The CISO resume,
and the claim that proves nothing.
Most CISO records lead with an absence. No breach, no material incident, no adverse finding. An absence is not evidence. It is the sentence a leader with no controls and good luck would also write. The reader's question is narrower: when something did happen, how quickly did you know, and who did you tell?
What gets read first
Two readers open a CISO record with different questions. The audit committee chair wants to know whether the organisation is governable: whether risk is quantified, reported, and owned somewhere other than your desk. The chief executive wants to know whether you will slow the business down. The first screen has to answer both. Most answer neither.
What settles it early is the perimeter of the job. Whose security was it: a single regulated entity, a group with autonomous subsidiaries, a platform holding customer data under contract? Then the operating facts. Budget and headcount. Whether the security operations centre was yours or a vendor's. Whether you reported to the board or through someone who summarised you.
The estate and its regulatory character: entities, jurisdictions, data classes held, and which regimes actually applied — DPDP, GDPR, HIPAA, PCI DSS, DORA, sectoral rules.
Budget and headcount, split between run and change. A large budget that is entirely licence renewal describes a different leader from one that funded a build.
Reporting line and board cadence. A standing quarterly item at the audit committee, with your own agenda slot, is the structural fact that separates a CISO from a head of security.
Whether you held the risk-acceptance pen or drafted for someone who did. Boards read this immediately and it is almost never on the page.
The numbers that carry weight
Security has better telemetry than most functions and publishes the least of it, usually on confidentiality grounds that do not survive contact with a redaction. Ranges, directions of travel and dates are almost always disclosable. Precision about the trend matters more than precision about any one incident.
Mean time to detect and mean time to contain, stated as a pair with the starting position. Detection alone is a monitoring claim; the two together describe an operating capability.
Certification outcomes with dates and scope: ISO 27001 certification or recertification, SOC 2 Type II with its observation window, and the count of major non-conformities. Scope is where these claims inflate, so stating it is itself a credibility move.
Regulatory or internal audit findings closed, with their age when you inherited them. Closing a four-year-old high-severity finding is a harder claim than closing ten new ones, and an audit committee reads it that way.
Phishing susceptibility as a trend across repeated tests, not a single result. One campaign is a data point; four quarters at rising difficulty is a programme.
Third-party risk coverage: the share of critical suppliers assessed, reassessed on cycle, and contractually bound to notify. Supply-chain exposure is the risk boards ask about most and CISO records address least.
Budget won and what it bought, tied to a risk you had quantified first. A 40% budget increase is a political claim. Quantifying privileged-access exposure, taking it to the audit committee, and funding an identity programme that removed standing admin rights is a control claim.
Where CISO profiles go quiet
Three sentences appear in most CISO records. Each makes a claim the reader cannot verify, and each has a verifiable version that is stronger.
“No breach on my watch.” Unverifiable, and it credits luck as readily as control. The stronger version is an incident you did handle: its class, how you found it, how long containment took, and what you changed afterwards so it could not recur the same way.
“Built a security-aware culture.” Training completion is an attendance record, not a behaviour. Report susceptibility and reporting rate together. The share of staff who actively report a suspicious message is the figure that shows the culture works.
“Aligned the programme to NIST CSF or ISO 27001.” Alignment is a filing status. State the maturity assessment, who ran it, the score when you arrived, the score when you left, and the two domains you deliberately left alone because the risk did not justify the spend.
Three lines, rewritten.
The same fact, made checkable. Every figure is illustrative of the shape an evidenced line takes — nothing here is invented on your behalf.
The claim on the left is not wrong. It is simply unreadable as evidence: nothing in it can be checked, compared or priced. The version on the right makes the same statement in a form a search partner can act on.
Managed the response to several security incidents with no material impact to the business.
Led response to a business email compromise affecting 14 mailboxes: detected by an internal reporting rule within two hours, contained the same day, regulator notified inside the 72-hour window on documented advice, and the vector closed by enforcing conditional access across the estate within six weeks.
Achieved ISO 27001 certification for the organisation.
Took the group through ISO 27001:2022 certification in nine months, covering three legal entities and two data centres, with two minor non-conformities and no majors, then held that scope through the first surveillance audit.
Strengthened third-party risk management and vendor due diligence processes.
Assessed 240 suppliers, tiered them by data access rather than by spend, and moved critical-tier assessment coverage from 31% to 100% in 14 months, with breach-notification clauses in 88% of critical contracts at renewal, from a base of none.