From Unusual Path to the Top: What Tarah Wheeler's Career Tells Us About Who Gets to Lead in Cybersecurity

Tarah Wheeler is CISO at TPO Group, a firm advising organisations where security failures carry real-world consequences. Her route there looked nothing like the standard playbook.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: The room is dimly lit with cool blue ambient
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Tarah Wheeler holds the role of Chief Information Security Officer (CISO) at TPO Group, a cybersecurity consultancy.
  • TPO Group works with organisations where security failures carry serious, real-world consequences.
  • Wheeler's path to that role did not follow the conventional career ladder most senior security leaders climb.
  • Her story raises pointed questions about who the security industry recruits and promotes.

A Chief Information Security Officer, or CISO, is the most senior person responsible for keeping an organisation's systems and data safe. It's a title that usually follows decades of narrowly technical work. Tarah Wheeler's story, reported by SecurityWeek, complicates that picture.

Wheeler is the CISO at TPO Group, a consultancy hired by organisations where a breach could mean something worse than a damaged share price. Hospitals, critical infrastructure operators. Government-adjacent bodies. The stakes aren't abstract.

Her background broke from the expected mould.

How do people usually reach this level, and why does Wheeler's path matter?

Most CISOs arrive through a tight corridor: computer science degree, network engineering, then a climb through security operations. Wheeler didn't take that corridor. Her route was wider and less linear, drawing on policy work, research, and public advocacy alongside technical practice.

That matters for two reasons.

First, the skills a top security leader actually needs, communicating risk to a board, reading regulators, modelling how people behave inside a system, aren't always built by a purely technical route. They're built by people who've had to explain hard ideas to non-technical audiences and argue a position under scrutiny.

Second, the security industry has a well-documented people shortage. A 2023 workforce study by ISC2, the body that issues the Certified Information Systems Security Professional qualification, estimated a global gap of 4 million unfilled security roles. Our reporting on this gap has run weekly since June, and a July story on skills measurement found that certifications alone don't close it. Expanding the accepted definition of a valid career path is one direct way to bring in people who'd otherwise be screened out.

None of this dismisses technical grounding. It matters. But Wheeler's career suggests that grounding can be built along more than one route, and organisations willing to look for it in unconventional places may find stronger leaders than those hiring strictly by credential checklist.

For ordinary people, the relevance is direct. Every organisation handling your health data or financial records needs someone like a CISO making the right calls. Whether that person got there by an orthodox route or an unusual one matters far less than whether they're genuinely good at the job.

Should you worry?

Not specifically about Wheeler. The more interesting question is whether her appointment signals anything broader about how the industry is starting to think about who's fit to lead. If it does, it's a shift that's overdue.

© 2026 Threat Vectr