Subscribe to the Premier Computers blog

Get new posts on security, compliance, and business in your inbox.

← Back to all articles
Business

What a Former Wall Street CISO Wants You to Know About Security Leadership

David Blauner, former Citigroup CISO, argues that great security leadership is less about technical mastery and more about business fluency, communication, and judgment under pressure.

Here’s a pattern you’ve probably noticed: companies keep hiring brilliant technical people to run security, and then wonder why the board still doesn’t trust them. Former Citigroup CISO David Blauner recently weighed in on this, and his take is worth sitting with. The best security leaders, he argues, aren’t necessarily the sharpest technologists in the room. They’re the ones who can translate risk into language a CFO, a regulator, or a hospital administrator actually understands.

This isn’t a new idea, but it’s landing differently right now. Security teams everywhere are drowning in tools, alerts, and acronyms (something The Register recently poked fun at when covering how the industry’s answer to AI security risk is often just… more AI, wrapped in more jargon). Meanwhile, CISOs are increasingly personally liable when breaches go sideways, thanks to tighter SEC disclosure rules and a few high-profile prosecutions. That combination, more complexity plus more accountability, is forcing a rethink of what “qualified” even means for a security leader.

Blauner’s point, distilled: a CISO’s real job is managing uncertainty and communicating it clearly, not memorizing every control framework. That means knowing when to escalate, when to say “we’re not ready” to a product launch, and how to build enough trust with the CEO that hard truths actually get heard before a crisis, not during one.

Why should this matter outside the security org? Because the CISO’s seat looks completely different depending on the industry, and the stakes of getting the “right” leader wrong vary a lot too. In finance, a CISO without business fluency can blow up a merger or trigger a regulatory fine that dwarfs the cost of the original incident. In healthcare, a security leader who can’t communicate clearly with clinicians and compliance officers puts patient care and HIPAA standing at risk simultaneously. In government, where budgets, procurement rules, and political pressure all collide, a CISO who can navigate bureaucracy as well as firewalls is often more valuable than one who can’t. Across all of these, the technology is rarely the bottleneck anymore. People and judgment are.

As boards face more scrutiny over their cyber oversight (and more shareholder lawsuits when things go wrong), how they define and vet security leadership talent is quietly becoming a governance issue, not just an IT one.

Questions 

  • Should boards require security leaders to have direct business or operations experience, not just technical credentials?
  • How much should a CISO’s personal legal liability shape who’s willing to take the job at all?
  • Is the “translator between tech and business” model of leadership realistic at smaller organizations without big budgets?
  • Does adding more AI tools to security operations actually reduce complexity, or just relocate it?
  • Should regulators in finance, healthcare, and government set different standards for what makes someone qualified to lead security?
  • What’s more valuable in a crisis: deep technical expertise or the ability to communicate risk clearly to non-technical leaders?