Why Technically Strong CISOs Lose to Weaker Peers: The Hidden Role of Internal Politics
Andrey Biryukov, an independent IT and information security expert who teaches at training centers and authors books, examines why technically strong CISOs often lose internal battles despite superior expertise.
The typical scenario involves a capable CISO who has built a solid team and stays current on threats yet sees a predicted incident occur after budget requests were denied. In contrast, a less technical peer secures growing budgets, board attention, and cross-functional cooperation even after incidents. The difference, Biryukov argues, is the ability to sell the security program inside the organization—an undervalued soft skill rarely covered in certifications or interviews.
Why CISO Influence Matters More Than Formal Power
CISOs rarely possess direct authority over other departments. They cannot order the CFO to release funds, force business units to alter processes, or discipline developers who ignore security requirements. Their only tool is influence, which must be earned through trust, arguments, relationships, and political capital rather than granted by title.
Every security initiative requires decisions from others: funding, prioritization, acceptance of inconvenience, or process changes. When the CISO cannot sell these ideas effectively, initiatives stall, business units bypass security, budgets stagnate, and the CISO becomes the scapegoat after the first major incident.
Translating Security into Business Language
Business leaders operate under competing priorities. The CFO manages limited budgets across ten initiatives, the CTO faces release deadlines, and the CEO answers to investors. Abstract warnings such as “we could be breached” or “risk is critical” quickly lose impact. Effective communication instead uses concrete scenarios: lost clients, revenue impact in millions, weeks of payment-system downtime, and regulatory investigations lasting quarters.
Biryukov contrasts two requests for a new SIEM. The weak version states that the current tool covers only 70 percent of logs. The strong version explains that the blind spot affects systems handling 40 percent of payments, detection time would rise from hours to days, and one day of downtime would cost a specific amount while regulatory fines would reach another figure.
Building Coalitions and Narratives
Successful CISOs build relationships long before budget cycles through joint projects, informal conversations, and participation in other leaders’ initiatives. Political capital accumulated in calm periods is spent during crises. A clear narrative also helps: stating that in 18 months the organization will pass major client audits without exceptions and reduce cyber-insurance costs by a defined percentage, supported by specific initiatives such as identity management and segmentation, makes the program memorable and discussable even when the CISO is absent.
Objections are treated as invitations to further dialogue rather than walls. Asking “What would need to change for this to become a priority?” reveals the additional selling required. After incidents, a short window of attention opens; only CISOs who arrive with pre-calculated business cases capture new resources.
The article concludes that security programs without internal buy-in exist only on paper. Technical knowledge alone does not protect the organization; the ability to translate that knowledge into decisions by budget holders determines whether the program succeeds or the CISO becomes expendable.
Related articles
Bybit Restricts Transfers to Sanctioned Entities Including Lazarus Group and CryptoPro
Cryptocurrency exchange Bybit has notified users that transfers to or from entities on its Restricted Counterparties list are prohibited, regardless of amount or whether conducted directly or through intermediaries. The list includes the North Korean state-sponsored Lazarus group and Russian cryptographic software developer CryptoPro due to their presence on sanctions lists from the United States, European Union, and United Kingdom. Bybit will automatically reject outgoing transfers to listed counterparties and may freeze incoming funds from them or related addresses, with potential account suspension or closure for users involved. The exchange emphasizes that blockchain transparency allows tracing of funds without user confessions and reserves the right to block transactions even with counterparties not yet explicitly listed. These measures are embedded in Bybit's terms of service to ensure compliance with international sanctions regimes.
Russia's MinTsifry Flags Google Android Developer Verification Rules as Risk to Domestic Apps
Russia's Ministry of Digital Development is assessing new Google policies that will require developer registration for Android apps distributed outside Google Play. The changes, starting in select countries in 2026 and expanding globally in 2027, could block sideloading of Russian applications previously removed from official stores due to sanctions. Minister Maksut Shadaev described the scenario as a potential barrier where users may no longer freely install APK files from third-party sources. Google plans to retain advanced modes and ADB installation options with extra warnings for unverified apps. Custom firmware projects such as LineageOS have stated their devices will remain unaffected by the verification system. Russian banks, marketplaces, and other services that rely on direct APK distribution are viewed as the most exposed.
Rosfinmonitoring Denies Mass Bank Account Blocks Over Partial Data Matches with Sanctions Lists
Rosfinmonitoring has issued clarifications rejecting reports of potential widespread freezes of bank accounts due to partial matches between client data and records of individuals subject to asset freezes. The agency stressed that the draft law is not intended to penalize people who merely share surnames or have similar name transliterations with sanctioned persons. Criteria for determining partial matches have not yet been defined and will be established by a separate order only after the federal law is adopted and real cases are analyzed. The measure provides only for temporary suspension of a transaction rather than automatic refusal or indefinite account blocking. Earlier reports from Izvestia had warned that loosely defined partial-match rules could generate numerous false positives affecting ordinary clients.
Understanding GOST Cryptography Standards: A Practical Guide for Russian Developers
The article provides a beginner-friendly breakdown of Russian GOST cryptographic standards, separating the core functions of hashing, digital signatures, and encryption. It covers the evolution of GOST algorithms across three generations from the 1990s to the current 2012+ standards including Stribog, Kuznechik, and Magma. Detailed explanations address how PKCS#11 interfaces with hardware tokens, how X.509 certificates function as digital passports, and how formats like CAdES, XAdES, and PAdES package signatures for verification. Comparisons with Western equivalents such as SHA-256, RSA, and AES help developers map familiar concepts to GOST implementations. The guide emphasizes practical integration with tools like CryptoPro for tasks involving detached signatures and certificate requests in PKCS#10 and PKCS#12 containers.