EARNED, NOT APPOINTED: THE REALITY OF THE CISO ROLE IN AUSTRALIA

e2 Cyber • August 6, 2026

One Role, One Organisation, No Second Chances to Make a First Impression

There is only one CISO seat per organisation. In most cases, it does not come up more than once every two to five years. When it does, the field of genuinely competitive candidates is narrow, the process is demanding, and the weight of expectation that arrives with the appointment is considerable. For the professionals aspiring to it, the path is long, non-linear, and rarely well understood from the outside. 


Jacob Bywater, Director at e2 Cyber, has worked with candidates and clients across the full spectrum of cyber security leadership hiring in Australia. His view of the CISO market is shaped by years of direct engagement with the people who hold these roles, the organisations that create them, and the candidates who fall just short. The picture he describes is more nuanced and more demanding than any job description captures. 


A CISO Talent Market Built on Musical Chairs 


The demand for CISO-level talent in Australia is real and it is growing. The regulatory environment accelerating that demand includes the Security of Critical Infrastructure Act, APRA CPS 234, the PSPF updated in July 2025, and the Essential Eight now mandated to Maturity Level 2 for Commonwealth entities - each of which requires genuine security leadership rather than compliance administration. Boards are increasingly aware that the cost of not having the right person in this seat is not abstract. It lands on the front page. 


But the supply of senior cyber security leaders who can genuinely fill these roles does not match the noise the market makes about them. What Bywater observes most consistently is not a dramatic influx of new talent into the upper echelons. It is movement. The same cohort of experienced professionals rotating between organisations, completing a programme of work, and moving on. 


"I think it's a bit like musical chairs," Bywater says. "You see people that have genuinely been impactful in these roles moving between organisations on a two-to-five-year career journey, completing something there and then moving to the next one. The opportunities to get a start at this level are hard to come by and there are not a lot of senior based roles that happen across the whole Australian market." 


That concentration of opportunity at the top creates a fundamental tension for everyone below it. How do you build the experience required for a role that almost no one will give you without that experience already? It is a question the market has not solved, and Jacob does not pretend otherwise. 


There Is No Single Path in Cyber Leadership, But There Are Patterns 


Ask for a typical CISO background and the honest answer is that there is not one. What varies most is the requirement of the role itself, which shifts significantly depending on the sector, the organisation's maturity, and what the hire is tactically expected to deliver. 


An organisation undergoing a major compliance uplift under the Critical Infrastructure Act or APRA CPS 234 needs a different kind of leader than one in a strong security position looking for sustainment and refinement. A start-up building secure by design from the ground up requires a different orientation again. The responsibility of the role dictates the profile of the person. 


That said, certain patterns do emerge. The most common trajectory Bywater observes is a technical foundation followed by exposure to security assessment, auditing or consulting work, then a progression into senior executive leadership. Alongside that, he has seen CIOs with extensive security exposure transition across into pure security leadership roles, and programme and project management leaders who have spent enough time directing security programmes to carry the required depth. 


"The people from a programme and project management background getting into these roles still have a strong level of security knowledge," Bywater notes. "Whether that's through training, exposure, or experience leading security programmes in other roles. It's not a construction programme manager moving straight into a CISO role." 


The minimum experience bar Bywater references consistently is ten to fifteen years across the industry, with some portion of that in ICT more broadly before narrowing to security. Beyond experience, organisations are increasingly seeking candidates with business education, particularly MBA-level study, to complement the technical foundation. The ability to translate cyber security investment into commercial language for boards and executive teams is no longer a differentiator. It is a baseline expectation. 


What the CISO Job Brief Materially Asks For 


The universal requirements that appear across almost every CISO brief Bywater has worked on share common threads, even where the specifics diverge. Deep experience and understanding within the cyber security domain is the foundation, typically a decade or more of direct exposure. Tangible, example-driven evidence of outcomes delivered, not merely roles held. Strong written and verbal communication at senior stakeholder level, including board reporting, executive presentations, and regulatory engagement. And a leadership profile that leans toward innovation and systemic thinking rather than operational management. 


"You often see where I've found innovative, big-solution thinkers," Bywater says. "People that want to solve big problems, people that think about what it looks like in five to ten years, not just completing what's in front of them day to day. It's rarely a purely managerial type person running the overall security of an organisation." 


On top of those foundations, relevant certifications and study matter, as does demonstrated delivery of ICT security programmes across multiple environments and sectors. Sector-specific depth is increasingly valued. An OT specialist pursuing a role in an OT-heavy regulated environment is a more compelling proposition than a generalist who has moved across too many different contexts to own any of them deeply. 


The technical versus leadership balance is harder to pin down, and Jacob is candid that it resists a simple formula. Some organisations need a CISO who can lead a full technology and architecture uplift and requires genuine depth across cloud, infrastructure, and frameworks. Others need a commercially astute executive who understands enough to ask the right questions and can hold the room with a board. Both are legitimate. Both require different people. The challenge for candidates is understanding which version of the role they are actually applying for. 


The Leadership Interview Process and What It Is Genuinely Measuring 


There is no standard CISO interview process. The number of rounds can range from two conversations to eight, depending on the organisation's size, structure and what the reporting line looks like. What does not vary is what the best interview panels are trying to determine. 


Bywater's consistent observation is that the most effective screening at this level is example-led rather than credential-led. The questions that in fact differentiate candidates are not about certifications or framework knowledge. They are about what the person walked into, what they found, what they decided to change, how they brought the team and the executive leadership along with them, and what happened as a result. 


"Tell me about the last organisation you worked in," Bywater says. "What was the environment like? What did you roadmap to change and how did you change it? How did you get the team on board? What were the outcomes? It's very example and experience orientated rather than technical black and white questions." 


That orientation matters because the panel is not really assessing whether someone knows a framework. They are assessing whether they can confidently enter a new environment, understand it quickly, and move it in the right direction. A candidate who has done that, and can articulate it clearly and with precision, builds the confidence that a hiring panel needs to make a decision at this level. 


Equally important is the ability to articulate with concision. Bywater's observation about candidates who talk too much is pointed and worth naming directly. At this level, the ability to communicate with precision and economy is itself a signal of capability. Senior people are busy. They want to hear what they need to hear. A candidate who fills the room with volume but not substance raises questions about what the gaps might be. 


"If you talk too much and tell me too much but there's no substance to it, that really impacts me," Bywater says. "It often tells me you're trying to make up for something. Rather than addressing a gap punctually and formally, you're addressing it by waffling and overselling." 


How Long It Takes to Hire a CISO and What to Expect 


For organisations expecting a CISO appointment to move at the same pace as a mid-level hire, Jacob is direct about recalibrating that expectation. Senior executives operate outside standard business hours. Getting meaningful time with them requires patience, flexibility, and a recruiter who can navigate the access. 


"Getting time with senior executives is difficult," Bywater says. "They're often phone calls after hours, on lunch breaks, or between travel schedules. A proper search at this level - reaching out, having real conversations, going through example-based questions, providing the right summaries back to the client - is somewhere between two to four weeks to do it properly." 


He also makes the point that the best candidate is not always the most visible one. Someone who does not carry a senior executive title on paper but has been holding equivalent responsibilities, and who might not surface on a standard LinkedIn keyword search, can be the right person. A thorough search means looking beyond the obvious places. Understanding how e2 Cyber approaches leadership searches provides context on what that process involves. 


What is the True CISO Salary Range? 


The CISO salary range in Australia is one of the widest of any role in the market, and for good reason. The scope, accountability and sector exposure of the role varies so dramatically that a single benchmark figure tells almost nothing useful. 


Based on available market data and direct recruiter observation, CISO base salaries in Australia typically range from around $160,000 at entry-level appointments or smaller organisations, through to well over $400,000 at senior enterprise level, with outliers in high-profile regulated environments reaching significantly higher. Bywater's own experience spans that full range and beyond. 


"I've met some getting paid $160K base all the way up to getting paid over $1 million on their base salary," Bywater says. "What comes with it and where the money really changes is based on what the organisation has in terms of data and what that correlates into in terms of genuine profit." 


Finance, defence, and major telcos consistently sit at the upper end. The organisations paying the most are often those that would receive the most scrutiny in the event of a breach. That correlation is not accidental. The higher the exposure, the higher the premium for the person holding accountability for it. 


Many of these senior appointments are also fixed-term engagements of two to five years, with a competitive process at the end. The market treats CISO tenure as a defined programme of work rather than a career-long appointment, and the structure of the roles reflects that. 


The Weight of the CISO Seat 


One of the most honest passages in any conversation about CISO careers is the one that addresses what the role truthfully costs. Bywater recounts a conversation he had with a CISO earning a seven-figure base salary - someone who had reached the peak of what the market offers financially - who said he would not do it again. 


"He literally said he never wants to be in another senior executive role," Bywater recalls. "He just wants to go back to doing his assessments and report writing and trying to influence executives from there. Because the responsibility, it's cost him his health, it's cost him some relationships. It's cost him a lot more than what he's made from a cash point of view." 


Bywater is careful to frame this not as a deterrent but as information. These are great roles to aspire to. The industry needs people in them who want to make a real impact. But the weight of responsibility that comes with holding accountability for the security of an entire organisation, particularly one operating in a regulated sector with billions of dollars of data and operational continuity at stake, is not something that shows up in a job description. 


Most organisations now place complete security accountability on the CISO. The question of whether that accountability is matched by commensurate influence across the business, including over software engineering, procurement and third-party partnerships, is one that Bywater observes divides the market. A CISO who is responsible for security outcomes but cannot influence the decisions that create security risk is in an inherently difficult position. Assessing that reality before accepting an appointment is as important as assessing the role itself. 


The Fractional and Interim Model 


Not every organisation that needs CISO-level leadership is positioned to hire one on a permanent basis. For smaller businesses, early-stage enterprises, or organisations going through a specific transition programme, a fractional or interim arrangement can provide access to senior capability at a scale the business can support. This model is particularly common through specialist service providers and cyber consulting firms such as our sister company Zaleo Consulting rather than through traditional recruitment. 


Bywater's view is balanced. There is genuine utility in the fractional model for organisations that need direction and governance without the full-time cost, and the quality of the person matters more in a fractional arrangement than in almost any other because the hours are limited. The question to weigh honestly is whether the arrangement provides enough depth of embeddedness for the person to genuinely understand the environment and make meaningful decisions within it. A CISO who is not fully across the characters, the culture, the architecture and the risks of the business is working with partial information. 


The practical question Bywater puts to organisations considering this path is a risk one. How much risk is someone able to genuinely own when they are dipping in and out rather than part of the full operational picture? That is not an argument against the model. It is an argument for being clear-eyed about what it can and cannot deliver. 


What Attracts and Retains CISO Talent 


The organisations that consistently attract and retain strong CISO talent share characteristics that go beyond compensation. Bywater's observation is that when hiring senior cyber security leaders, what draws them is genuine organisational investment in the outcome - boards that are engaged, executive peers who are aligned, and a team that is excited about what the appointment could mean. 


What pushes them out is the inverse. A CISO who develops a strategy, secures buy-in, presents a roadmap, and then finds there is no funding to execute it is a CISO who is counting days to the exit. The mandate has to be real, not ceremonial. The authority has to match the accountability. 


Bywater also makes the point that cultural alignment at this level matters as much as skills alignment. He has represented candidates he considered certain appointments, only to receive feedback that the panel felt the cultural fit was not right. At senior executive level, the team the person would join has a significant say in who sits alongside them. The process is evaluative from both sides. 


Presenting at Leadership Level 


The question of how candidates at this level should present themselves in the market is one where Bywater's advice is clear and consistent: lead with leadership, not management. The distinction between the two is significant and it shows in how people present. 


A leader can be trusted to inspire, influence and direct. They make the place better, not just operationally but culturally. They attract people to the organisation through their appointment. They have a presence at executive level that creates confidence across the business, not just within the security team. 


That quality is visible in how someone carries themselves in an interview, how they talk about the teams they have built, the change they have driven, and the decisions they have made under pressure. It is not about the certificates on the wall - it is about the story of where you have been and what you built there. 


Building the Pipeline the Industry Needs 


Looking at the five-year horizon for CISO talent in Australia, Bywater is genuinely optimistic about the quality of what is coming through. The competitive entry point into cyber security, while difficult for individuals, is producing a higher calibre of emerging talent than a more permissive market would. The best of those people will make it through. 


What concerns him is structural. The industry is producing capable technicians and capable managers. What it is not consistently producing is leaders. The difference matters enormously at CISO level and Bywater sees it as a gap the education system and the industry itself have not taken seriously enough. 


"I think a lot of people get promoted earlier in their careers because they are asked to do managerial tasks rather than leadership based tasks," Bywater says. "And what scares me is that we could end up with a bunch of managers in leadership roles that may lack innovation, that may lack big picture thinking, may lack the ability to challenge the status quo or see the world differently." 


The other structural gap he stresses is communication. The methods and channels through which the next generation of cyber security leaders will need to communicate span a far wider and more complex landscape than previous generations encountered. The ones who navigate that complexity well, who can communicate across formats, levels and audiences with equal confidence, will be the ones who make it to the top and stay there. 


On AI and its impact on the role, Bywater’s view is honest in its uncertainty. He acknowledges that what a CISO is responsible for today will be meaningfully different in five years. He does not pretend to know exactly what that looks like. What he says with confidence is that the rate of change will be exponential, and the leaders who thrive in that environment will be those who stay curious, keep adapting, and do not mistake the current job description for the permanent definition of the role. 


"Keep up," Bywater says. "Keep adapting, keep communicating, and enjoy the journey." 


One Final Word for Candidates Wanting to Step Up 


Bywater's closing message to candidates pursuing CISO-level roles is worth sitting with. There is one CISO per organisation. The competition is real and it is sustained. Being passed over does not mean you are not ready. It may mean the moment has not arrived yet, or that a better-matched candidate was in the field at the same time. 


Every day spent developing in your current role, expanding your knowledge, and building the examples that will one day tell your story at an interview panel, is a day closer to getting there. 


"If you get knocked down, just get back up again and keep going," Bywater says. "Whilst you might apply multiple times and not get the outcome that you want, don't give up. You've already gotten to a point in your career that you've demonstrated most of what's required. It's finding the opportunity to give you a break." 


A big picture role requires a big picture thinker. That requires patience, perseverance, resilience, and the ability to take feedback and apply it quickly. All of which, are exactly the qualities the role itself demands. 


Whether you are a cyber leader / CISO ready for your next move, or an organisation looking for someone to lead the team, we're ready to help. Get in touch to talk through your ideal organisation, read our latest updates about cyber leadership news, or about your cyber leadership hiring needs.

Let's Chat
Man on a phone in a cityscape, wearing a black polo shirt and smiling at the camera.
By e2 Cyber July 9, 2026
What Australia's GRC talent market is telling recruiters and hiring managers about pay, demand and the skills gap, from e2 Cyber Senior Consultant Ben Rogalsky.
Person completing a certification on a laptop in a warm-lit library
By e2 Cyber May 8, 2026
Discover the best cyber security certification in Australia to advance your career, build in demand skills, and stay competitive in a fast growing cyber job market.
Two men in black polo shirts review plans together at a table in an office-like setting.
By e2 Cyber May 5, 2026
Australia faces a cyber security skills gap with a need for qualified professionals. The problem is more complex than just certifications. e2 Cyber discusses.
Two people talking across a table in a warm, softly lit office setting
By e2 Cyber April 23, 2026
How budgets, candidate competitiveness, cyber security salaries and talent availability is currently affecting cyber security recruitment and hiring in Australia.