Umm… maybe?
I was asked this question this week by a founding engineer. They wanted to know if CISO’s are technical or not. Wow, did they ask the right person for this! (or maybe not if you don’t agree with my thoughts lol)
So here is my take.
Are CISO’s technical? No, not enough of them are.
Should CISO’s be technical? Well, yes as much as possible, especially if it helps them understand the engineering/product side of the business.
Do they need to be technical? For smaller companies and engineering forward ones, yes. However, many businesses don’t require it… but it doesn’t hurt.
In fact, many larger companies have a CISO that does all the strategy and high level stuff and then the Deputy CISO or Head of Security that does all the real security. 🤷🏼♂️
However this is changing, especially with AI.
Let’s get a few things straight.
The CISO (or VP of Security) position is typically a position that doesn’t exist at startups or medium sized enterprises.
For smaller companies and startups, it’s usually called the Head of Security or even sometimes security lead, or founding security engineer.
Rarely does a startup have a CISO. If they do, then it’s usually a naming thing to show they are bigger than they are.
Let’s go back to the original question.
Are CISO’s Technical?
Historically, no they have not been.
But that kinda changed when Alex Stamos became CISO of Yahoo.
It slowly has been changing since.
Anyone interviewing these days will know that even in leadership or compliance positions at banks, the questions are getting more technical.
You have to study for interviews again.
Why is that?
Well, I think it’s mostly driven by the market.
When the market contracts, people in tech are asked to do more. Employers demand more.
Companies can afford to wait for that person that has the right mix of technical and non-technical skills.
The Role of AI with the CISO
Not only that, but let’s not forget the role of AI here.
AI is shortening the gap between technical know-how and experience.
The one thing I AM TELLING EVERYONE right now is to get your hands dirty and start building and deploying apps. (Here’s a WIP guide)
I don’t care what app you build, just build something.
You will learn throughout the process.
Learning increases neuroplasticity.
Better yet, if you’re in security, then you have an opportunity to run a security review against the thing you just built.
Win-win!
Learn the language, or speak English only?
Let’s posit the question this way:
If you travel to a foreign country, do you learn some of the phrases, history, and try the food of the local people?
Or do you stick to your native language and fast-food and refuse to learn.
Will the people be impressed that you decided to learn a few words in their language?
Or that you understand more about their culture and history than just at a high level (or worse, not at all)?
Yes, almost always they will be.
What does that result in?
Connection!
Now you’ve won their hearts and favor. They feel like you understand them, or at least see them.
This is a form of communication and understanding… that can lead to (wait for it)... empathy!
Now imagine this foreign country is your Engineering Department.
The engineers are often why the company exists. They make the thing the company sells. Their product touches the customer.
So how would they feel if you don’t even know what programming language they speak, let alone never deployed an app in an environment like theirs.
Or if you can’t speak cloud and are still talking about power distribution and racking and stacking?
They won’t feel seen or heard.
The Role of The CISO
Our role is to keep things secure.
Sometimes that requires behavior change.
To effect behavior change, you need social capital.
To gain social capital, you need understanding.
To obtain understanding, you need to speak the language.
That means a CISO needs to be able to speak the following languages:
Business
Financials
Marketing
Customer Needs
Legal
Engineering
Product
The CISO is one of the few roles that requires such broad cross domain knowledge and deep understanding. Good security people are also educators. To meet people people where they are and reach them effectively, we need to be well informed. Technology is just one of those areas.
AI Disclaimer: This article was 100% hand written in a Google Doc (one shotted with some coffee, FluxFM, and a pastry) and text was not submitted to any AI agent.
Images are AI generated.
Related Discussion
Jensen Huang on the future of jobs
Just finished listening to this interview and found the discussion around the future of programming and job to be quite relevant to my discussion above.
Transcript:
https://lexfridman.com/jensen-huang-transcript#future-of-programming
Additional Security News
(Thanks to Marco from CloudSecList for the below items)
Sysmon for AI Agents, very cool!
I’ve been saying how we need telemetry on the endpoint on what’s going on. This is part of the solution here. I love how the logs are SIEM friendly! Woot.
OSS Models deliver Opus 4.8 Cybersecurity Results
Glad someone is doing this. We’re going to see more and more of this. What we definitely need is some form of standard testing framework so that we can really compare apples-apples. I saw a talk by the founder of Corgea on this topic at DEF CON.
Threat Hunter AI Analyst
I love it when companies have engineering blogs and post about the cool stuff they’re doing. This is how we all learn. Not to mention, it helps engineers really craft their communication skills.
Everyone is doing this in one form or the other. It’s always evolving, but love seeing the details here.





Great perspective. With technology evolving so quickly, it’s hard for CISOs to keep up, but they need both the technical and business skills to stay on top of what’s required within their organization.
Updated the article with some additional links and reading.