8 min read

What a CISO Actually Does on a Tuesday Afternoon

The CISO job description reads like a strategy role. The actual job is mostly operational. Here is what a competent CISO does on a typical Tuesday afternoon, and what the things look like in practice

Purple Teaming Threat Modelling

The CISO job description reads like a strategy role. The job description talks about vision, alignment, governance, and risk. The actual job is mostly operational. The actual job is a long list of meetings, conversations, and decisions, most of which never make it into the job description.

Here is what a competent CISO does on a typical Tuesday afternoon, and what the things look like in practice.

The 14:00 meeting that was supposed to be 30 minutes

The first meeting is at 14:00. The first meeting was supposed to be 30 minutes. The first meeting is about a vendor contract that the procurement team is pushing back on. The procurement team is pushing back because the vendor contract has a price increase that the procurement team did not budget for. The vendor is the SIEM vendor. The SIEM is the foundation of the detection capability. The price increase is real.

The CISO has to decide. The CISO has to decide whether to push the procurement team to approve the contract at the increased price, or whether to use the price increase as the moment to start the conversation about replacing the SIEM. The CISO has to decide based on the strategic importance of the SIEM, the operational cost of replacing the SIEM, and the relationship with the SIEM vendor. The CISO has to decide in 30 minutes.

The 14:00 meeting is not a strategic meeting. The 14:00 meeting is an operational meeting with strategic implications. The CISO has to make a decision that affects the strategic direction of the programme. The CISO has to make the decision without the benefit of the strategic context. The CISO has to make the decision with the procurement team and the vendor account manager in the room.

The CISO has to make the decision. The CISO has to make the decision in 30 minutes. The CISO has to make the decision without the benefit of the strategic context. The CISO has to make the decision in 30 minutes with the procurement team and the vendor account manager in the room. The CISO is doing this kind of decision three or four times a week.

The 15:00 conversation that is the actual work

The 15:00 slot is a conversation. The conversation is not a meeting. The conversation is a thirty-minute slot in the CISO's calendar that is reserved for the conversations that do not fit into meetings. The conversation is the CISO's most important slot of the day.

The conversation is with the SOC manager. The conversation is about the incident from the previous night. The incident from the previous night was a credential-stuffing attack against the customer-facing authentication system. The credential-stuffing attack was detected by the WAF. The credential-stuffing attack was blocked by the WAF. The credential-stuffing attack was logged in the SIEM. The credential-stuffing attack was not escalated to the SOC. The credential-stuffing attack was not investigated by the SOC. The credential-stuffing attack was not reported to the CISO.

The CISO finds out about the incident from the SOC manager the next morning. The CISO finds out about the incident in the 15:00 conversation. The CISO finds out about the incident because the SOC manager wanted to talk about it. The SOC manager wanted to talk about it because the SOC manager was not sure whether the response was right.

The CISO and the SOC manager talk. The CISO and the SOC manager talk about whether the WAF was the right control. The CISO and the SOC manager talk about whether the SIEM should have alerted. The CISO and the SOC manager talk about whether the SOC should have investigated. The CISO and the SOC manager talk about whether the CISO should have been told. The CISO and the SOC manager talk for 30 minutes. The CISO and the SOC manager come out of the conversation with a list of the specific things that are going to change.

The 15:00 conversation is the actual work. The 15:00 conversation is the work that the CISO is most directly responsible for. The 15:00 conversation is the work that the CISO is most able to do well. The 15:00 conversation is the work that the leadership is most likely to want to skip. The 15:00 conversation is the work that the leadership cannot afford to skip.

The 16:00 email that took 45 minutes

The 16:00 email took 45 minutes. The 16:00 email was a long email about a security incident at a peer organisation. The long email was from the CISO of the peer organisation. The CISO of the peer organisation is going through the same things the CISO is going through. The CISO of the peer organisation is reaching out to ask the CISO how the CISO is handling the same things.

The 16:00 email is not a strategic email. The 16:00 email is an operational email. The 16:00 email is an email that is asking for the CISO's specific advice on a specific problem. The 16:00 email is an email that is asking for the CISO's time.

The CISO has to respond. The CISO has to respond with the CISO's specific advice on the specific problem. The CISO has to respond with the CISO's time. The 16:00 email takes 45 minutes. The 16:00 email takes the CISO's time.

The 16:00 email is the kind of work that the CISO is most likely to be doing. The 16:00 email is the kind of work that the CISO is most likely to be doing at 16:00. The 16:00 email is the kind of work that the CISO is most likely to be doing for the rest of the CISO's career. The 16:00 email is the work.

The 17:00 decision that the CISO has been putting off

The 17:00 decision is the decision that the CISO has been putting off. The 17:00 decision is the decision about whether to approve the budget for the next phase of the detection engineering programme. The next phase of the detection engineering programme is the most important project the CISO is running. The next phase of the detection engineering programme is also the most expensive. The next phase of the detection engineering programme is also the one that the CISO is not sure will deliver the value that the next phase of the detection engineering programme is supposed to deliver.

The 17:00 decision is the decision that the CISO has been putting off. The CISO has been putting off the decision because the CISO is not sure. The CISO is not sure because the CISO does not have the data. The CISO does not have the data because the CISO has not been running the red team engagements that would give the CISO the data. The CISO has not been running the red team engagements because the CISO has been putting off the red team engagements. The CISO has been putting off the red team engagements because the CISO is not sure whether the red team engagements will deliver the value that the red team engagements are supposed to deliver.

The 17:00 decision is the decision that the CISO has to make. The 17:00 decision is the decision that the CISO has to make without the data. The 17:00 decision is the decision that the CISO has to make based on the CISO's judgement. The 17:00 decision is the decision that the CISO has been putting off.

The CISO makes the 17:00 decision. The CISO makes the 17:00 decision based on the CISO's judgement. The CISO's judgement is informed by the CISO's experience. The CISO's judgement is informed by the CISO's conversations. The CISO's judgement is informed by the CISO's understanding of the programme. The CISO's judgement is the best that the CISO can do.

The 18:00 thought that the CISO does not share

The 18:00 thought is the thought that the CISO has when the CISO is wrapping up the day. The 18:00 thought is the thought that the CISO does not share. The 18:00 thought is the thought that the CISO has about whether the CISO is doing the work that the CISO is supposed to be doing.

The 18:00 thought is the thought that the CISO is not doing enough of the work that the CISO is supposed to be doing. The 18:00 thought is the thought that the CISO is doing too much of the work that the CISO is not supposed to be doing. The 18:00 thought is the thought that the CISO is being pulled in too many directions. The 18:00 thought is the thought that the CISO is not making the time for the work that the CISO is supposed to be making the time for.

The 18:00 thought is the thought that the CISO has every day. The 18:00 thought is the thought that the CISO does not share. The 18:00 thought is the thought that is the most honest thought the CISO has.

The honest answer

The honest answer is that the CISO job is mostly operational. The honest answer is that the CISO job is mostly meetings, conversations, and emails. The honest answer is that the CISO job is mostly the work that the CISO is doing between the strategic work.

The honest answer is that the CISO is doing the strategic work in the operational work. The honest answer is that the CISO is making the strategic decisions in the 30-minute meetings. The honest answer is that the CISO is shaping the strategic direction in the 15:00 conversations.

The honest answer is that the CISO job is the work. The honest answer is that the work is the operational work. The honest answer is that the operational work is the strategic work. The honest answer is that the CISO is doing the strategic work in the operational work.

The honest answer is that the CISO job is hard. The honest answer is that the CISO job is mostly operational. The honest answer is that the CISO job is worth doing. The honest answer is that the CISO job is the work.