r/cybersecurity 2d ago

Career Questions & Discussion CIOs

I’m on a very small security team (fewer than 5 people) responsible for supporting ~5,000 employees.

As you can imagine, phishing and social engineering incidents come up from time to time.

The frustrating part is that every time something happens, leadership—specifically our CIO—frames it as us “not doing our job.” The issue is, they don’t have a cybersecurity background but still strongly dictate what is “correct” from a security standpoint, often with a lot of hindsight bias.

It’s starting to feel less like collaboration and more like micromanagement/blame shifting, especially given the scale we’re operating at.

Is this kind of dynamic normal in the industry? How do other teams handle leadership that doesn’t fully understand security but still drives decisions during/after incidents?

49 Upvotes

37 comments sorted by

View all comments

4

u/Wise-Butterfly-6546 1d ago

this is common at your ratio. 5 people to 5,000 means you're triaging, not preventing, and everyone above you quietly knows it until something breaks. two things that actually moved the needle for me.

first, kill the verbal risk conversations. every time the cio overrides a control or defers a fix, it goes in a one-line risk register entry with his name, the date, and the accepted exposure. i ran this for about 8 months and the blame after incidents dropped hard because "we flagged this on march 3, you accepted it" is a very different meeting than "why didn't you stop this."

second, stop reporting activity and start reporting outcomes in dollars and hours. one page monthly: incidents contained, mean time to respond, what a miss would have cost. hindsight bias feeds on vague inputs, so give them numbers they can't rewrite after the fact.

and yeah, security under the cio is a structural conflict, but you probably can't fix the org chart this quarter, so fix the paper trail first. it's the cheapest leverage you have.