The library
All guides
Fully open, no paywall. Each guide is built from questions asked in real CISO loops. Read them in ship order or jump to the round you're preparing for.
Interview · 7 guides
The interview
- Interview
The Complete CISO Interview Guide (2026)
How the CISO interview loop actually works: every round, what each interviewer is testing, and the failure modes that kill technical candidates.
Last reviewed Jul 2026 - Interview
50 Real CISO Interview Questions (and What They're Actually Testing)
50 questions from live CISO interview loops, with annotations decoding what recruiters, CEOs, and boards are actually evaluating at each round.
Last reviewed Jul 2026 - Interview
CISO Case Study and Tabletop Interviews: How to Run the Room
CISO tabletop and case study interviews: the breach, budget cut, and M&A scenarios, what panels actually score, and how to run the room like an operator.
Last reviewed Jul 2026 - Interview
Questions You Should Ask in a CISO Interview (by Interviewer)
What to ask the CEO, CFO, GC, CTO, and board when interviewing for a CISO role, and how to read the answers before you take a scapegoat seat.
Last reviewed Jul 2026 - Interview
The CISO Panel Interview: CEO, CFO, GC, and Board Rounds Decoded
What the CEO, CFO, GC, CTO, and board actually test in a CISO panel day: real agendas, example questions, and how to stay consistent across rounds.
Last reviewed Jul 2026 - Interview
The CISO Interview Presentation: Acing the Strategy Round
How to win the CISO presentation round: what each prompt variant signals, the 10-slide arc, the 90-day one-pager play, and why Q&A is the real interview.
Last reviewed Jul 2026 - Interview
CISO References and the Back Channel: The Round You Don't Attend
How executive referencing and back-channel checks really decide a CISO hire: on-list vs off-list references, managing your own narrative, and the honesty rule.
Last reviewed Aug 2026
Board · 2 guides
The board
- Board
How to Present to the Board as a CISO (Deck Structure Included)
The CISO board presentation, slide by slide: what boards actually want, the deck structure that works, and how to ace the interview version.
Last reviewed Jul 2026 - Board
SEC Cyber Disclosure and Materiality: What a CISO Actually Owns
What the SEC cyber rules mean for CISOs: the four-day 8-K, the materiality judgment and who makes it, governance disclosure, and personal-liability exposure.
Last reviewed Aug 2026
First 90 days · 2 guides
The first 90 days
- First 90 days
The 90-Day CISO Plan: What Panels Expect and How to Build It
How to build a 90-day CISO plan that survives an interview panel and works after you sign: the three phases, 11 conversations, and failure modes.
Last reviewed Jul 2026 - First 90 days
The First 30 Days After Signing: Pre-Start Diligence for New CISOs
What to do between signing a CISO offer and day one: paper diligence, pre-start conversations, exit mechanics, and the logistics that bite later.
Last reviewed Jul 2026
Compensation · 3 guides
The offer and the money
- Compensation
CISO Compensation and Negotiation: The Offer Terms Nobody Warns You About
How to negotiate a CISO offer: equity by stage, D&O and indemnification, reporting line, budget commitments, and scapegoat-resistant severance.
Last reviewed Jul 2026 - Compensation
Red Flags in CISO Offers: How to Spot a Scapegoat Seat
How to spot a scapegoat CISO seat before you sign: red flags in the process, the role design, the offer paperwork, and how to walk away well.
Last reviewed Jul 2026 - Compensation
CISO Salary Guide: What Security Executives Actually Make
What CISOs actually make in 2026: base, bonus, equity by company stage, vertical premiums, and why salary surveys undershoot real total comp.
Last reviewed Jul 2026
Career path · 23 guides
The path to the seat
- Career path
First-Time CISO: Making the Director-to-CISO Jump
How to land your first CISO seat from a Director or Head of Security role: the real gap, board evidence, retained search, and realistic paths in.
Last reviewed Jul 2026 - Career path
The CISO Resume: What Search Firms and Panels Actually Read
How to write a CISO resume that survives the 30-second search-firm scan: scope numbers, outcome bullets, and the executive format that gets callbacks.
Last reviewed Aug 2026 - Career path
CISO Recruiters: How to Get on Executive Search Radars
How retained search actually works for CISO roles, which firms run security searches, and how to build recruiter relationships before you need them.
Last reviewed Aug 2026 - Career path
Fractional CISO and vCISO: Rates, Reality, and the Career Math
What fractional CISO work actually pays, who buys it, how to land the first client, and whether it helps or hurts a later run at the full-time seat.
Last reviewed Aug 2026 - Career path
VP of Security vs CISO: Titles, Scope, and Which to Take
How security-executive titles actually differ (officer status, board exposure, recruiter filters) and which title to take at your next jump.
Last reviewed Aug 2026 - Career path
How CISOs Actually Get Hired: Search Firms, Back Channels, and the Hidden Market
How CISO hiring really works: retained search firms, internal recruiters, back channels, and how to get on the radar before the seat opens.
Last reviewed Jul 2026 - Career path
The UK and EU CISO Market: NIS2, DORA, and How the Interviews Differ
How the UK and EU CISO market really works: NIS2 and DORA in interviews, UK salary ranges, interim day rates, and how European loops differ from US ones.
Last reviewed Aug 2026 - Career path
Deputy CISO and BISO Interviews: The Deliberate Stepping Stones
How deputy CISO and BISO roles really work, when each is the fastest path to a CISO seat, and how to interview and negotiate them as career steps.
Last reviewed Jul 2026 - Career path
How to Become a CISO in 2026: Realistic Paths and Timelines
The four realistic paths to a CISO seat, honest timelines, what recruiters actually probe, and what to do this year, from a sitting security executive.
Last reviewed Jul 2026 - Career path
CISO vs CSO: The Difference, and Which Seat to Take
What actually separates a CSO from a CISO, when converged security leadership is real, and how to decide which seat to take at your next move.
Last reviewed Aug 2026 - Career path
CISO vs CTO: How the Roles Differ and Where They Collide
What separates a CISO from a CTO in scope, reporting, and mandate, why security reporting into the CTO is contentious, and how the two actually work together.
Last reviewed Aug 2026 - Career path
CISO vs CIO: Difference, Reporting Line, and Tension
How the CISO and CIO roles differ in mandate and scope, why the CISO reporting to the CIO is contested, and how the two roles work together or clash.
Last reviewed Aug 2026 - Career path
What Comes After the CISO? Boards, Advisory, Second Acts
The real career paths after the CISO seat: board and audit-committee roles, advisory and fractional portfolios, venture, founding, and retiring on your terms.
Last reviewed Aug 2026 - Career path
CISO Certifications: Which Ones Actually Matter
The certifications that help a CISO career, the ones that are table stakes, and the honest truth that no certification gets you the seat: scope evidence does.
Last reviewed Aug 2026 - Career path
How to Hire a CISO: A Guide for CEOs and Boards
How to hire a CISO: when you actually need one, where to find real candidates, how to structure the role so strong ones say yes, and the mistakes that repel them.
Last reviewed Aug 2026 - Career path
CISO Job Description: A Template That Works
A CISO job description template for boards and CEOs: the scope, reporting line, and must-haves to include, plus the language that quietly repels strong candidates.
Last reviewed Aug 2026 - Career path
CISO vs DPO: The Difference and Why One Cannot Be the Other
How the CISO and Data Protection Officer roles differ, why GDPR makes combining them a conflict of interest, and how the two work together on privacy and risk.
Last reviewed Aug 2026 - Career path
CISO vs Security Architect: Roles, Scope, and Career Path
How the CISO and security architect roles differ in scope and seniority, why one is an executive and the other a technical expert, and how to move between them.
Last reviewed Aug 2026 - Career path
Director of Security vs CISO: The Real Difference
What actually separates a Director of Security from a CISO in scope, authority, and comp, whether the titles overlap, and how to make the jump between them.
Last reviewed Aug 2026 - Career path
When Does a Company Need a CISO?
The real triggers that mean a company needs a CISO, why headcount alone is the wrong signal, and when a fractional or Director-level hire is the smarter first move.
Last reviewed Aug 2026 - Career path
The APAC CISO Market: Singapore, Australia, and How Hiring Differs
How the APAC CISO market really works: Singapore and Australia salary ranges, MAS and APRA CPS 234 in interviews, and how the loops differ from US ones.
Last reviewed Aug 2026 - Career path
The India CISO Market: GCCs, RBI, CERT-In, and How Hiring Works
How the India CISO market really works: GCC vs domestic-enterprise seats, RBI and CERT-In in interviews, salary ranges in INR, and how the loops differ.
Last reviewed Aug 2026 - Career path
Managing Managers Across Multiple Layers: A CISO's Playbook
How to lead through multiple layers of management as a CISO: skip-levels, delegating outcomes, keeping signal across a growing security org, and developing managers.
Last reviewed Aug 2026
Verticals · 4 guides
By company type
- Verticals
CISO Interviews at AI Companies: What's Actually Different
What AI lab and AI startup CISO loops ask that nobody else does: model weight security, agentic runtime risk, org design, and equity-heavy comp.
Last reviewed Jul 2026 - Verticals
Startup CISO vs Enterprise CISO: How the Interviews Differ
How CISO interviews differ at startups, growth companies, and enterprises: who runs the loop, what they probe, comp structure, and stage-specific traps.
Last reviewed Jul 2026 - Verticals
Fintech CISO Interviews: The Regulatory Round
How fintech CISO interview loops really work: the regulatory rounds, fraud-security questions, partner bank dynamics, and comp patterns to expect.
Last reviewed Jul 2026 - Verticals
Healthcare CISO Interviews: HIPAA, Devices, and the Two Healthcares
Provider and healthtech CISO interviews are different jobs. Ransomware downtime, medical devices, HIPAA, HITRUST, comp, and red flags from a hiring exec.
Last reviewed Jul 2026
No guide matches that yet. Try a broader term, ortell us what you're preparing for.
Free template
Steal the 90-Day CISO Plan
The exact 90-day plan structure hiring panels expect: the single asset every CISO candidate gets asked for. Free, editable, yours in one click.