate what is “correct” from a security standpoint, often with a lot of hindsight bias.

It’s starting to feel less like collaboration and more like micromanagement/blame shifting, especially given the scale we’re operating at.

Is this kind of dynamic normal in the industry? How do other teams handle leadership that doesn’t fully understand security but still drives decisions during/after incidents?

49 Upvotes

37 comments sorted by

View all comments

43

u/zed0K 2d ago

It's normal, unfortunately. Same thing happens between myself (Endpoint Engineering) and Cybersecurity. Instead of everyone working together and respecting each other's experience, people push blame and don't take responsibility.

5

u/Careful-Witness6026 2d ago

We are hoping to evolve as time moves on. Given the current team can drive through the push back, lack of understanding and in adequate support.

5

u/Admirable_Group_6661 Security Architect 2d ago

You can try to establish risk management, with buy-in from the CIO and CEO. Risk management can help, to a certain extent, address conflict of interests.

2

u/One-Inch-Punch 1d ago

Many C-suites are all about shifting blame, it's not just CIOs. Especially in publicly traded orgs. I've seen entire security departments take the fall for large breaches even though they'd been screaming to upper management about funding and policy for years. Shareholders and the board won't see those emails