RSnake's Case for a CISO Code of Ethics
Robert Hansen argues that kickbacks, no-show jobs, and shelfware deals aren't just embarrassing — they're a national security problem.

Robert "RSnake" Hansen has a blunt diagnosis: the CISO role is riddled with self-dealing, and nobody with formal authority is doing anything about it.
Hansen's argument centers on a specific set of behaviors. Kickbacks from vendors. No-show advisory positions that pay CISOs to rubber-stamp purchasing decisions. Investments in "dirty" VC funds with portfolio companies that land on the buyer's approved vendor list. Shelfware that gets procured, never deployed, and quietly benefits the person who signed the contract. None of this is hypothetical — he frames it as endemic.
The operational consequence is concrete. When a CISO's incentives run sideways to their organization, security tooling gets selected for the wrong reasons. Coverage gaps follow. Those gaps get exploited.
At the enterprise level, that means breach exposure. At scale — think critical infrastructure operators or defense contractors — Hansen's concern escalates to national security implications. A compromised procurement decision inside a major utility or a Tier 1 defense supplier doesn't stay contained.
The profession currently has no enforceable ethics framework. Attorneys have bar associations. Physicians have medical boards. Certified public accountants answer to state licensing bodies. CISOs, regardless of what certifications they hold, answer to their employer and, in practice, almost no one else. ISACA and (ISC)² publish codes of conduct for credential holders, but enforcement is thin and largely self-reported.
Hansen's proposed remedy is a formal code of ethics with teeth — disclosure requirements for financial relationships, restrictions on concurrent vendor advisory roles, and some mechanism for accountability that sits outside the hiring organization.
The counterargument is predictable: CISOs already operate under fiduciary-adjacent duties to their boards, and adding a regulatory layer risks driving talent out of a market that already can't fill seats. That tension is real. It doesn't make Hansen wrong.
The deeper problem is structural. The CISO market rewards relationships and certifications over demonstrable outcomes. Vendors cultivate those relationships deliberately — advisory board seats, conference sponsorships, equity grants in pre-IPO rounds. A code of ethics without disclosure mandates attached to it is a press release, not a control.
Hansen isn't calling for a federal regulator, at least not explicitly. But the logic of his argument points there. Self-regulation in a market this opaque, with consequences this serious, has a poor track record.



