Leadership · 6 min read
Top 3 Traits for CISOs in the New Era of Cybersecurity
By David Lin · Chief Executive Officer, MyAble Inc.
The cybersecurity landscape has transformed over the past decade. Today's Chief Information Security Officer must be more adaptable and skilled than ever, balancing technological acumen, cost-conscious decision-making and, perhaps most importantly, trust-building across the organization.
Reflecting on my own experience, from navigating the fallout of a nation-state cyberattack at Sony Pictures Entertainment to guiding new technology leaders, the modern CISO role is more dynamic and challenging than it has ever been. Three traits have become indispensable: resilience under pressure, the ability to communicate and foster trust, and a forward-looking approach to technology adoption.
1. Resilience under pressure
It's no secret that cybersecurity is high stakes. A CISO is often the last line of defense against threats that, if successful, cripple an organization's operations. At Sony Pictures Entertainment, where I led the recovery of IT operations after a nation-state attack, resilience wasn't merely beneficial. It was essential. Every day brought unique, urgent challenges that had to be solved quickly and decisively.
The ability to stay calm and resourceful in high-stakes situations is resilience. During a crisis, a CISO must maintain a clear mind to assess the situation accurately, decide on priorities, and communicate objectives effectively. The real challenge is managing your own stress while leading a team, so that the collective response stays cohesive rather than fragmenting into a dozen well-intentioned side quests.
A CISO with true resilience doesn't just recover from attacks. They learn, refine, and fortify defenses for the future.
Building a resilient mindset takes deliberate practice: mentorship, training, and personal habits that hold up when the pager goes off at 2am. Resilience also extends well beyond the crisis itself. Every breach and every attempted attack produces data, insight into where the vulnerabilities are and how efficiently the response actually ran. The organizations that improve fastest are the ones that treat the post-incident review as seriously as the incident.
2. Building trust through communication and collaboration
CISOs once operated behind the scenes, interacting primarily with IT teams. Today they must be as much diplomat as defender, bridging gaps across departments and communicating risk, strategy and outcomes in ways that land with everyone from engineers to board members.
A successful security strategy requires collaboration across the enterprise: IT, HR, legal, finance, even marketing. Virtually every department has a stake in data security and resilience. Building those bridges requires a CISO who can translate complex security concepts into business language and genuinely relate to each team's concerns.
Across multiple global enterprises I've seen how critical cross-functional trust becomes during a crisis. After an incident, we needed every department participating actively in investigation and recovery. That was only possible because we had already established open lines of communication and trust, addressing concerns transparently and explaining requirements in terms that made sense for each team. Building a culture where cybersecurity isn't an afterthought takes time and a strategy that will differ from company to company.
Communication matters just as much in daily operations. Educating non-technical stakeholders about their role in security reduces risk and builds shared responsibility. In my experience, framing security as something that protects them, meaning their family, their accounts and their identity, builds far more goodwill than framing it as organizational policy. People embrace practices they see the point of. They route around ones that feel like hurdles.
3. A forward-looking approach to technology and threat
Cybersecurity is a constantly evolving field. New threats emerge daily and new technologies must be vetted carefully. Today's CISO needs a forward-looking approach, one that balances agility with caution.
Over years of overseeing security programs I've watched the rapid adoption of cloud, IoT and now AI. These innovations offer real benefits and they introduce real new exposure. A CISO in this era can't simply react to them; they anticipate them, staying informed and proactive rather than perpetually catching up.
A forward-looking CISO tracks emerging technology while keeping a clear view of the organization's long-term strategy, considering scalability, cost-effectiveness and compatibility with what already exists. Part of the job is knowing when and how to integrate something new so it simplifies rather than complicates operations.
Just as importantly, CISOs today must be risk-oriented rather than fear-driven. Instead of dismissing a new technology because it introduces risk, assess that risk in the context of what the business is trying to achieve, then manage it. Security technology is only effective when it's understood, accepted and maintained by the broader organization, and none of that happens if the security team is seen as the department of no.
Nurturing the next generation
Resilience, communication and foresight define a strong CISO. But the greatest value any CISO leaves behind is a robust team. The next generation of security professionals will face an increasingly sophisticated threat landscape, and it's the responsibility of today's leaders to mentor and develop them.
That means identifying and nurturing talent, creating room to grow, and empowering genuine autonomy. I've been fortunate to watch mentees become formidable leaders in their own right. Developing leadership in others strengthens the immediate team and prepares the organization for whatever comes next.
As threats continue to escalate, the CISO role will keep evolving. By fostering resilience, building trust and staying forward-looking, we can build security strategies that protect the organization and position it for growth. Empowering the next generation is the ultimate measure of success, making sure our defenses are strong today and sustainable tomorrow. That, I believe, is the true mark of a CISO who understands the demands of this era.
Facing one of these decisions?
MyAble helps leadership teams turn security from a cost center into a business capability: strategy, AI governance, fractional CISO leadership and incident readiness.
Let's Chat