logo

A Tale of Two CISOs: Why An Engineering-Focused CISO Can Be a Liability

ID: d52485ac-bc60-53ef-bd54-52fc6ed6ac94

STIX ID: report--d52485ac-bc60-53ef-bd54-52fc6ed6ac94

Feed Name: Dark Reading

Date Published: 2025-12-04

Date Updated: 2026-04-21

Author: David Schwed

...
...

This article contrasts an "engineer" CISO—who treats security primarily as an engineering problem focused on preventative technical controls—with a "holistic" CISO who integrates people, process, and technology to build resilience; it warns that engineering-only approaches can simply move risk into less-observed areas (build pipelines, glue code, human workflows) and cites incidents like the Bybit theft and AI supply-chain/prompt-injection risks as illustrations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.