NuHarbor Security
  • Solutions
    Solutions
    Custom cybersecurity solutions that meet you where you are.
    • Overview
    • Our Approach
    • Data Icon Resources
    • Consultation Icon Consult with an expert
    • By Business Need
      • Identify Gaps in My Cybersecurity Plan
      • Detect and Respond to Threats in My Environment
      • Fulfill Compliance Assessments and Requirements
      • Verify Security With Expert-Led Testing
      • Manage Complex Cybersecurity Technologies
      • Security Monitoring With Splunk
    • By Industry
      • State & Local Government
      • Higher Education
      • Federal
      • Finance
      • Healthcare
      • Insurance
    Report 2023-2024 SLED Cybersecurity Priorities Report
    2023-2024 SLED Cybersecurity Priorities Report
    Read Report
  • Services
    Services
    Outcomes you want from a team of experts you can trust.
    • Overview
    • Data Icon Resources
    • Consultation Icon Consult with an expert
    • Security Testing
      • Penetration Testing
      • Application Penetration Testing
      • Vulnerability Scanning
      • Wireless Penetration Testing
      • Internal Penetration Testing
      • External Penetration Testing
    • Assessment & Compliance
      • CMMC Compliance
      • NIST 800-53
      • HIPAA Security Standards
      • ISO 27001
      • MARS-E Security Standards
      • New York Cybersecurity (23 NYCRR 500)
      • Payment Card Industry (PCI)
    • Advisory & Planning
      • Security Strategy
      • Incident Response Planning
      • Security Program Reviews
      • Security Risk Assessments
      • Virtual CISO
      • Policy Review
    • Managed Services
      • Curated Threat Intelligence
      • Managed Detection and Response (MDR)
      • Sentinel Managed Extended Detection and Response (MXDR)
      • SOC as a Service
      • Splunk Managed Services
      • Tenable Managed Services
      • Vendor Security Assessments
      • Vulnerability Management
      • Zscaler Support Services
    Report 2023-2024 SLED Cybersecurity Priorities Report
    2023-2024 SLED Cybersecurity Priorities Report
    Read Report
  • Partners
  • Resources
    Resources
    Explore reports, webinars, case studies, and more.
    • Browse Resources
    • Consultation Icon Consult with an expert
    • Blog icon Blog
    • Podcast icon Podcast
    • Annual SLED CPR icon Annual SLED CPR
    • Downloadable Assets icon Downloadable Assets
    Report 2023-2024 SLED Cybersecurity Priorities Report
    2023-2024 SLED Cybersecurity Priorities Report
    Read Report
  • Company
    Company
    We do cybersecurity differently – the right way.
    • Overview
    • Data Icon Resources
    • Consultation Icon Consult with an expert
    • Leadership
    • News
    • Careers
    • Contact
    Report 2023-2024 SLED Cybersecurity Priorities Report
    2023-2024 SLED Cybersecurity Priorities Report
    Read Report
  • Consult with an expert
  • Client support
  • Careers
  • Contact
1.800.917.5719
NuHarbor Security Blog
    • Compliance
    • Cybersecurity Technology
    • Security Operations
    • Industry Insights
    • Security Testing
    • Advisory and Planning
    • Application Security
    • Managed Detection and Response
    • Threat Intelligence
    • NuHarbor
    • Managed Services
    • Cyber Talent
August 20, 2014

Why your CISO needs to be the best sales person in your company

Justin Fimlaid Justin Fimlaid

I read an article today that really hit home and prompted to me hit the blog post. The article was in Security Week titled "How a CISO Can Be a Change Agent Within a Company" written by Mark Hatton.v It's great article, and very true--Mark made some great points.

One statistic in the article made me stop and think, "the average tenure of a CISO is 22 months."v There was no support for this statistic.v I "googled" a bit to see if I could find some support for the metric and found a few rough numbers but nothing concrete.v The interesting thing about this number is that I believe the number is true without the statistic support I was looking for.v I've been a CISO for a large international company and there was times it was miserable, I'll spare the dirty details.v Based on my personal experience 22 months feels about right.

My lesson learned is this, in order for security to thrive the C(I)SO needs to be the best sales person in the company and this sales job is the most important sales position for shareholder value.v As Mark Hatton mentions in his article about a positive perception, a C(I)SO job is about the popularity of the person holding the role in that they need to be a respected advisor and be able to talk freely about risk without being run out of the conference roomvwith torches and pitch forks by C-Level staff.v In sales it's a hard thing to establish trust and rapport, then you need to either create a need for your product or convince your executive team they need the product you are selling, then you need to close the sale.v Once all this is done, you need to rinse and repeat.

Here's the realism.v If the C(I)SO fails in their sales effort and the need was valid (i.e. a data breach follows), the actual loss is MUCH more severe than the lost opportunity or the incremental cents per share add to the bottom line--the entire revenue stream is now at risk and the entire per share value is at risk OR future earnings might be at risk is Intellectual Property is lost.v C(I)SO's (and security teams) help protect the continuity of the business revenue stream and keep customers coming back to your company versus the competitor.v The C(I)SO job is important, and intelligently applying security controls and architecting secure solutions that help your business innovate and enable your business for future growth.

Security teams can enable your business.v No one in the business is better positioned than a Security team to develop and create information platforms for business innovation while reducing risk of data or financial loss. C(I)SO's need to create a mutually beneficial value proposition for their companies.

In the words of Zig Ziglar "You will get all you want in life, if you help enough other people get what they want.”

Included Topics

  • Compliance
Justin Fimlaid
Justin Fimlaid

Justin (he/him) is the founder and CEO of NuHarbor Security, where he continues to advance modern integrated cybersecurity services. He has over 20 years of cybersecurity experience, much of it earned while leading security efforts for multinational corporations, most recently serving as global CISO at Keurig Green Mountain Coffee. Justin serves multiple local organizations in the public interest, including his board membership at Champlain College.

Related Posts

Industry Insights 5 min read
The Center of Security Operations Is Your Data, Not Your SOC
Read More
5 min read
How Can Infrastructure Penetration Testing Help Your Business? Read More
Security Testing 2 min read
How Vendor (3rd Party) Security Assessments Can Help You Build a Better Security Program Read More

Subscribe via Email

Subscribe to our blog to get insights sent directly to your inbox.

Subscribe Here!

Latest Pwned episodes

Episode 200 - Reflections of Pwned...Until Next Time
April 03, 2024
Episode 200 - Reflections of Pwned...Until Next Time
Listen Now
Episode 199 - When a BlackCat Crosses Your Path...
March 21, 2024
Episode 199 - When a BlackCat Crosses Your Path...
Listen Now
Episode 198 - Heard it Through the Grapevine - Beyond the Beltway, 2024
March 08, 2024
Episode 198 - Heard it Through the Grapevine - Beyond the Beltway, 2024
Listen Now
NuHarbor Security logo
NuHarbor Security

553 Roosevelt Highway
Colchester, VT 05446

1.800.917.5719

  • Solutions
  • Services
  • Partners
  • Resources
  • Company
  • Contact
  • Privacy Policy
Connect
  • Twitter
  • Linkedin
  • YouTube
©2025 NuHarbor Security. All rights reserved.