# The CISO Trap: Why the Best Security Leaders Are Rethinking Everything


Steve Blauner spent years at Citigroup navigating one of the most complex security environments on the planet — a global financial institution with millions of customers, dozens of regulators across multiple jurisdictions, and threat actors ranging from nation-states to organized crime. When someone with that resume talks about what the role demands now versus what it demanded a decade ago, the delta is stark enough to suggest we're essentially talking about two different jobs.


The title stayed the same. The job didn't.


## From Gatekeeper to Governor


The original CISO mental model was defensive: build walls, monitor for breach, respond when something got through. Success was absence — nothing leaked, nothing crashed, no headlines. That model worked reasonably well when security lived in the basement of the org chart, reported to the CIO, and was evaluated on uptime metrics and firewall logs.


That world ended somewhere around 2015 and the security profession spent the next decade catching up to that fact. What Blauner and the small cohort of CISOs who came up through major financial institutions understood early was that the gatekeeper framing was a trap. You can't win a game defined entirely by what didn't happen. You can't get budget for absence. You can't explain a breach to a board that approved your program by saying "we stopped the last seventeen."


The CISOs who survived and built durable programs shifted their framing to risk governance — they stopped being the people who said "no" and started being the people who said "here's what we're accepting and why." That sounds like a subtle distinction. It's not. It's the difference between being a cost center that leadership tolerates and being an executive who's actually in the room when decisions get made.


## The Legal Crosshairs


Here's what that transition costs, though: visibility. When the CISO is a strategic executive with a seat at the table, they're also a named defendant when things go wrong.


The SolarWinds case cracked this open. The SEC sued SolarWinds and its CISO Tim Brown directly in 2023, alleging they misled investors about the company's security posture before and after the breach. Even after a federal judge dismissed most charges in mid-2024, the message to the profession was unmistakable: the person with "Chief Information Security Officer" on their business card now carries personal legal exposure that barely existed five years ago.


The SEC's 2023 cybersecurity disclosure rules didn't help. Material incidents now require public disclosure within four business days. That clock starts when the company determines an incident is material — which creates perverse incentives to slow-walk that determination. The CISO is now caught between regulators demanding speed and legal teams demanding caution, with their personal liability sitting in the middle.


Blauner's perspective on what makes a great security leader has to be understood against this backdrop. "Great" now includes the capacity to operate under legal and regulatory pressure that previous generations of CISOs never faced.


## AI and the Career Fork


The AI question is where things get genuinely complicated for security professionals at every level, not just CISOs.


On one side: AI is making certain security tasks faster and cheaper. Alert triage, threat hunting at scale, log analysis, phishing detection — these are areas where capable AI tooling is reducing the human hours required. That's real and it's happening now.


On the other side: the same capability shift is hitting attackers harder and faster. AI-generated phishing campaigns have already demonstrated the ability to produce personalized lure content at volumes that human operators couldn't match. AI-assisted vulnerability research is compressing the time between CVE publication and weaponization. The asymmetry that defenders have always complained about — attackers only have to be right once — is getting worse.


What this creates is a bifurcation in security careers. The people who can work *with* AI tooling — who can design detection systems, interpret outputs, identify where the models fail, and build the human judgment layer on top — are going to be valuable. The people doing purely mechanical work that AI can now automate are in a harder position.


For CISOs, the AI challenge is different: it's governance. Every organization is now adopting AI tools across every function, often faster than security teams can assess them. Data going into AI training pipelines, API connections to external models, shadow AI adoption by employees using consumer tools — this is the new perimeter, and most organizations don't have a clear picture of where their sensitive data is flowing.


## Operational Resilience: The Real Frontier


The concept Blauner points to — operational resilience — deserves more attention than the security press typically gives it.


The intellectual shift it represents is significant: from "prevent all bad outcomes" to "ensure the organization can absorb, adapt to, and recover from disruption." That sounds like admitting defeat. It's actually more honest about what security programs can realistically deliver.


Europe recognized this and codified it. The EU's Digital Operational Resilience Act, which came into force in January 2025, requires financial institutions to prove they can withstand and recover from ICT disruptions — not just that they've built defenses. DORA demands documented threat-led penetration testing, third-party risk management, and recovery capability testing. It's essentially requiring organizations to prove resilience rather than just claim it.


U.S. financial regulators are moving the same direction, with OCC, Fed, and FDIC guidance increasingly focused on recovery time objectives and demonstrable continuity capabilities. The CISO who understands operational resilience as the frame isn't just being philosophically sophisticated — they're anticipating the regulatory direction.


---


## HackWire Analysis


The conversation around CISO leadership tends to produce either hagiography ("here's what a visionary looks like") or complaint ("nobody respects us, the board doesn't listen"). Blauner's perspective earns more credibility than most because it comes from someone who ran security at an institution with real systemic risk — a Citigroup breach isn't a reputational problem, it's potentially a financial stability problem.


But the piece most coverage misses is this: the CISO role is currently being asked to do three different jobs simultaneously, and the structural tension between them is real.


Job one is technical governance: understanding the threat landscape, running the security program, managing incident response. Job two is regulatory and legal navigation: keeping the organization compliant with an accelerating body of disclosure requirements, working with counsel on materiality determinations, managing personal liability exposure. Job three is business enablement: being a credible voice in product and technology decisions, assessing AI adoption risk, communicating clearly to a board that mostly lacks technical fluency.


These three jobs require different skills, different relationships, and different rhythms. The best CISOs figure out how to modulate between them. The ones who burn out — and turnover in the role is still brutal, average tenure hovering around 18-26 months — usually do so because the organization hired them for one and then quietly demanded all three.


The operational resilience framing is useful precisely because it offers a through-line: if you're building for resilience, you're simultaneously doing good technical work, satisfying regulators who want to see recovery capability, and speaking a language that boards understand because "can the business keep running" is a question executives know how to evaluate.


The CISOs who internalize this aren't just good at security. They're good at their actual job.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)