I can't listen to CISO podcasts anymore
Yesterday I started one, I cut it off after eight minutes. I already knew everything. And the worst part is that I know exactly why it's like this, because I'm often on the other side of the mic, being a CISO myself.

Yesterday I started one, I cut it off after eight minutes. I already knew everything. And the worst part is that I know exactly why it's like this, because I'm often on the other side of the mic.
Why do CISO podcasts all sound alike?
I can't listen to them anymore. Yesterday, a CISO podcast crossed my path, I hit play, and after a few minutes I cut it off. Not because the person was bad, I have no idea, actually. Because I already knew every answer before it came. Security that supports the business without slowing it down, integration as early as possible, secure by default, AI that assists without replacing, with a human somewhere in the loop, and the inevitable inflection point where we would all be. Eighteen years I've been doing this job, and I've been hearing this same script word for word for eighteen years.
"Keep it light, keep it educational": the brief before recording
The thing is, I know where it comes from. I'm on the other side of the mic more often than my fair share, I get booked for these formats. And there's always, before recording, that moment where they send you the questions in advance and slip in that it'll be light, educational, that you need to stay accessible. In plain terms, don't say anything that might upset the sponsor whose logo will appear at the end. Nobody is stupid in this story. Everyone is afraid, and everyone has good reasons to be afraid.
What does a CISO who speaks frankly really risk?
Because the day a CISO says something precise and true, a flaw he chose to leave open for lack of resources, a budget he was denied, a company he left because he was being asked to sign what he didn't want to sign, he hands out ammunition. To a lawyer, to a board of directors, to a future recruiter who will type his name into Google. The hollow line, at least, never turns back on him. I understand the calculation, and I find it dispiriting.
That lawyer's letter is not a figure of speech. In October 2022, Joe Sullivan, the former security chief of Uber, became the first security officer criminally convicted for covering up a data breach; he was handed three years of probation, a fine of 50,000 dollars and two hundred hours of community service. A year later, in October 2023, the US SEC charged SolarWinds CISO Tim Brown by name, a first for a security director pursued personally over his public statements. The courts eventually took apart most of the case, the SEC dropping its last charges in November 2025, but the message had already landed: what you say about your security can be turned against you, under oath.
The numbers say the rest. In Proofpoint's Voice of the CISO 2024 barometer, 61% of UK security leaders reported being worried about personal liability, and 67% would refuse a role without directors and officers insurance. A BlackFog survey from late 2024 goes further: 70% of the security decision-makers questioned say that cases like SolarWinds have worsened their view of the profession, and a third see it as a no-win situation, penalised internally if they flag a flaw, prosecuted externally if they keep quiet about it. Faced with these figures, it is hard to blame a CISO for being cautious.
I hand out ammunition every time, and I do it on purpose
Me, I hand out ammunition every time, and I do it on purpose. Sometimes I answer beside the easy question, I say in front of a room that some framework everyone praises is useless in the context we're talking about, I recount a decision I only half stand behind. And every time it's the same mechanics, the room cooling off, the moderator moving on a little too quickly, and three days later the comment explaining that I'm too negative, not constructive enough. I don't get re-invited everywhere, and I do without.
Only, let's be honest about what it costs me. I'm a CISO, so I carry that risk like the others, the seat, the board, the lawyer's letter that sometimes ends up arriving. But I'm not only that. I train, I audit, I write, I advise elsewhere. When I say something disruptive, I'm not betting everything on a single square, and it's that spread that buys me a measure of my freedom of tone, not some kind of courage. The CISO whose sole job, sole employer, sole income this is, he risks far more on a single sentence. I'm not going to pretend we're in the same boat.
Does the problem come from a lack of individual courage?
Because the real problem isn't individual. It isn't a story of the brave on one side and the cowardly on the other. The people best placed to say useful things, those who are in the seat, in the thick of the decision, with all the context, are precisely the ones the ecosystem has taught to keep quiet. Legal, marketing, the sponsor, employer branding, career caution, all of it filters the message until it no longer teaches anyone anything. In the end, there isn't a crowd of mediocre chatterers facing a silent elite. There's an entire discipline that has made speaking truthfully costly, and then acts surprised that its conferences put everyone to sleep.
Why I'll never make a good podcast guest
So no, I'll never make a good podcast guest. Not out of bravery, I've just explained that my freedom of tone comes above all from the fact that I'm not betting everything on a single seat. Simply, I have no reassuring formula to slot in before the credits, and I trip up too often in public to keep up the pretense. Yesterday's episode, I cut it off after eight minutes. It's probably the most honest thing I did all day.
Sources
- Conviction of Joe Sullivan, former Uber CSO, for covering up a data breach: SecurityWeek, May 2023.
- SEC charges against SolarWinds CISO Tim Brown, then dismissal of the remaining claims in November 2025: Jones Day, December 2025 and Harvard Law School Forum on Corporate Governance, December 2025.
- Concern over personal liability, directors and officers insurance and burnout: Proofpoint's Voice of the CISO 2024 barometer, via Raconteur, July 2024.
- Effect of prosecutions on perception of the role and the "no-win situation": BlackFog survey, via Security Boulevard, December 2024.
Frequently asked questions
Why can't the author listen to CISO podcasts anymore?
Because he already knows every answer before it comes: security that supports the business, secure by default, AI that assists without replacing. After eighteen years in the job, he hears this same script word for word.
Why is the CISO message so bland?
Before recording, the questions are sent in advance and you're asked to stay light and accessible, meaning to say nothing that might upset the sponsor. Everyone is afraid, and everyone has good reasons to be afraid.
What does a CISO risk by speaking frankly?
A precise and true remark can turn back on him with a lawyer, a board of directors or a recruiter. The hollow line, on the other hand, never turns back on whoever says it.
Can a CISO be prosecuted personally after a data breach?
Yes, and there are precedents. In 2022, former Uber security chief Joe Sullivan was criminally convicted for covering up a breach, and in 2023 the US SEC charged SolarWinds CISO Tim Brown by name over his public statements. The charges against him were dropped in late 2025, but the precedent remains.
Does fear of personal liability push CISOs into silence?
Surveys suggest so. In 2024, 61% of UK security leaders said they were worried about personal liability according to Proofpoint, and 70% felt, according to BlackFog, that cases like SolarWinds had worsened their view of the role. A third see it as a no-win situation.
Does the problem come from a lack of individual courage?
No. The author believes this isn't a story of the brave and the cowardly, but an entire discipline that has made speaking truthfully costly, then acts surprised that its conferences put everyone to sleep.
Why does the author allow himself a freer tone?
Because he doesn't depend on a single seat: he trains, audits, writes and advises elsewhere. That spread buys him a measure of freedom of tone, which he clearly distinguishes from courage.

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
