The following is a guest article by Phillip Lee, cybersecurity advisor at Reisender. The views expressed in this article are solely those of the author.

Security leaders are actively seeking seats in the C-suite to help organizations better address strategic threats and keep pace with increasingly stringent regulatory requirements—demands that are pushing security expertise and reporting capabilities to the board level. This pursuit is entirely reasonable.

However, introducing a new role into the executive team is a significant move that requires careful consideration of business needs, role definition, and candidate fit. The following guide is designed to help CFOs and boards determine whether your Chief Information Security Officer (CISO) is ready for the C-suite and boardroom, while also helping you identify and support areas where security leaders need to grow.

Phillip Lee, cybersecurity advisor at Reisender
Phillip Lee
Image used with permission from Phillip Lee

I have witnessed security leaders fail in executive communications by being either too technical or too philosophical, and I have also seen security professionals without C-suite titles excel in similar conversations. The following assessment factors can help you determine whether your CISO has the capability to justify when and how to bring the security leader into the C-suite—a step you should indeed take.

Ensure your CISO possesses the following:

Executive presence.This is the most obvious trait and the easiest for other board members to notice, so I will not dwell on it here, but it must be considered alongside the other factors in this article. The leadership development path for CISOs differs from that of typical C-suite members, so you should focus on providing development opportunities for emerging security leaders within your organization to cultivate executive presence.

One key indicator of whether a security leader already possesses or can develop appropriate executive presence is observing their relationships within the organization, beyond security and IT. A CISO who values cross-functional relationships and understands business operations is more likely to contribute to overall business goals.

Appropriate level of technical skills.The degree of technical security skill a CISO should possess is one of the most hotly debated topics in the cybersecurity community. In reality, the CISO's technical proficiency should match the demands of the role, and this need varies greatly depending on the type of company—whether it is a technology company or in a non-technology industry.

What you should truly focus on regarding technical skills is: Can the CISO translate technical risks, vulnerabilities, and requirements into a context that non-security leaders can understand? This is often an area where leaders with technical backgrounds struggle, but the ability to translate such topics for the executive level can be developed.

Appropriate level of GRC skills.Governance, risk management, and compliance (GRC) are typically core areas of focus for CISOs, even when these functions are shared with departments such as legal, compliance, and operations. Your security leadership should be able to connect security risks and compliance needs with business risks and value drivers.

Your CISO should be able to drive alignment between security GRC activities and business risk management activities such as enterprise risk management. If a leader resists this alignment, it will be difficult to build the right relationships and connections at the executive level, because security programs work best when integrated with other operational processes.

Reporting skills.Presenting information with the appropriate level of detail, format, and delivery is a fundamental requirement for a CISO to effectively participate in executive meetings. Leaders who value this capability take the time to communicate with other leaders in the organization and align on materials before presenting to senior management. Observing how a CISO handles review and feedback in meetings can help gauge their attitude when difficult decisions must be discussed with senior leadership.

Evaluating a CISO should involve multiple executives, including operations and legal leaders, so they can provide valuable feedback on the security leader's performance. A CISO prepared for a leadership role will establish a reporting cadence across the business to enhance alignment between security and other departments.

Financial and budget acumen.Many CISOs and security leaders are accustomed to creating budgets and requesting funding on an ad hoc basis. This does not mean they lack the necessary skills, but it may mean they need coaching to align their approach with finance department norms. A security leader who can align cybersecurity needs and risks with the correct financial standards will be more effective in board and budget discussions.

Look for leaders who quantify risks in financial terms whenever possible, adjust budgets according to the organization's financial situation, and present budget information in metric- or risk-related formats.

Bridge builders.Many of the points above point to bridge-building capability. This is a key skill for CISOs at the C-suite and board level. Some security leaders achieve goals by spreading fear and malicious threats, which often fails to build trust and credibility with executives.

Look for CISOs who regularly meet with you, your peers, and core business units, and who incorporate those perspectives into security programs. A recent example: When your CISO approached the adoption of artificial intelligence within the organization, did they take a collaborative approach and seek business input, or did they adopt a rigid, uncooperative stance?

The importance of the right team

Deciding how and when to give a CISO an executive seat is not just an assessment of their individual performance, but also an assessment of the team they have built. A security leader who is ready to report to the board and serve as part of the organization's leadership team must have a team capable of supporting them in that role.

Look for a versatile security team whose members demonstrate some of the traits you expect from the CISO. Also, observe whether the CISO coaches the team and gives members opportunities to hone the skills needed to support the organization.

Excellent CISOs invest time in developing their team and use them as amplifiers in executive and board reporting. If a leader allows rising stars on the team to present on relevant topics or supplement knowledge, this is a positive signal that your security leader can deliver value at the executive level.

The factors above may seem straightforward, but your leadership team should carefully consider them when deciding the role cybersecurity plays in the corporate structure. Please refer to the metrics and standards you use for other executives entering the C-suite and incorporate them into your evaluation of the CISO.

The skills mentioned here can be developed internally or acquired through external hiring; your cybersecurity leader does not need to possess all of them. However, if you intend to bring your top security leader into the C-suite, these skills should exist within that leader's team.