RSnake's Case for a CISO Code of Ethics
Robert Hansen argues that kickbacks, no-show jobs, and shelfware deals aren't just embarrassing, they're a national security problem.

Key points
- Robert "RSnake" Hansen argues CISO self-dealing (kickbacks, no-show advisory roles, vendor equity stakes, shelfware) is endemic, not exceptional.
- Security tooling selected for the wrong reasons creates coverage gaps that get exploited.
- At critical infrastructure or defense-contractor scale, a single compromised procurement decision carries national security consequences.
- The profession has no enforceable ethics framework: ISACA and (ISC)² publish codes of conduct, but enforcement is thin and largely self-reported.
- Hansen proposes disclosure requirements, restrictions on concurrent vendor advisory roles, and an accountability mechanism outside the hiring organization.
Does CISO self-dealing actually threaten national security?
Robert "RSnake" Hansen has a blunt diagnosis: the CISO role is riddled with self-dealing, and nobody with formal authority is doing anything about it. The behaviors he names are specific. Kickbacks from vendors. No-show advisory positions that pay CISOs to rubber-stamp purchasing decisions. Investments in vendor-connected VC funds whose portfolio companies land on the buyer's approved list. Shelfware procured, never deployed, quietly benefiting whoever signed the contract. He frames all of it as endemic.
The operational consequence is direct. When a CISO's incentives run sideways to their organization, tooling gets selected for the wrong reasons, coverage gaps follow, and those gaps get exploited. Inside a major utility or a Tier 1 defense supplier, one compromised procurement decision doesn't stay contained.
Should you worry about a profession with no licensing body?
Attorneys have bar associations. Physicians have medical boards. Certified public accountants (CPAs) answer to state licensing bodies. CISOs, whatever certifications they hold, answer to their employer and in practice almost no one else. ISACA and (ISC)² publish codes of conduct for credential holders, but enforcement is thin and largely self-reported.
Our read of 2024-2025 SEC 10-K filings, published 29 May 2026, found a striking abundance of "no material impact" disclosures that raise exactly this accountability question.
Hansen's proposed remedy is a formal code of ethics with real enforcement: disclosure requirements for financial relationships, restrictions on concurrent vendor advisory roles, and accountability that sits outside the hiring organization.
What's the counterargument?
CISOs already operate under fiduciary-adjacent duties to their boards, and a regulatory layer risks driving talent from a market that already can't fill seats. That tension is real. It doesn't make Hansen wrong.
Vendors cultivate relationships deliberately: advisory board seats, conference sponsorships, equity grants in pre-IPO rounds. A code of ethics without disclosure mandates is a press release, not a control. Hansen isn't calling for a federal regulator, at least not explicitly. But the logic points there. Self-regulation in a market this opaque, with consequences this serious, has a poor track record.
The harder question isn't whether a code of ethics is needed. It's who has the standing to write one that procurement desks and boards would actually respect.



