The Man Who Helped Build the CISO Role Explains What That Job Actually Takes

Charles Blauner served as the top security executive at JPMorgan, Citigroup, and Deutsche Bank. His advice for the next generation of security leaders: find many mentors, give back constantly, and never mistake technical skill for leadership.

ThreatVectr Newsdesk· 4 min read
A timeline of cybersecurity evolution over 20 years, featuring AI and cloud icons
Share

Key points

  • Charles Blauner held the chief information security officer (CISO) role at three major banks across roughly 20 years: JPMorgan, Deutsche Bank, and Citigroup.
  • The CISO title was created in 1994, and Steve Katz became the first person to hold it in 1995.
  • Blauner and fellow first-generation CISO Phil Venables have together mentored more than 120 security leaders who went on to hold CISO roles themselves.
  • Blauner argues that resilience and communication matter more to a successful CISO than deep technical knowledge.
  • He warns that the CISO job is unlike any other senior leadership role because your opponents are actively, full-time, trying to make you fail.

Charles Blauner was a computer science graduate working at a telecom research firm in the early 1990s when hackers started showing up. Companies began to panic. Somebody had to be responsible for keeping the systems safe.

Blauner got lucky. He stepped into information security at almost the exact moment the profession was being invented.

By 1997 he had become one of the first people in the world to hold the title of CISO, meaning chief information security officer, the executive responsible for a company's entire digital security strategy. He went on to hold that role at JPMorgan, Deutsche Bank, and Citigroup over roughly two decades. He spoke about what he learned in a conversation first aired by Dark Reading.

Who actually invented the CISO role?

The title was created in 1994 and then filled in 1995 by Steve Katz, now widely called the godfather of the profession. Nobody knew what the job was supposed to look like, Blauner says, because nobody had done it before.

"None of us had any idea what we were doing," he says. "But we had a leader. And we had a visionary."

Katz established two habits that spread through the whole field. First, he pushed collective defence: security teams could not protect their organisations alone, so they had to share information and work together across company lines. That idea eventually helped produce the Information Sharing and Analysis Centers, known as ISACs, which are organisations where companies in the same industry pool intelligence about attacks.

Second, Katz gave his time away. He mentored CISOs, sales staff, and anyone he believed needed guidance, right up until the end of his life. That culture of paying it forward became a defining feature of the profession.

Between Blauner and fellow first-generation CISO Phil Venables, more than 120 security leaders have come up through their combined mentoring networks.

What does it actually take to lead a security team?

Technical ability gets you into the field. It does not, on its own, make you a good security leader.

Blauner is direct on this: resilience, communication, and business judgment increasingly separate effective CISOs from the rest. The reason is structural. Every other senior executive faces competition, market shifts, and operational problems. A CISO faces all of that, plus a group of criminals and hackers whose entire working day is spent looking for a way to break through.

"That reality makes the CISO role unlike any other in the C-suite," he says. "And one of the most demanding."

His advice for anyone early in a security career: do not look for one mentor. Build a network, and collect several.

For those further along, he is equally direct: if you have benefited from mentoring, it is your turn to give it back. At his last formal CISO job he ran an internal mentoring programme with a specific rule attached. To be a mentor, you also had to accept a mentee. You paid to get in by giving.

What does this mean for ordinary people?

Most of us are not CISOs. But the banks, hospitals, retailers, and public services we rely on every day are only as secure as the people running their security teams.

A profession that treats mentorship and shared knowledge as core values tends to produce better-prepared leaders. Better-prepared leaders catch more attacks before those attacks reach customers' personal data.

If you work inside any organisation with digital systems, which is almost every organisation, you can ask whether your employer takes security leadership seriously. Is there a named person responsible for security? Do they have support from the top? Those questions are not just for IT departments. They are for anyone whose information sits inside a company's systems.

© 2026 Threat Vectr