Coaching for CISOs and security leaders
The pressures that burn out security leaders are rarely technical. I coach CISOs and senior security leaders through decision load, board scrutiny and unsustainable pace, drawing on the years I've spent in the seat myself.
The job, not the stack
Most security leaders I work with already know the frameworks. The strain sits in the decisions, the boardroom, and the pace — not in a missing control.
Decision fatigue
You are the last stop on every material risk call. The volume does not drop; the quality of those calls is what the organisation remembers. Coaching here is about judgement under load — what you decide, what you defer, and what you refuse to carry alone.
Board scrutiny
Directors want a clear account of risk, investment and residual exposure. They do not want a tour of the toolset. We work on presence, evidence, and the conversation that holds when the questions are sharp.
Unsustainable pace
Incident load, regulator interest, and a change agenda that never quite closes. Tenure suffers when the operating rhythm has no recovery. We rebuild a cadence you can still be in the role to execute.
1:1 executive coaching
A confidential working relationship for sitting, newly appointed, and incoming CISOs. Self-funded or employer-sponsored. Paced to a role that does not pause for development activity.
Who it is for
- CISOs and Heads of Security in growing medium-sized businesses, enterprise, or government
- Leaders in the first 18 months of the role, when board exposure and isolation peak
- Senior security leaders being prepared for the CISO seat
- Sponsored engagements where the organisation wants the leader to last
What it addresses
- Decision fatigue — what you own, what you escalate, what you stop doing
- Board and executive conversations that have to land the first time
- Pace, recovery, and the habits that keep tenure viable
- Isolation of the role: few peers inside the organisation can be used as a sounding board
Cadence
Typically fortnightly sessions of 60–90 minutes, over an initial 6–12 months. Adjusted when incident load makes a slot impossible — the relationship does not punish the job.
Format
Sessions are delivered by video. Between sessions: a short written recap and one or two agreed actions. No platform, no app, no group theatre unless you ask for it.
Commercials
Self-funded or employer-sponsored. Pricing is on application after an introductory call. I will not quote a package before I understand the role.
Organisational engagements
Security leadership work, sold the way consulting is sold. Scoped against an outcome, delivered to a team or a newly appointed leader, and closed with something the organisation can use.
This is often the help a growing medium-sized business needs: a newly appointed security leader, a stretched leadership bench, or a culture gap the board or executive team can now see. The same engagements run in enterprise and government.
Board-readiness
For a newly appointed CISO or security lead. Structured preparation for the first board cycle: the narrative, the metrics, and the questions that will actually be asked.
Leadership bench
Development for the managers under the CISO — the people who will either multiply the function or leak every decision back upstairs.
Security culture
Programs that change how the organisation takes and talks about cyber risk. Built around behaviour and decision rights, not posters.
Discovery
A short, paid scoping conversation with the sponsor and the leader in the seat. We agree the outcome, the constraints, and who is in the room.
Delivery
A defined series of workshops, 1:1s, or a board-readiness block. Cadence is set in the statement of work — typically over 8–16 weeks, not an open retainer without a purpose.
Close
A written account of what changed, what remains, and what the sponsor should watch. Pricing is on application.
How I work
Sustainable leadership performance, not a personal-growth curriculum. The work sits on two pillars — Self Mastery and Professional Mastery — held together by ethics, values and culture. I use it because the operating job fails when only one side is developed.
Self Mastery
The conditions that keep a security leader fit to decide.
Self-esteem
Decisions that still hold when the room is hostile. Grounded confidence, not performance.
Emotional regulation
Staying usable in incidents and board sessions — reading the room, and your own state, without leaking it into the decision.
Capacity and recovery
The operating rhythm that prevents burnout. Recovery is treated as leadership infrastructure, not a personal hobby.
Repeatable habits
Cadence you can sustain across a multi-year tenure: how you prepare, decide, brief, and close loops.
Professional Mastery
The craft the organisation can see.
Collaboration
Getting technology, risk, legal, operations and the business into the same decision without diluting accountability.
Critical thinking
Separating signal from vendor noise. Choosing the few moves that change residual risk.
Communication
Translating complexity into a board-usable account of risk, investment and residual exposure.
Managing priorities
Holding urgent incident work and important program work in the same week without letting one consume the other.
Ethics · Values · Culture
These sit at the centre. Technical mastery without them is a liability. Self Mastery without them is theatre.
The role is the curriculum
We work live issues: the board paper, the hire, the incident wash-up, the conversation you have been postponing.
Confidential by default
1:1 work is not reported back to the organisation unless you set that as a condition of sponsorship.
No theatre
I will not add a framework you already have. If the need is technical consulting, I will say so.
Coaching credentials
Certificate IV in Mentoring and Coaching (Global Coaching Academy, 2010), built on ICF core competencies. More than 500 hours of individual and group coaching delivered. ICF member; currently pursuing ICF credentials.
Pricing is on application.
