CISO Executive Development and Coaching

Illustration of directional road sign

CISO Development: Training vs Coach

July 31, 20252 min read

Originally posted December 13, 2024; last revised July 13, 2026

CISO roles seldom fail because the CISO lacked information. More often, the constraint is how the CISO operates when information alone is not enough.

Where knowledge stops being the problem

Key moments in a CISO’s work typically do not break because a framework was unknown:

  • Budget conversations stall even when the business case is sound.

  • Board discussions drift or harden despite clear metrics and narrative.

  • Major incidents damage trust even when response plans are followed.

In these situations, the constraint is not more slides or more courses. It is how the CISO uses what is already known: how uncertainty is presented, how resistance is handled, and how confidence is built or eroded in the room.

The issue is not whether the CISO understands risk. It is whether that understanding can be translated into judgment, influence, and action under pressure.

Coaching works on the executive

Executive coaching focuses on:

  • Live executive situations: upcoming board meetings, strategic negotiations, leadership changes, and cross-functional conflict.

  • The CISO’s patterns under stress: tendencies to over-explain, narrow into technical detail, avoid confrontation, or over-accommodate.

  • Intentional behavioral change: alternative ways to frame risk, ask for support, and respond to opposition, tested and refined over repeated cycles.

The return does not come from adding more information. It comes from changes in how the CISO exercises judgment, responds under pressure, and works through other executives.

Those changes affect decisions, relationships, and outcomes well beyond the immediate situation.

Where development investment shifts

Training spend usually improves capability down the organization: stronger teams, more consistent execution, and greater process maturity.

Coaching spend acts across and up: on influence with the CEO and board, the ability to secure and sustain support, and the resilience of trust when events go poorly.

Under-investing in either has consequences. Weak technical depth undermines the program. Weak executive capacity leaves the CISO dependent on unexamined habits and ad hoc learning in the most consequential parts of the executive portion of the role.

A useful lens for any CISO or executive sponsor:

  • If training spend increases, will board confidence in security leadership rise at the same rate?

  • If the CISO’s executive capacity improves meaningfully, what changes over the next several board cycles, major initiatives, and incidents?

In many organizations, training is established and budgeted. CISO-specific executive coaching remains underused relative to the visibility and risk profile of the role.

What kind of problem is this?

The dividing line is practical.

Knowledge, process, and team capability call for training.

Stalled board support, tense peer relationships, and fragile trust following incidents point to a different problem.

The security program may be technically sound. The question is whether the CISO can secure, retain, and exercise the authority required to lead it effectively.

CISO trainingexecutive coachingleadership developmentrisk managementbusiness integrationCISO growthinformation security
blog author image

Chris Brown

Chris Brown, Executive Coach to CISOs, and CEO of New Cyber Executive

Back to Blog