
That reframing matters, because it captures something happening across the security industry right now: the CISO’s job is shifting from guarding systems to keeping the business running, no matter what hits it. Understanding why requires going back to where the role began.
A Job Invented in 1995, One Crisis at a Time
The chief information security officer title didn’t exist before 1994. It was created after a very concrete problem: attackers, reportedly operating out of Russia as an organized group rather than a lone hacker, stole $10 million from Citibank in an intrusion that shook the bank’s management. Steve Katz, who had spent years explaining computing to executives at Morgan Guaranty, got a call from a recruiter soon after and became the first person ever to hold the CISO title, in 1995. Blauner followed two years later, part of a small founding cohort that, in his words, "had no idea what we were doing" but had a visionary to follow.
Katz’s real legacy wasn’t a piece of technology — it was a philosophy. He insisted that security had to be treated as a collective problem, which is part of why he helped build the information-sharing organizations known as ISACs, groups that let banks, hospitals, and other critical industries trade threat intelligence instead of fighting alone. He also believed security was fundamentally about business risk, once suggesting his own title should have been "Chief Information Risk Officer" rather than CISO. That idea — that a security leader’s real currency is risk, not just technology — is the thread running through everything that followed.
The Only Executive With a Dedicated Adversary
Blauner argues the CISO occupies a strange place in the executive suite. A CFO can lose the trust of colleagues by cutting budgets, but no one is actively engineering ways to defeat the CFO. A CIO juggles competing priorities, but isn’t opposed by an adversary whose entire purpose is to make them fail. The CISO is different: someone, somewhere, is spending every working hour trying to find the gap that turns into a headline.
That structural pressure explains a lot of the turnover and burnout stories that circulate in security news. But Blauner pushes back on the idea that the job is simply "too hard." Instead, he frames the friction as a communication problem: security leaders often talk in technical language to people who think in business outcomes. His example is blunt — if you tell a chocolate-division head about a vulnerability in abstract technical terms, they tune out; tell them it could disrupt chocolate production or let someone tamper with the product, and suddenly they’re listening. The skill that separates a merely competent CISO from an effective one, in this telling, isn’t deeper technical mastery — it’s translation.
From Guarding the Perimeter to Guarding the Mission
That translation instinct is really a symptom of a bigger shift: security leadership moving from a purely technical mandate toward something closer to operational resilience — the idea that an organization should keep delivering its essential services even when systems are disrupted. Blauner sees this as the field’s "next frontier," arguing that CISOs who start from the question "what are our critical business processes, and how do we keep serving customers through a crisis?" naturally become business leaders rather than technologists who happen to sit near the top. It’s worth being clear that this is Blauner’s own framing of where the profession should head, not a settled industry standard that every company has already adopted — plenty of organizations still run security as a largely technical function reporting deep inside IT.
The contrast between the two eras is easiest to see side by side:
| Dimension | Early CISO era (1990s–2000s) | Today’s leadership expectation |
|---|---|---|
| Primary focus | Protecting networks and systems from intrusion | Keeping critical business services running under disruption |
| Core skill | Technical depth (engineering, architecture) | Communication, risk translation, cross-functional leadership |
| Success measure | Absence of breaches, uptime of defenses | Business continuity, speed of recovery, executive trust |
| Relationship to business | Support function, often buried in IT | Increasingly treated as a strategic, business-aligned role |
| Decision environment | Rule-based, technical playbooks | Fast decisions under pressure, often with incomplete data |
Where the Signal Actually Travels
If resilience is the destination, it helps to see the path a piece of technical information takes before it becomes a business decision. Blauner’s account of crisis leadership — courage under uncertainty, fast pivots, translating jargon into stakes people understand — maps onto a fairly simple chain:
flowchart TD A[Threat or anomaly detected] --> B[Security team assesses business impact] B --> C[CISO translates risk into business terms] C --> D[Executives and board decide response] D --> E[Incident response and recovery] E --> F[Operational continuity maintained]
Notice where the CISO actually sits in that chain: not at the technical detection step alone, but in the translation node that turns a technical signal into a decision leadership can act on. Miss that step, and even a well-defended organization can freeze at the moment it matters most.
Who a CISO Actually Answers To
Resilience-minded leadership also raises a structural question: where should the CISO sit on the org chart to make that translation credible? Survey data on this varies by year and by organization, but one snapshot found roughly a third of CISOs reporting to the CIO, close to a fifth reporting to the CTO, a smaller share to the chief risk officer, and only about 3% reporting directly to the CEO — with a notable 8% sitting three or more levels below top leadership. That pattern has drawn criticism, since a CISO who reports to the CIO may face pressure to soften security findings that reflect badly on the CIO’s own technology decisions. There’s no single "correct" structure, and reporting lines differ widely by company size and industry — but the debate itself reflects the same tension Blauner describes: security leaders straddling a technical function and a business-facing one.
What AI Actually Changes — and What It Doesn’t
Any conversation about the future of this role now runs into AI, and Blauner’s take is measured rather than alarmist: talented people will always have work, he argues, because AI won’t put cybersecurity "out of business" — it will change what people spend their time on, automating the "boring, mundane stuff" like sorting through false positives, while leaving strategic risk conversations and architecture decisions to humans. That view lines up with survey findings from security professionals themselves: 88% expect AI to significantly affect their jobs in the near future, and 82% see it improving their efficiency, largely by automating repetitive tasks like monitoring network traffic and analyzing behavior patterns. Notably, 56% also said AI will make parts of their job obsolete — but "obsolete tasks" and "obsolete careers" are not the same thing, and the same survey data points to a persistent global shortage of cybersecurity workers, not a surplus.
Mentorship as Infrastructure, Not a Nice-to-Have
One thing that doesn’t show up in job descriptions but runs through Blauner’s account is how collaborative this leadership track actually is. He credits Katz’s habit of mentoring "anyone who needed help" — salespeople, junior analysts, competitors’ staff — with creating a culture where senior CISOs are expected to pay it forward, not hoard expertise. Blauner and his peer Phil Venables alone count more than 120 CISOs who trace their careers back through their mentorship, plus several times that many informal mentees. Colleagues who worked alongside Katz through information-sharing groups describe the same pattern of him "giving selflessly back to the global infosec community" well into retirement. In an executive landscape often built around individual accountability, that’s an unusually communal way to define leadership success.
The Takeaway
None of this means technical skill stops mattering, or that every company needs to restructure its org chart tomorrow. But it does explain why the most-discussed security leaders today sound less like engineers and more like translators — people whose value lies in connecting a technical signal to a business decision, and in building teams and networks resilient enough to keep functioning when, not if, something goes wrong. The tools securing a network will keep evolving. What Blauner suggests won’t change is the need for someone in the room who can make a technical risk sound like exactly what it is: a business risk.


