Root To CISO

The Number #1 Skill Every Successful CISO Has Than No One Teaches You | Root To CISO Podcast

Kris Rides

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 10:04

Cybersecurity professionals are taught to focus on tools, threats, and technical expertise. While it's important to have technical skill, the reality is that for you to advance you need this

In this week's episode we recap a cybersecurity skill that has come up almost in all our chats with successful CISO and one thing is clear. The most successful security leaders aren’t just technical experts, they understand the business inside and out and know how to align their work to business objectives.

In this episode the conversation goes beyond technical skills and dives into  learning how organizations make money, understanding executive priorities, incentives, and objectives, and aligning with business operations and teams outside cybersecurity. 

The episode explores how cybersecurity professionals can align their work with what actually drives a company forward, because security doesn’t operate in isolation. Every control, every decision, and every risk has a direct impact on business performance.

You’ll also learn why strong communication and listening skills are critical, how to build trust across departments like HR, marketing, and sales, and how aligning with executive goals can help you deliver both security outcomes and business value.

Here is what stands out in the episode:

  • Why cybersecurity professionals must understand the business extensively
  • How CISOs align security with executive objectives
  • The importance of communication and stakeholder management
  • Turning cybersecurity into a business enabler
  • Translating technical risk into business impact
  • Building trust across teams and departments

If you want to move beyond being seen as “just technical” and start influencing real decisions, this episode gives you a clear perspective on how to do it. Whether you’re early in your cybersecurity career or aiming for a leadership role, understanding the business is not optional. It’s the foundation for long-term success.

Listen to the full episode and follow for more insights from cybersecurity leaders and hiring managers on how to grow your career and stand out in the industry.

#RootToCISO #Podcast #Cybersecurity #Leadership #CareerGrowth #BusinessUnderstanding

Speaker 5

Hi, and welcome to the Root To CISO Byte Size podcast. I'm your host Kris Rides, and in these bite-sized episodes, we'll be speaking to experienced cybersecurity hiring managers. We'll be asking their advice on how you can stand out from the crowd to make the career moves you desire.

Speaker 8

I truly believe that we have the hardest job, function and job role in an organization because we have to be right all the time. Mm-hmm. Right? Not only that, but we have to know the entire business. It's not, one department and I'm a subject matter expert of one department organization. I have to be a subject matter expert every single. A department in the organization, I need to understand how they work, how they operate. Mm-hmm. What are the processes? What are the intricacies? What are the interdependencies? I need to understand how the business makes money. I need to understand how I could potentially affect from them, if I implement a certain control, how that may affect them making money. I need to understand how if someone was to attack a business unit, a business process, an entity, one of our third parties, how that would affect. Organization, how would we, either find or some type of, investigation or, or lawsuit might, might come into play. I need to understand all of that.

Speaker 7

It is funny 'cause what you're talking about there as an attribute is knowing and understanding the business, and that's probably the number one. Yeah, probably the number one attribute of when I've been speaking to all of these different CISOs business continually came up and then, and so I went out to like 500 CISOs over the last couple of years and asked them you, what are the three attributes you think you need to be, and again, business number one. And I think that's something that people that are a little bit earlier in their career. Need to kind of realize that it's never too early to understand the business you work for. Understand what your impact is. If you are an individual contributor, you still have an impact on that business. And I think the earlier you understand that, that's probably rocket fuel for a career.

Speaker 8

It is, it is. And that's why I go back to, I think the path that I took and those opportunities that I was given, has empowered me to be, the leader that I am today and, and be successful, in how I manage the program.

kris-rides_1_01-08-2026_134143

I've talked to so many CISOs and, you know, adding value and being a good listener, understanding the business, like all of these are skill sets that. A CISO needs, whether you know you're a current CISO or it's something you're aspiring to, or even if you're earlier on in your career, like these are the sort of conversations you need to be having because if you understand the business and you understand the stakeholders, you can provide value.

squadcaster-fe33_1_01-08-2026_164143

My initial, approach is to see what the executive team is doing and. What's on their mind and what's their objectives and not to really be too concerned about

kris-rides_1_01-08-2026_134143

talking

squadcaster-fe33_1_01-08-2026_164143

about risk and only things that I'm interested in.

kris-rides_1_01-08-2026_134143

In trying address, but really try to figure out how I can help them and how I can be be a partner from the business standpoint, which is what we do all the time anyways. But it's really just diving into what's top of mind and yes, you get into what's keeping 'em up at night, and it could be something that's recent, whatever it might be,

squadcaster-fe33_1_01-08-2026_164143

but ultimately they have their objectives that they need to execute on

kris-rides_1_01-08-2026_134143

now they're starting the trickle down to their teams. My main thing is, is, all right, how can I get involved and how can I help? And yes, I will align with some of the stuff of the

squadcaster-fe33_1_01-08-2026_164143

that's

kris-rides_1_01-08-2026_134143

been talked about before from a risk manager standpoint, and really the interest from a security technology team, but. But

squadcaster-fe33_1_01-08-2026_164143

it's a refresh. All right, let's just dive in and see where I can help.

kris-rides_1_01-08-2026_134143

And then hopefully people are thinking of, you know, the cybersecurity team as not the cost center, but the enabler. Right. And that's so important.

squadcaster-fe33_1_01-08-2026_164143

Exactly. And the enabling aspect, that's the most important and. Understand how the executives and the team is gonna be

kris-rides_1_01-08-2026_134143

gonna

squadcaster-fe33_1_01-08-2026_164143

getting the bonus, how they're incentivized to get this. And then ultimately, you align with that. You'll get your stuff done as well, and you'll probably address a few risks along the way.

kris-rides_1_01-08-2026_134143

Whatever you're bonused on is what company is obviously targeting for you to do. And, and I want my security to be something that helps you achieve that rather than stops you.

squadcaster-fe33_1_01-08-2026_164143

Exactly, especially when you take a look at like objectives, business objectives that trickle all the way down to the individual contributors. Everything should be aligned and there's no other way to do it than really understanding how the executives are going

kris-rides_1_01-08-2026_134143

are

squadcaster-fe33_1_01-08-2026_164143

to ultimately get paid if they meet their objectives. Now, when you tie in, again, alignment with risk

kris-rides_1_01-08-2026_134143

and

squadcaster-fe33_1_01-08-2026_164143

from security and technology standpoint. A heck of a lot easier discussion when you actually talk about, how it's gonna impact your objectives. We should try to figure out how to, make this work.

Speaker 3

I think a good CISO. So needs to sit back and listen to everything and understand. So I go out to the other business functions, HR, marketing, sales, you have, whatever it is. And I sit down with them and just learn about what they do, and how they fit into the business. I don't ask them for anything necessarily. I build up that rapport with them by listening and understanding their challenges and what they need to do and get done. And so that way, when I. Have a project or effort that I need their support with, then I can go to them and I, I can bring them something that's reasonable because I already know what their challenges are and what they, what they face day to day. So I'll build out, a new process or something that already fits their challenges or their way of working into it. And so, and then collaborate on finalizing that, and I just, and it, and then building up that rapport, if I really need them to do something, or, there's incident, I've got to have them shut down stuff or whatever it is, they realize that that's something really important, and they'll go do it as opposed to, every, every month, there's a new, emergency that they got to work on. It gets old and they don't listen after a while, so, just that communication, that billing report, that listening, I think is really key.

Speaker

It's the classic tale of the boy that cried wolf, right? You cry wolf enough times, eventually people start ignoring you and, And so building that rapport and knowing that when you've got a really big ask, you wouldn't normally be asking for it. And when you do have an ask, you've already pre thought about what they need. They take that seriously. I think the communication stuff is something that I think we can all work on for sure. And I mean, is there anything. You've done particularly to improve your communication skills, anything that you'd recommend for others that need to do better at that.

Speaker 3

Yeah, I mean, it's work in progress for sure. But, for me, it's, it's worked really well of. Being fairly, not highs and lows of, Oh, God, we got to, we got this, we got to do it. it's more of just staying somewhat mellow or even keeled, with talking to them and, with anybody. And not getting flustered and, and, or, minimizing the amount of fluster if, no matter what's going on. And it just, it helps calm everybody down. And help everybody think clearly for what we need to do, as opposed to, kind of creating chaos. So I think just that, man and being careful of how you say things again, it kind of goes back to people perceiving things differently. It's really important of how you express something. So a risk or asking them to do something. It might be important for you. It's not that important for them. So you've got to help them understand why it's important, how it's important for them and what the priority is and then help them work through that as opposed to saying, all right, we're going to do this.

Speaker

Yeah. A hundred percent. So communication skills, number one,

Speaker 3

and

Speaker

what's your next attribute?

Speaker 3

next one is being able to translate technology to business, at the CSO level, or this, running a program. You've really got to be able to do that. And, we're talking about earlier with the, the boardroom, training, highly recommend it. It really changed my thinking around to what, The board E. L. T. really focus on from a business perspective, and it's different than what I really thought. and so it it helped a lot. I was doing good. I was getting the point across but still maybe a little too much detail or. Little too much technical focus, but now it's again, continuous learning improvement, but, it's really important to be able to change that, vulnerability on a server into why it's important to the business, and then provide options. Hey, you're, we can just leave it there. We can, put a workaround in maybe, or, we can, actually do something about it. And this is what it means to the business for each of those options.

Speaker 6

Thank you for listening to the Root To CISO Byte Size podcast. I hope you enjoyed this episode. Make sure you keep an eye out for season three of the full Root To CISO podcast. And in the meantime, stay up to date by liking, commenting, and of course subscribing to our channel. Thank you.