Career path

Managing Managers Across Multiple Layers: A CISO's Playbook

How to lead through multiple layers of management as a CISO: skip-levels, delegating outcomes, keeping signal across a growing security org, and developing managers.

Last reviewed August 8, 2026 · 7 min read · Free, no paywall

The hardest transition in a security-leadership career is not moving from engineer to manager. It is moving from managing people who do the work to managing people who manage the people who do the work. I sit on the hiring side of security-leadership searches, and this is the specific competence that separates a Director who plateaus from one who becomes a CISO who can actually run an organization: the ability to lead through two, three, or four layers without either drowning in detail or losing the plot entirely. This guide is the operating playbook for that layer of leadership.

How do you manage managers across multiple layers?

You manage managers by giving up direct control of the work and taking on responsibility for the system that produces it. Instead of assigning tasks, you set context and outcomes and hold your direct managers accountable for delivering through their own teams. The four moves that make it work are a clear charter and measurable outcomes for each manager, consistent skip-level conversations that surface what is really happening two layers down, a standardized operating rhythm so information does not distort as it travels, and deliberate time spent developing your managers into leaders. Your value stops being that you are the best operator and becomes that you built a system of leaders who do not need you in the room.

The first shift: from work to outcomes

When you manage individual contributors, you can see the work. When you manage managers, you cannot, and trying to is the single most common failure mode. The instinct that made you successful, being the person with the sharpest technical judgment and the fastest hands, becomes a liability, because there is no longer enough of you to go around and every hour you spend doing the work is an hour you are not spending building the people who should be doing it.

The replacement discipline is managing to outcomes. Every manager who reports to you should have a charter that answers three questions without you: what this function is accountable for, what good looks like this quarter in measurable terms, and where its authority begins and ends. If you find yourself telling a manager how to do something rather than what outcome you need and by when, you have quietly reabsorbed their job. The test is simple: if you went dark for two weeks, would the org keep producing the right things? If the honest answer is no, you are still operating, not leading.

The information problem, and why it is the real job

Here is the mechanic nobody explains before you live it. Every layer between you and the work is a lossy channel. A concern that is obvious on the ground becomes a caveat by the time it reaches the team lead, a footnote by the time it reaches the Director, and nothing by the time it reaches you, because at each hop the person relaying it is human and has an incentive to round the news toward fine. By the time a problem two layers down is bad enough to surface on its own, it is usually a crisis rather than a course correction.

Most of what follows is really about defeating that distortion. You cannot fix it by demanding more status, because status is exactly the channel that is lossy. You fix it by building parallel paths for signal to reach you undistorted: direct conversations with people below your reports, instrumented metrics that do not care about anyone’s feelings, and retrospectives that examine what actually happened rather than what was planned.

Skip-levels: your highest-bandwidth sensor

A skip-level is a conversation with someone below your direct reports, without their manager present. Done well, it is the best instrument you have for sensing the true health of the organization. Done badly, it is a fast way to destroy the trust of the managers you depend on.

The rules that keep it useful:

  • Cadence over intensity. A predictable rhythm, a rolling set of 1:1s or small-group sessions so that over a quarter you have heard directly from most of the org, beats an occasional dramatic town hall. People tell you real things when the format is routine.
  • Listen, do not evaluate. Frame it as understanding obstacles and how decisions land from the ground, not as checking up. Ask what is slowing them down, what they would change about how the team works, and what they wish leadership understood. Avoid status; status is what the org rhythm is for.
  • Never relitigate in the room. If someone raises a decision their manager made, do not overrule it on the spot. That teaches everyone that the way to win an argument is to go around their boss to you, which destroys your managers’ authority and trains the org to route around them.
  • Close the loop as coaching. Aggregate themes across many skip-levels and feed them back to your managers as development, not as an accusation sourced from one person. The point is to make your managers better, not to run the org over their heads.

The failure mode to watch in yourself is using skip-levels to satisfy your own itch to still be close to the work. That is about you, not the org, and people feel the difference. For the first-time version of this transition, the first-time CISO guide covers the mindset shift from operator to leader in more depth.

Standardize the operating rhythm so signal survives

Managers left to their own devices will each invent a different way of running staff meetings, tracking work, and reporting up. That variance is what makes the information problem worse, because you cannot compare two teams whose managers measure and report entirely differently. A light, shared operating rhythm is the fix, and it is not bureaucracy if you keep it small.

The elements worth standardizing across layers:

  • A small, consistent metric set per function with a few leading indicators, the ones that move before outcomes do, and a few lagging ones. In a security org this differs by function: mean time to detect and respond for the SOC, control coverage and audit findings for GRC, escaped-defect and remediation-latency trends for AppSec, provisioning and access-review timeliness for identity. Read the exceptions, not the averages; the average hides the team that is quietly on fire.
  • A roughly common staff-meeting format so a Director’s staff meeting and a lead’s staff meeting rhyme. This lets you drop into any level and orient in minutes, and it lets managers move between teams without relearning everything.
  • A shared planning and review cadence so priorities set at your level actually propagate down and evidence of progress actually propagates up, on the same clock. The 90-day plan framework is a useful spine for setting that cadence when you inherit or build an org.

The goal of all this is not control. It is a nervous system, a way for the organization to feel pain early and locally rather than late and everywhere.

Develop managers, or you will manage forever

If you do not actively build your managers into better leaders, you will spend the rest of your tenure compensating for their gaps yourself, and you will cap the size of org you can run at the size you can personally hold in your head. Developing managers is not a soft nicety; it is the load-bearing activity of multi-layer leadership.

Concretely, that means coaching your managers on the same transition you went through, from doing to leading, because most of them are earlier in it than you are. It means delegating genuinely hard, visible problems to them and letting them own the outcome, including the risk of a public stumble, rather than only handing down safe work. It means calibrating your managers against each other so that a strong rating from one means roughly what it means from another, which keeps promotions and performance fair across the org and keeps your best people from leaving over perceived inequity. And it means being explicit about which decisions are theirs, which are yours, and which are theirs to make but yours to be informed of, so that authority is clear and nobody is either paralyzed or freelancing.

When to add a layer, and when not to

Layers are not free. Each one you add is another hop of information loss and another degree of separation between you and reality. Add a layer when your direct managers can no longer give their own teams enough attention to lead them well, which usually shows up as decisions backing up, people feeling unmanaged, or your directs working as senior individual contributors instead of leaders. A common guideline is five to eight reports for a front-line manager and somewhat fewer for a leader of managers, because managing through people costs more attention than managing the work directly.

Do not add a layer simply because headcount grew, and be willing to remove one when a reorg has left a manager with two reports and a title. In a security org, the shape usually evolves from a flat team of leads, to functional groups such as SOC, GRC, AppSec, and identity each with a manager, to those managers reporting through Directors as the org crosses roughly thirty to fifty people. The Director of Security versus CISO guide is useful for thinking about where accountability really sits as those layers form.

The mindset that ties it together

The through-line of managing across layers is a hard psychological trade. You give up the direct, legible satisfaction of solving the problem yourself, and you accept the indirect, deferred, and sometimes invisible satisfaction of having built a group of people who solve it better than you would have, at a scale you never could alone. Leaders who cannot make that trade stay brilliant Directors of small teams. Leaders who make it become the kind of CISO a board trusts with a real organization, and eventually the kind of leader whose second act, covered in the what comes after the CISO guide, is built on exactly this ability to develop other leaders. The work is no longer the work. The people who do the work are the work.

Frequently asked

How do you manage managers across multiple layers?

You manage managers by shifting from directing work to setting context and outcomes, then holding your direct managers accountable for delivering through their own teams. The core moves are: give each manager a clear charter and measurable outcomes rather than tasks, run consistent skip-level conversations to hear what is really happening two layers down without going around your managers, standardize the operating rhythm (metrics, staff meetings, planning) so information does not distort as it travels, and spend real time developing your managers as leaders. Your job stops being the best operator in the room and becomes building a system of leaders who do not need you in the room.

What is a skip-level meeting and how should a CISO run one?

A skip-level meeting is a conversation with someone one or more layers below your direct reports, without their manager present, so you can sense the health of the org directly. Run them on a predictable cadence, frame them as listening rather than evaluation, ask about obstacles and how decisions feel from the ground rather than status, and never use them to relitigate a manager's decisions in the moment. Close the loop by feeding themes back to your managers as coaching, not by acting unilaterally on one person's account, which would undermine the manager you are trying to develop.

How does a CISO keep visibility without micromanaging?

Replace direct observation with instrumented signal and trusted rituals. Define a small set of leading and lagging metrics per function, review them on a fixed cadence, and read the exceptions rather than the averages. Combine that with skip-levels, incident and project retrospectives, and roughly consistent staff-meeting formats across teams so you can compare like with like. The goal is to detect drift two layers down early through patterns, not to inspect individual tasks, which erodes the managers you rely on and does not scale past one or two teams.

What is the right span of control for a CISO's security org?

There is no single number, but a common guideline is five to eight direct reports for a manager and slightly fewer for a leader managing other managers, because managing through people is more cognitively expensive than managing individual contributors. As a security org grows past roughly thirty to fifty people, you typically move from a flat team of leads to two or three layers spanning functions such as SOC, GRC, AppSec, and identity. Add a layer when your directs can no longer give their own teams enough attention, not merely because headcount grew.

Free template

Steal the 90-Day CISO Plan

The exact 90-day plan structure hiring panels expect: the single asset every CISO candidate gets asked for. Free, editable, yours in one click.

Instant access, no confirmation hoops. Occasional emails on landing the seat; unsubscribe anytime.