Quick answer: Every CISO needs three mentors, not one - a long-term mentor for career-level judgment, a tactical mentor for specific technical or vendor decisions, and a peer mentor working through the same stage at the same time. If any one of the three is missing, that is this week's task, not a someday task. Use the readiness checklist and vendor-evaluation criteria below if you are building this into a formal program.
David B. Cross, CISO and security leader, made a point at a CISOPlatform session that's easy to nod along to and hard to actually act on: every CISO needs three different types of mentors, not one.
The long-term mentor
This is someone who has known your career for years, who can speak to your growth pattern rather than a single decision. They are the person who remembers where you started and can tell you honestly whether you are actually progressing or just staying busy.
The tactical mentor
This is someone deep in the specific problem you are facing right now - a board presentation, a breach response, a budget fight. They may not know your whole career, but they have solved this exact problem recently and can save you months of trial and error.
The peer mentor
This is another CISO at a similar stage, dealing with similar pressures in real time. Not a senior advisor - a peer. Someone who validates that what you are experiencing is normal for the role, not a sign you are failing at it.
Why most CISOs only have one
Most security leaders default to whichever mentor type they found first, usually a senior executive who took an interest in their career, and stop there. That covers the long-term relationship but leaves the tactical and peer gaps unfilled - which is exactly when CISOs make avoidable mistakes on specific, solvable problems, or quietly burn out because they think their stress is unique to them.
Bikash Barai's addition: pay it forward
FireCompass co-founder Bikash Barai added a point that reframes mentorship as circular rather than one-directional: every CISO who has benefited from mentorship has an obligation to mentor someone earlier in their career. The community only compounds if senior leaders keep replenishing it, rather than only drawing from it.
Speaking of paying it forward: verified CISOPlatform members can redeem a free AI-powered pentest of their attack surface from FireCompass - a practical resource worth passing along to the mentee who is still building out their security program.
A question for the CISOPlatform community
Which of these three mentor types are you missing right now - and who in this community could fill that gap? Drop a comment below. This is exactly the kind of matching a community like this should be doing instead of leaving it to chance.
Do you actually need a new mentor right now? A self-assessment
- Can you name, right now, who you'd call for each of the three roles - long-term, tactical, peer - without having to think about it?
- Has it been more than six months since a substantive conversation with any of the three?
- Are you making a decision about your role based on how you assume you should feel, rather than a peer confirming what's actually normal for the job?
- Is the only feedback you get on your career trajectory coming from your own manager - who has an obvious stake in how you rate your own progress?
- When you hit a specific, technical, high-stakes problem this year, did you have someone to call who had solved that exact problem recently - or did you solve it cold?
Two or more gaps here means you're not missing "a mentor" in the abstract - you're missing a specific one of the three types, and the fix is to go find that type specifically rather than default to whoever's available.
Questions to ask a prospective mentor before you start
- What's your realistic availability - are we talking monthly calls, or ad hoc when something comes up?
- Are you comfortable being direct and tactical, or do you tend toward general encouragement? (Useful to know which of the three types you're actually getting.)
- Have you mentored a CISO or security leader before, and what did that relationship actually look like in practice?
- What are your boundaries on confidentiality - what can and can't go further than this conversation?
- What do you expect back from this relationship? Reciprocity doesn't have to be symmetric, but it should be named, not assumed.
If you're building a formal mentorship program: evaluation criteria for mentorship-matching or executive coaching vendors
| Criterion | What to look for |
|---|---|
| Matching methodology | Transparent criteria for pairing - not a black-box algorithm you cannot inspect |
| Coach/mentor vetting | Verified experience specifically with security leadership roles, not generic executive coaching |
| Confidentiality policy | Written boundaries on what is and is not reported back to the organization |
| Outcome tracking | Some measurable signal of program value beyond attendance - retention, promotion rate, satisfaction |
| Flexibility across the three types | Supports long-term, tactical, and peer matching separately rather than one generic "mentor" bucket |
| Cost model | Clear per-participant or per-program pricing that scales with your team size |
A simple tool: build your own mentor map
Three columns, one page: who is my long-term mentor, who is my tactical mentor for the problem I'm facing right now, who is my peer mentor - and a fourth column for who I am mentoring in return, per Bikash Barai's point about paying it forward. If any of the first three columns is empty, that's this week's task, not a someday task.
Related reading on CISO Platform
- Continuous Penetration Testing in the AI Era: What Bruce Schneier Told Us
- CISO Personal Liability After SolarWinds: What the Community Actually Thinks
- AI Agent Governance: The Checklist a Room Full of CISOs Actually Agreed On
- Is Your AI a Trusted Advisor or an Untrusted One? A Governance Checklist
- Penetration Testing as a Service (PTaaS): A 2026 Buyer's Guide
- DORA Threat-Led Penetration Testing (TLPT): A CISO's Compliance Guide
- OWASP Top 10 for Agentic Applications (2026): How to Actually Test AI Agents

Comments