3 Types of Mentors Every CISO Needs

3 Types of Mentors Every CISO Needs

Quick answer: Every CISO needs three mentors, not one - a long-term mentor for career-level judgment, a tactical mentor for specific technical or vendor decisions, and a peer mentor working through the same stage at the same time. If any one of the three is missing, that is this week's task, not a someday task. Use the readiness checklist and vendor-evaluation criteria below if you are building this into a formal program.

David B. Cross, CISO and security leader, made a point at a CISOPlatform session that's easy to nod along to and hard to actually act on: every CISO needs three different types of mentors, not one.

 

The long-term mentor

 

This is someone who has known your career for years, who can speak to your growth pattern rather than a single decision. They are the person who remembers where you started and can tell you honestly whether you are actually progressing or just staying busy.

 

The tactical mentor

 

This is someone deep in the specific problem you are facing right now - a board presentation, a breach response, a budget fight. They may not know your whole career, but they have solved this exact problem recently and can save you months of trial and error.

 

The peer mentor

 

This is another CISO at a similar stage, dealing with similar pressures in real time. Not a senior advisor - a peer. Someone who validates that what you are experiencing is normal for the role, not a sign you are failing at it.

 

Why most CISOs only have one

 

Most security leaders default to whichever mentor type they found first, usually a senior executive who took an interest in their career, and stop there. That covers the long-term relationship but leaves the tactical and peer gaps unfilled - which is exactly when CISOs make avoidable mistakes on specific, solvable problems, or quietly burn out because they think their stress is unique to them.

 

Bikash Barai's addition: pay it forward

 

FireCompass co-founder Bikash Barai added a point that reframes mentorship as circular rather than one-directional: every CISO who has benefited from mentorship has an obligation to mentor someone earlier in their career. The community only compounds if senior leaders keep replenishing it, rather than only drawing from it.

Speaking of paying it forward: verified CISOPlatform members can redeem a free AI-powered pentest of their attack surface from FireCompass - a practical resource worth passing along to the mentee who is still building out their security program.

 

A question for the CISOPlatform community

 

Which of these three mentor types are you missing right now - and who in this community could fill that gap? Drop a comment below. This is exactly the kind of matching a community like this should be doing instead of leaving it to chance.

Do you actually need a new mentor right now? A self-assessment

  • Can you name, right now, who you'd call for each of the three roles - long-term, tactical, peer - without having to think about it?
  • Has it been more than six months since a substantive conversation with any of the three?
  • Are you making a decision about your role based on how you assume you should feel, rather than a peer confirming what's actually normal for the job?
  • Is the only feedback you get on your career trajectory coming from your own manager - who has an obvious stake in how you rate your own progress?
  • When you hit a specific, technical, high-stakes problem this year, did you have someone to call who had solved that exact problem recently - or did you solve it cold?

Two or more gaps here means you're not missing "a mentor" in the abstract - you're missing a specific one of the three types, and the fix is to go find that type specifically rather than default to whoever's available.

Questions to ask a prospective mentor before you start

  • What's your realistic availability - are we talking monthly calls, or ad hoc when something comes up?
  • Are you comfortable being direct and tactical, or do you tend toward general encouragement? (Useful to know which of the three types you're actually getting.)
  • Have you mentored a CISO or security leader before, and what did that relationship actually look like in practice?
  • What are your boundaries on confidentiality - what can and can't go further than this conversation?
  • What do you expect back from this relationship? Reciprocity doesn't have to be symmetric, but it should be named, not assumed.

If you're building a formal mentorship program: evaluation criteria for mentorship-matching or executive coaching vendors

CriterionWhat to look for
Matching methodologyTransparent criteria for pairing - not a black-box algorithm you cannot inspect
Coach/mentor vettingVerified experience specifically with security leadership roles, not generic executive coaching
Confidentiality policyWritten boundaries on what is and is not reported back to the organization
Outcome trackingSome measurable signal of program value beyond attendance - retention, promotion rate, satisfaction
Flexibility across the three typesSupports long-term, tactical, and peer matching separately rather than one generic "mentor" bucket
Cost modelClear per-participant or per-program pricing that scales with your team size

A simple tool: build your own mentor map

Three columns, one page: who is my long-term mentor, who is my tactical mentor for the problem I'm facing right now, who is my peer mentor - and a fourth column for who I am mentoring in return, per Bikash Barai's point about paying it forward. If any of the first three columns is empty, that's this week's task, not a someday task.

Related reading on CISO Platform

Votes: 0
E-mail me when people leave their comments –

Priyanka Aash is Co-Founder of CISO Platform, the world's first online community for information security executives, and Co-Founder of FireCompass. She has been nominated for the Cybersecurity Excellence Award for leadership and AI innovation in cybersecurity, honored with the NetApp Excellerate HER award, and featured in SC Media's Women in IT Security series. She is the author of The AI Divide. Security technologist Bruce Schneier advises FireCompass.

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion