Career path

What Comes After the CISO? Boards, Advisory, Second Acts

The real career paths after the CISO seat: board and audit-committee roles, advisory and fractional portfolios, venture, founding, and retiring on your terms.

Last reviewed August 2, 2026 · 4 min read · Free, no paywall

Almost everyone writing about the CISO role treats it as the summit: how to reach the seat, how to survive it. Far fewer people talk about what comes after, and it matters, because the CISO job is unusually intense, carries real personal liability, and is one people leave, by choice or exhaustion, more often than the outside world assumes. I run security leadership at a large technology company and I watch peers move on from the seat constantly. This guide is the honest map of where they go, and how the ones who land well set it up years in advance.

What comes after being a CISO?

The paths after a CISO seat cluster into five: board and audit-committee roles, an advisory or fractional portfolio, a venture role such as operating partner or CISO-in-residence, founding a security company, or a larger operating seat like a converged CSO. A sixth, chosen more often than people admit, is stepping back deliberately after the burnout the role is known for, trading a second full-time seat for a lower-intensity advisory life. The best outcomes are built while you still hold the operating seat, not after you leave it.

The board path: the most sought-after second act

The role most exiting CISOs want, and the hardest to get, is the board seat. Demand is genuinely rising: SEC cyber-disclosure rules, ransomware in the headlines, and personal-liability cases have pushed boards to want a director who can read a security posture and ask the right questions. A sitting or former CISO is a natural fit.

The path is slower and more deliberate than most people expect. Public-company board seats almost never go to a first-time director; they go to people with a governance track record. So the realistic sequence is: start with private-company and startup advisory boards, take audit-committee exposure where you can get it, sit on a non-profit or association board to learn how boards actually operate, and build the network of directors and search firms that fill board seats. Crucially, this is built while you are still a CISO, using the board exposure the operating seat gives you. The CISO who waits until they have left the seat to think about board work has removed their strongest credential from the present tense.

The advisory and fractional portfolio

For many, the most attractive second act is not one job but a portfolio: a handful of advisory retainers, a fractional or interim CISO engagement or two, some board work, and the occasional expert or diligence project. It pays well, often comparably to a full-time seat once it is built, for a fraction of the intensity and with far more control over your calendar. The mechanics, the rates, and the trap of underpricing advisory work are covered in the fractional CISO guide; the short version is that the portfolio is the natural landing zone for a CISO who wants to stay in the game without the weight of the operating seat.

The portfolio also does not require a clean exit. Plenty of CISOs build the advisory side quietly while still employed, so that when they do leave, there is already a book of relationships to turn into engagements rather than a standing start.

Venture and the CISO-in-residence path

Security has become a large enough category that venture firms want operational security expertise on the inside. The roles vary: operating partner helping portfolio companies with security and helping the firm diligence security startups, CISO-in-residence, or advisor to specific investments. For a CISO who enjoys the pattern-matching across many companies that the role already involves, and who has built a reputation and a network, venture is a genuine and increasingly common path. It rewards the same asset the board path does: a name that other executives and founders already trust.

Founding, and the larger operating seat

Some CISOs have lived a problem long enough that they leave to build the product they wished existed, becoming a security founder. It is the highest-variance path and suits a specific personality; most CISOs are temperamentally risk managers, not risk takers, which is worth an honest look in the mirror before raising a round.

Others simply are not done operating, and move to a bigger version of the same job: a larger or more complex CISO seat, or a converged CSO role that adds physical security, investigations, and executive protection to the mandate. That expansion is a real career upgrade and is covered in the CISO vs CSO guide.

Retiring, or slowing down, on your terms

The path nobody markets but many take: stepping back. A decade or more in security leadership, with the stress and the liability, is genuinely enough for some people, and the ones who accumulated real equity in operating seats can afford to shift into a light portfolio of advisory and board work that pays for a few days a month. Full retirement is rarer than a deliberate downshift, but both are legitimate, and neither is failure. The role earns you the option; the equity determines whether you can take it.

The one thing that separates a good second act from a scramble

Every path above is built before you leave the seat, not after. The board network, the advisory relationships, the venture connections, the reputation that makes any of it possible: all of it compounds from the platform the operating seat gives you, and all of it is far harder to build once you have handed back the title. The CISOs who land the second act they want are the ones who treated the seat as a launchpad from the start, kept a live network outside their own company, and made a few deliberate deposits, an advisory board here, a conference talk there, before they needed the return.

If you are still climbing toward the first CISO seat, the same lesson runs in reverse: the how to become a CISO guide is the front half of this story. The seat is the middle of a career, not the end of one.

Frequently asked

What do CISOs do after being a CISO?

The common paths are board and audit-committee seats, advisory or fractional portfolios, venture roles such as operating partner or CISO-in-residence, founding a security company, or moving to a larger or converged security-executive seat. A meaningful number also step back deliberately after the burnout that the role is known for, taking a lower-intensity advisory life rather than another full-time seat.

Can a CISO become a board member?

Yes, and demand is rising because SEC disclosure rules and cyber risk have pushed boards to want a security-literate director. The realistic path is starting with private-company and advisory boards, audit-committee work, and non-profit boards to build governance experience, then moving toward public-company seats. It usually takes years and is built while you still hold the operating seat, not after.

Do CISOs retire early?

Some do, and the role's intensity and personal-liability exposure are a real reason. After a decade-plus in high-stress security leadership, many CISOs shift to a portfolio of advisory and board work that pays well for far fewer hours, rather than fully retiring. Whether that is financially possible depends heavily on the equity they accumulated in operating seats.

Is being a CISO a good long-term career?

It can be, if you treat the seat as a platform rather than a destination. The role builds board exposure, executive network, and risk judgment that convert into advisory, board, and venture opportunities that outlast any single job. The risk is burning out in the seat without building those next-step assets, which is why the strongest CISOs start planning the second act while still in the first.

Free template

Steal the 90-Day CISO Plan

The exact 90-day plan structure hiring panels expect: the single asset every CISO candidate gets asked for. Free, editable, yours in one click.

Instant access, no confirmation hoops. Occasional emails on landing the seat; unsubscribe anytime.