The role of the chief information security officer (CISO) has transformed dramatically over the past three decades, evolving from an emerging technical position into one of the most strategically important leadership roles in business. Few people have witnessed that evolution as closely as Charles Blauner, who served as CISO at JPMorgan, Citigroup, and Deutsche Bank after entering the field at the dawn of information security.
In this episode of Heard It From a CISO, Blauner reflects on the influence of Steve Katz, who is regarded as “The Godfather” of the CISO role, and explains how mentorship, collaboration, and a culture of paying it forward helped shape the profession. He also discusses why today’s security leaders must be more than technical experts, arguing that resilience, communication, and business acumen are increasingly defining characteristics of successful CISOs.
Cybersecurity leaders face a challenge few other executives encounter: Their success depends on staying ahead of adversaries whose full-time job is to find ways to make them fail. According to the veteran security executive, that reality makes the CISO role unlike any other in the C-suite — and one of the most demanding.
In this conversation, Blauner offers career advice for aspiring cybersecurity professionals, explains why building a network of mentors matters more than finding just one, and shares the qualities he believes separate effective CISOs from the rest. Along the way, he addresses AI’s impact on security jobs and argues that the future of cybersecurity lies not only in protecting technology, but in helping organizations build lasting operational resilience.
This is part of Dark Reading’s ongoing Heard It From a CISO video series, which features frank, exclusive conversations with cybersecurity leaders in the trenches. Check out the entire series here.
Heard It From a CISO With Charles Blauner: Full Transcript
This transcript has been edited for clarity and length by Informa TechTarget’s internal AI assistant. For the full experience, please watch the video.
Dark Reading’s Kristina Beek: Hi, my name is Kristina Beek, and I’m an associate editor with Dark Reading, and we are here for another episode of Heard It From a CISO. Today I’m joined by Charles Blauner. Thank you so much for being with us today.
Charles Blauner: It’s my pleasure, Kristina.
DR’s Kristina Beek: Awesome. So, I would love if you could just introduce yourself and then just tell us about your background.
Charles Blauner: I’m Charles Blauner. My background is from a long time ago. I was a computer science major. I was working at a company called Bell Communications Research, which supported the telephone companies, and hacking started.
And then all of a sudden, people thought we needed security and I got lucky. I was at the very beginning of information security being a thing. I moved into banking in the mid-90s and I spent most of my career there. [Then] I was the CISO of JP Morgan, Deutsche Bank, and Citigroup across 20 some odd years. And today I’m an operating partner at Crosspointe Capital.
DR’s Kristina Beek: I know that you were sort of mentored by Steve Katz, who was the original CISO, the grandfather or the godfather of cybersecurity, the CISO role, as you described. What would you say about his role in sort of creating the CISO role and how he sort of established that. What kind of precedent did it set?
Charles Blauner: Well, so your question breaks into a bunch of different things. I mean, the precedent was set in 1994 by actually creating the title and then hiring Steve to be in it. Obviously, when Steve took the title, no one really knew what the job was because we were just beginning it. And I think why so many of us sort of think of Steve as sort of the godfather. That very early group of CISOs — Steve was 1995, I was 1997, and there were a few others, Ron McLean and a number of us — none of us had any idea what we were doing. But we had a leader. And we had a visionary, which was Steve.
And so, we all just sort of worked together to sort of, on our own, define what the CISO title really was about. And honestly, it’s continued to evolve in the 30 years since then. But Steve set the precedent, or two important precedents, I think. One was Steve set the precedent that this was about the collective, right? We had to do this together because we couldn’t really do it on our own. And a few years later, the ISAC became Steve and myself and a few others. So, the first thing was the collective defense.
The second thing, I think that was so critical to how Steve was and those of us that sort of learned from him was Steve was the most generous person, in giving back his time, that I’ve ever met. At the end of his career, at the end of his life, he was mentoring CISOs, he was mentoring salespeople, he was mentoring anyone who he felt was a good person that needed help. Even some people he didn’t necessarily feel were good people but really thought they needed help. And so, Steve created this sort of culture of mentoring and sort of just giving back to the community. So not only was this about a collective defense, but for it to really work, we all had to really give back and pay it forward. And if you look at any of the people from that sort of first generation of CISOs, like Phil Venables and myself, we are almost probably the two that are almost probably still at some degree active from that generation. Between the two of us, we have well over 120 CISOs that have come out of our family tree.
We’ve probably each mentored two to three times that many people that didn’t work for us along the way. And I don’t want to speak for Phil, but if you asked him, I guarantee he would give a big chunk of that credit back to the sort of culture that Steve helped create.
DR’s Kristina Beek: Absolutely, yeah. That’s amazing that Steve was able to create such a legacy like that. And talking about mentorship, that sort of brings me to another one of my questions, which is just that I imagine that you feel that mentorship is incredibly important. And today, would you advise people to seek out a mentor when it comes to cybersecurity at their company or maybe not even at their company? Would you advise higher ups to seek mentees to give back?
Charles Blauner: Absolutely the answer to those questions is yes, but I would actually say it in a broader way.
DR’s Kristina Beek: OK.
Charles Blauner: If I’m a person early in my career, I’m not seeking out one mentor. I’m seeking out a whole bunch of mentors.
DR’s Kristina Beek: OK.
Charles Blauner: All right, and if I’m a person later in my career, I’ve hopefully been lucky enough to receive some good mentoring and now think of it as my turn to sort of pass it down. At my last formal job, one of the things I did was I created an informal mentoring program within my organization. But one of the conditions of being a mentor was you had to also be a mentee.
So, like, if you were a director and you had a managing director as your mentor, you had to have a senior vice president as a mentee. You had to sort of pay to get in and you had to pay it back. And so, yeah, mentoring is key. I would also say mentoring is also going right back to that whole idea of part of that community fabric, so don’t necessarily just seek out mentors and mentees, but build a network. And some of those people in your network will become mentors and some will be mentees, but that network is really critical for CISOs and anyone really in the cyberspace.
DR’s Kristina Beek: Yeah, absolutely. You mentioned that mentoring is obviously really important, perhaps for anyone. But in regard to CISOs, you once described it as the second hardest job within a company and perhaps maybe that’s why having community is so important. Why would you describe that role as so challenging?
Charles Blauner: So, the CEO’s role is clearly the most challenging in any large enterprise, right? Because in the end they are the person that is accountable for making the final decision. But if you think about the other sort of C-type roles in an organization — the CIO, the CTO, the CFO, the chief HR person, you might have a chief risk officer in some organizations — all of them have relatively well-defined jobs and relatively well-defined success criteria. And they have a whole organization trying to support them.
And, in a lot of ways, the CISO is similar, but the CISO is unique amongst all the other CXOs in that they actually have an active adversary. They actually have someone whose entire reason to exist is to break everything you’ve done.
DR’s Kristina Beek: Right.
Charles Blauner: The CFO doesn’t have an adversary, right? He may not always have a lot of friends if he’s cutting budgets and the like, but the CFO doesn’t necessarily have an adversary.
A CIO doesn’t have an adversary. The CIO, he or she has lots of challenges, but there’s no one out there spending every minute of every day trying to circumvent and break what they’re doing.
But the CISO is that person, right? The CISO, besides all the other pressures that the other senior leaders have, has an active adversary, has someone who is trying every day to find new ways to make you fail, all right? Because for the criminal to succeed, the CISO fails. And that may be an oversimplification, but you really have someone out there whose job it is to make you fail, and that’s completely unique.
DR’s Kristina Beek: That kind of brings me to a question that just came to mind, which is that, I’ll be scrolling the Dark Reading website and maybe I’ll see a commentary piece or something about whether or not we are too critical of the CISO, whether or not maybe their job is too difficult. And maybe this is because there’s so much, you know, job turnover in terms of who’s holding the role at a certain company. Would you agree or disagree with that?
Charles Blauner: So first of all, I don’t think the job is too difficult. I think it just takes a certain kind of person to do that job. And so definitely not too difficult. But one thing I would say that’s sort of like an important consideration there is that part of the reason that the struggle that you described exists is because there’s often a disconnect in sort of the language and the framework that people use.
CISOs would be better loved, better accepted, better integrated if, when they spoke to the business folks, they put it into a frame of reference the business folks can understand.
DR’s Kristina Beek: Right.
Charles Blauner: That’s where a lot of CISOs struggle is that they forget that all the technical baloney that they’re talking about, that they live with day in and day out, and it’s sort of natural to them.
If you’re talking to the head of a chocolate manufacturing division, you think they have the slightest clue what the heck you’re talking about?
Now, if you take that conversation to the chocolate guy and say, “The reason you care about this is because it can disrupt your ability to produce chocolate, or someone can tamper with the flavors of the chocolate.”
Now, the chocolate guy cares.
DR’s Kristina Beek: Right.
Charles Blauner: Right, and so it’s …
It’s a burden that we have to actually take in our roles as CISOs and that as easy it is to talk our speak, if you want people to be sympathetic, you want to get them on board, you want to get them aligned with what you’re thinking about, you actually have to take the extra step as a seesaw and put it into their frame of reference.
DR’s Kristina Beek: Yeah. You mentioned that communication is very clearly important. And you also mentioned that it takes a certain type of person to be CISO. What kind of person would you say or what qualities are like sort of essential to be successful in that role?
Charles Blauner: Oh wow, there are a number. I actually once did a whole talk about the CISO role and I think I listed 8 or 10 different qualities, but besides communications, there was probably two or three most critical.
The most critical is you have to be resilient. It is a hard job. You will have rough, unpleasant meetings sometimes with management. And you have to be resilient and you have to depersonalize these things. It’s really easy to go into a meeting and get the crap beat out of you because there was a disagreement and take it personally. Or you can go into it and not take it personally and come out of it and just figure out how you sort of go forward.
If you take it personally, you turn into a vegetable and want to go off and hide in the corner somewhere. So, I think besides communications, resilience is really critical.
I think you have to be really comfortable in making decisions in environments where you don’t necessarily have good data. All right, because where the CISO has to be at the top of the game is in a crisis.
And, in a crisis, you have to make decisions quickly, seldom with good data, and so having the courage of your convictions to make good decisions, make fast decisions, and then also understand that sometimes you messed up and you need to quickly recognize that and pivot. So, I’d say those are probably the most important. The technical stuff you can learn, but being resilient, being a good communicator, those are things that are a little bit more innate.
DR’s Kristina Beek: Yeah, that makes sense. You mentioned the technical stuff and in terms of people just first going into cybersecurity — not necessarily at the level of CISO — whether it be, you know, entry level professionals, whether it be somebody looking to pivot into cybersecurity, there are clearly a lot of different ways to go into cybersecurity. You mentioned that you had a college degree…
Charles Blauner: Computer science, which for my generation was rare, but today is pretty common.
DR’s Kristina Beek: What would you recommend as the best path for someone who wants to go into this field?
Charles Blauner: I’m going to give you a completely unsatisfying answer because there is no best path. For a couple of years I ran a workshop and the first session of it was always about career journeys, and then we would always bring in a bunch of diverse folks. And the key thing everyone got out of the session was, “Wow, there is no one path to becoming a CISO.”
The truth is that we talk about cybersecurity as if it’s sort of one big thing. But there are aspects of cybersecurity where it’s really helpful to be deeply technical. Like if you’re doing an engineering job, if you’re a pen tester, if you are growing up and becoming a security architect, right?
But there are other spaces that are completely non-technical. Like if you are a risk manager and you’re working with a business and you’re trying to help them assess what their risk posture looks like. That’s not a technical thing. That’s really a business smart sort of thing.
DR’s Kristina Beek: OK.
Charles Blauner: You could be an intel analyst, and again, a different set of skills. And so, there are lots of different kinds of cyber jobs that need lots of different kinds of skill sets. And there is no one right path to a CISO.
I think the majority of CISOs today are growing up more technical. But I don’t think that says you have to be deeply technical to actually be a great CISO.
DR’s Kristina Beek: You mentioned that there are a lot of different types of jobs and roles in cybersecurity. Naturally, I know a lot of people are probably concerned about the rise or prominence of AI. AI in and of itself may not be new. I know in the past you’ve mentioned it’s more large language models (LLMs) that are scaring people. What would you say to the people who are concerned about not having a job or maybe cybersecurity not having a place for them?
Charles Blauner: So, what I would say is really talented people will always have work, generally speaking. AI isn’t going to put cybersecurity as a thing out of business. It’s just going to change the things that we’re going to focus on and worry on. And it will take a lot of the really boring, mundane stuff in and automate the hell out of it. But the person who is sitting down with the business leader talking about their risk profile, the person who is really thinking about strategic architecture decisions and the like, the nature of jobs will change. But the need for security doesn’t change.
I mean, everyone talks about developers going away because of all the AI coding tools. Developers aren’t going away. All the AI coding tools have changed is the level of abstraction at which they’re doing their work.
The SOC isn’t going to go away.
But what AI tools allow is for the SOC people to be doing much more critical, interesting stuff because all of the management of understanding false positive, false negative — a lot of that boring stuff — the AI will do well.
They’ll still need a SOC. They’re just going to be doing much more interesting work.
DR’s Kristina Beek: Yeah. Absolutely. And on the topic of change in cybersecurity, we’re coming up on our time. So, this is my last question, and you can interpret this question however you’d like. What does the future of cybersecurity look like to you?
Charles Blauner: What I’ve said in the past, I’ll stay sort of consistent with.
We’ve had an evolution of the whole space from this idea of information security to cybersecurity.
But the real place it needs to really be in the long run is about operational resilience, business resilience. Where I envision the whole topic of cybersecurity evolving is into a broader conversation about operational resilience. And by the way, when you start to think about it in that way, one of the real advantages is you’re much more actually aligned to the business now. Because when you think about things from the perspective of operational resilience, your starting point is what are your critical business processes? How does the business actually serve its clients, carry out its mission?
CISOs who take that road map and start to be resilience leaders — with cyber being just a critical component of it — will be the ones that most naturally truly become business leaders.
DR’s Kristina Beek: Absolutely. Well, thank you so much for your time. I enjoyed this conversation. It was really great. And I know that this will be so beneficial for so many people. So, thank you so much.
Charles Blauner: It’s my pleasure. Have a great rest of your afternoon. Cheers.


