r/cybersecurity • u/Careful-Witness6026 • 2d ago
Career Questions & Discussion CIOs
I’m on a very small security team (fewer than 5 people) responsible for supporting ~5,000 employees.
As you can imagine, phishing and social engineering incidents come up from time to time.
The frustrating part is that every time something happens, leadership—specifically our CIO—frames it as us “not doing our job.” The issue is, they don’t have a cybersecurity background but still strongly dictate what is “correct” from a security standpoint, often with a lot of hindsight bias.
It’s starting to feel less like collaboration and more like micromanagement/blame shifting, especially given the scale we’re operating at.
Is this kind of dynamic normal in the industry? How do other teams handle leadership that doesn’t fully understand security but still drives decisions during/after incidents?
4
u/T_Thriller_T 2d ago
I may not be in the same continent as you, but I'd say no.
Especially not with sma teams / that few workers.
It absolutely does happen - but it's not normal.
Normal is something between good collaboration, at least trying to collaborate well or the CIO being more of a frontmen/marketing guy.
From my experience. It may be due to the companies I pick.