Almost everyone writing about the CISO role treats it as the summit: how to reach the seat, how to survive it. Far fewer people talk about what comes after, and it matters, because the CISO job is unusually intense, carries real personal liability, and is one people leave, by choice or exhaustion, more often than the outside world assumes. I run security leadership at a large technology company and I watch peers move on from the seat constantly. This guide is the honest map of where they go, and how the ones who land well set it up years in advance.
What comes after being a CISO?
The paths after a CISO seat cluster into five: board and audit-committee roles, an advisory or fractional portfolio, a venture role such as operating partner or CISO-in-residence, founding a security company, or a larger operating seat like a converged CSO. A sixth, chosen more often than people admit, is stepping back deliberately after the burnout the role is known for, trading a second full-time seat for a lower-intensity advisory life. The best outcomes are built while you still hold the operating seat, not after you leave it.
The board path: the most sought-after second act
The role most exiting CISOs want, and the hardest to get, is the board seat. Demand is genuinely rising: SEC cyber-disclosure rules, ransomware in the headlines, and personal-liability cases have pushed boards to want a director who can read a security posture and ask the right questions. A sitting or former CISO is a natural fit.
The path is slower and more deliberate than most people expect. Public-company board seats almost never go to a first-time director; they go to people with a governance track record. So the realistic sequence is: start with private-company and startup advisory boards, take audit-committee exposure where you can get it, sit on a non-profit or association board to learn how boards actually operate, and build the network of directors and search firms that fill board seats. Crucially, this is built while you are still a CISO, using the board exposure the operating seat gives you. The CISO who waits until they have left the seat to think about board work has removed their strongest credential from the present tense.
The advisory and fractional portfolio
For many, the most attractive second act is not one job but a portfolio: a handful of advisory retainers, a fractional or interim CISO engagement or two, some board work, and the occasional expert or diligence project. It pays well, often comparably to a full-time seat once it is built, for a fraction of the intensity and with far more control over your calendar. The mechanics, the rates, and the trap of underpricing advisory work are covered in the fractional CISO guide; the short version is that the portfolio is the natural landing zone for a CISO who wants to stay in the game without the weight of the operating seat.
The portfolio also does not require a clean exit. Plenty of CISOs build the advisory side quietly while still employed, so that when they do leave, there is already a book of relationships to turn into engagements rather than a standing start.
Venture and the CISO-in-residence path
Security has become a large enough category that venture firms want operational security expertise on the inside. The roles vary: operating partner helping portfolio companies with security and helping the firm diligence security startups, CISO-in-residence, or advisor to specific investments. For a CISO who enjoys the pattern-matching across many companies that the role already involves, and who has built a reputation and a network, venture is a genuine and increasingly common path. It rewards the same asset the board path does: a name that other executives and founders already trust.
Founding, and the larger operating seat
Some CISOs have lived a problem long enough that they leave to build the product they wished existed, becoming a security founder. It is the highest-variance path and suits a specific personality; most CISOs are temperamentally risk managers, not risk takers, which is worth an honest look in the mirror before raising a round.
Others simply are not done operating, and move to a bigger version of the same job: a larger or more complex CISO seat, or a converged CSO role that adds physical security, investigations, and executive protection to the mandate. That expansion is a real career upgrade and is covered in the CISO vs CSO guide.
Retiring, or slowing down, on your terms
The path nobody markets but many take: stepping back. A decade or more in security leadership, with the stress and the liability, is genuinely enough for some people, and the ones who accumulated real equity in operating seats can afford to shift into a light portfolio of advisory and board work that pays for a few days a month. Full retirement is rarer than a deliberate downshift, but both are legitimate, and neither is failure. The role earns you the option; the equity determines whether you can take it.
The one thing that separates a good second act from a scramble
Every path above is built before you leave the seat, not after. The board network, the advisory relationships, the venture connections, the reputation that makes any of it possible: all of it compounds from the platform the operating seat gives you, and all of it is far harder to build once you have handed back the title. The CISOs who land the second act they want are the ones who treated the seat as a launchpad from the start, kept a live network outside their own company, and made a few deliberate deposits, an advisory board here, a conference talk there, before they needed the return.
If you are still climbing toward the first CISO seat, the same lesson runs in reverse: the how to become a CISO guide is the front half of this story. The seat is the middle of a career, not the end of one.