A day in the life of a CISO extends well beyond security controls, covering business relationships, risk judgement, governance and organisational change.
At the 13th Security Edge, David Gee, Author, CISO and ADAPT Advisor, joined Maryam Bechtel, CISO at TAL Australia, and Keith Howard, CISO at Suncorp Group, to explore how security leaders can establish trust, focus investment on material risks and adapt governance as AI changes the operating environment.
Key takeaways:
- Build relationships before making major changes. Strong connections across technology, risk, finance, legal and the wider business give CISOs a clearer view of the organisation and stronger support during crises.
- Prioritise material risk over isolated compliance measures. Security investment should address risks that could genuinely affect the organisation rather than allowing procedural issues or maturity scores to drive priorities.
- Design AI governance for accountability and recovery. Define boundaries, observability, human oversight and recovery paths early, then keep testing as technology and organisational capability develop.
New CISOs need an independent view before changing the organisation
Understanding the organisation should come before major decisions about its security posture.
Keith recommends testing cultural fit and establishing relationships before the first day, including with the CIO, CRO, auditors and line-two risk teams.
Maryam extends that network across finance, legal, crisis management, communications and the wider business.
Those relationships provide critical support during incidents and help security leaders secure investment for risk reduction.
Independent reviews can then establish a more objective baseline.
Keith and Maryam advocate for a detailed assessment for practitioners alongside a clear, outcome-focused view for the board.
This gives leaders evidence about the organisation’s current position before major judgements or changes are made.
Material risk should guide security investment
Compliance, security and business enablement are connected responsibilities, but each serves a different purpose.
Keith distinguishes compliance from actual security posture.
Meeting a requirement does not remove the need to understand which threats could cause material harm to the organisation.
Maryam adds business enablement to the CISO mandate.
Some investments may have limited direct impact on compliance or risk reduction while still supporting the organisation’s ability to operate and innovate.
Materiality provides the prioritisation test.
Resources should concentrate on risks with meaningful organisational consequences rather than small procedural issues or a single maturity score.
AI governance needs accountability, recovery and continuous learning
Autonomous systems require clear boundaries around what they can do, how their actions are observed and who remains accountable.
Maryam’s framework centres on accountability, observability, boundaries, recoverability, and continuous testing and learning.
Keith reinforces the need to build those controls into the design, including recovery paths and human oversight before deployment.
People capability has to develop alongside those controls.
Teams need curiosity, resilience, comfort with ambiguity and a willingness to learn as the operating model changes.
Keith advocates practical workshops, time during working hours and collaboration with AI specialists to build confidence progressively.
Strong CISO leadership creates the relationships, feedback loops and learning practices that help the organisation make better decisions as conditions change.