<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CISO Talent Gap in Career Discussions</title>
    <link>https://community.isc2.org/t5/Career-Discussions/CISO-Talent-Gap/m-p/35932#M2612</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1590936133"&gt;@emb021&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;$2-3 million for a CISO??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yeah, I don't think so.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am a vCISO for several companies and I don't make 6 figures (tho I should), certainly nothing close to that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1590936133"&gt;@emb021&lt;/a&gt;&amp;nbsp;what's it like to be a vCISO? How much time do you need to dedicate to each client? Sounds like a cool gig&amp;nbsp;&lt;img id="smileyvery-happy" class="emoticon emoticon-smileyvery-happy" src="https://community.isc2.org/i/smilies/16x16_smiley-very-happy.png" alt="Smiley Very Happy" title="Smiley Very Happy" /&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 27 May 2020 04:09:31 GMT</pubDate>
    <dc:creator>AppDefects</dc:creator>
    <dc:date>2020-05-27T04:09:31Z</dc:date>
    <item>
      <title>CISO Talent Gap</title>
      <link>https://community.isc2.org/t5/Career-Discussions/CISO-Talent-Gap/m-p/35917#M2607</link>
      <description>&lt;P&gt;Do you have leadership aspirations? Want to become the next powerhouse CISO? This report is a MUST READ in order to learn the how to manage factors critical to success. The report examines the evolution of security management practices and the emergence of the "virtual CISO" for small and medium businesses. The report also suggests that CISO salaries are in the $2-3 million USD range (page 23), but that's not any of my friends...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://resources.kudelskisecurity.com/addressing-security-leadership-talent-gap" target="_blank" rel="noopener"&gt;CYBER BUSINESS EXECUTIVE&amp;nbsp;RESEARCH: SECURITY&amp;nbsp;LEADERSHIP TALENT GAP&amp;nbsp;Effective Strategies to Recruit, Retain, and Develop&amp;nbsp;CISO Talent in Challenging Times&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:32:01 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/CISO-Talent-Gap/m-p/35917#M2607</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2023-10-09T09:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: CISO Talent Gap</title>
      <link>https://community.isc2.org/t5/Career-Discussions/CISO-Talent-Gap/m-p/35927#M2611</link>
      <description>&lt;P&gt;$2-3 million for a CISO??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yeah, I don't think so.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am a vCISO for several companies and I don't make 6 figures (tho I should), certainly nothing close to that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 15:21:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/CISO-Talent-Gap/m-p/35927#M2611</guid>
      <dc:creator>emb021</dc:creator>
      <dc:date>2020-05-26T15:21:16Z</dc:date>
    </item>
    <item>
      <title>Re: CISO Talent Gap</title>
      <link>https://community.isc2.org/t5/Career-Discussions/CISO-Talent-Gap/m-p/35932#M2612</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1590936133"&gt;@emb021&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;$2-3 million for a CISO??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yeah, I don't think so.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am a vCISO for several companies and I don't make 6 figures (tho I should), certainly nothing close to that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1590936133"&gt;@emb021&lt;/a&gt;&amp;nbsp;what's it like to be a vCISO? How much time do you need to dedicate to each client? Sounds like a cool gig&amp;nbsp;&lt;img id="smileyvery-happy" class="emoticon emoticon-smileyvery-happy" src="https://community.isc2.org/i/smilies/16x16_smiley-very-happy.png" alt="Smiley Very Happy" title="Smiley Very Happy" /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 04:09:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/CISO-Talent-Gap/m-p/35932#M2612</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2020-05-27T04:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: CISO Talent Gap</title>
      <link>https://community.isc2.org/t5/Career-Discussions/CISO-Talent-Gap/m-p/35938#M2613</link>
      <description>&lt;P&gt;As a virtual CISO myself I have been assigned to a single agency (5000+ employees) and currently assigned to two smaller agencies (1- ~100 employees, 2- ~250 employees) and can tell you there are pluses and minuses with each assignment. When I was at the larger agency I had more control of every detail of security from deciding direction to leading the cyber program. At the smaller agencies it is more of policy creation and guidance role.&lt;/P&gt;&lt;P&gt;The big negative is that you are sometimes treated like a contract employee (which I guess you technically are) and sometimes not given complete access or control needed to do the job.&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 14:51:03 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/CISO-Talent-Gap/m-p/35938#M2613</guid>
      <dc:creator>CISOScott</dc:creator>
      <dc:date>2020-05-27T14:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: CISO Talent Gap</title>
      <link>https://community.isc2.org/t5/Career-Discussions/CISO-Talent-Gap/m-p/51023#M3436</link>
      <description>&lt;P&gt;Nice report, however, it seems to be more of a marketing material being released by a cybersecurity firm providing such services.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2022 15:05:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/CISO-Talent-Gap/m-p/51023#M3436</guid>
      <dc:creator>crycos</dc:creator>
      <dc:date>2022-05-17T15:05:54Z</dc:date>
    </item>
    <item>
      <title>Re: CISO Talent Gap</title>
      <link>https://community.isc2.org/t5/Career-Discussions/CISO-Talent-Gap/m-p/51030#M3437</link>
      <description>The time is based on the contract we had with each client. Usually so many hours per month. This was taken up by regular meetings I had with the client to go over things, checking to make sure things were operating smoothly.&lt;BR /&gt;&lt;BR /&gt;Now, depending on the client, I spent more time with them at the beginning of the engagement because I was often focused on either developing or improving policies and procedures, and getting them put into place. Part of that is making sure controls are in place and that evidence is being gathered on a regular basis. There are many activities that need to done on a regular basis (annual, quarterly, monthly, bi-monthly, weekly, etc). This is especially important for companies who must maintain HITRUST, SOC, PCI, ISO27001, etc.&lt;BR /&gt;What is frustrating is what happens when client X is in a crisis and this impacts the time I would spend with client A, B, and C? I had one client hit by ransomware and I had to help them out, but this impacted me in regards to the time I was spending with another client who needed me to help them prep for SOC 2.</description>
      <pubDate>Tue, 17 May 2022 18:03:07 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/CISO-Talent-Gap/m-p/51030#M3437</guid>
      <dc:creator>emb021</dc:creator>
      <dc:date>2022-05-17T18:03:07Z</dc:date>
    </item>
  </channel>
</rss>

