Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Cybersecurity leadership does not require one standard route through IT. In a February 19, 2025, SecurityWeek interview, Kevin Winter of Deloitte and Richard Marcus of AuditBoard described careers that began in psychology, military service, finance and startup work—and explained why today’s CISO needs business judgment, organizational influence and a team that can sustain demanding work.
Two routes into cybersecurity leadership
Winter and Marcus illustrate how varied a path to the CISO role can be. Their accounts are examples, not a formula: both describe learning through changing roles and taking on opportunities as they appeared.
Kevin Winter: psychology, military service and technology leadership
Winter studied psychology and initially considered medical school. Financial constraints led him to join the Marine Corps, where he says he developed technical and leadership skills. His career then included cybersecurity and technology roles at Joint Task Force–Computer Network Operations, Booz Allen, SRA, a return to Booz Allen as CIO, and Deloitte. SecurityWeek identified him as Deloitte’s Global CISO when it published the interview.
Richard Marcus: finance, startups and security
Marcus studied finance and entrepreneurship, then worked in Wall Street equity research. Following the 2007–08 housing crisis, he joined startup Edgecast. A PCI audit there became an entry point into technology, security and broader business responsibilities. His path continued through security operations and Verizon Media to AuditBoard, where SecurityWeek identified him as CISO at the time of publication.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
The practical lesson is not to imitate either biography. A nontraditional starting point can be an asset when paired with continued learning, willingness to move beyond familiar work and the ability to connect security decisions to business needs.
What the CISO role asks beyond technical expertise
Winter and Marcus both emphasize that a CISO must understand how the organization operates and work across its boundaries. Technical depth matters, but it is not enough on its own: security leaders need to influence design, communicate with executives and explain how security supports the business.
Rank #2
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Winter argues that security and IT infrastructure are closely connected, so a security leader should understand IT operations and help shape systems before they are built. He says, “So, the CISO must be a peer with the CIO – and in many cases I’m seeing the CISO leading in the design work.” He described security leading network design work at Deloitte.
Marcus described a different arrangement at AuditBoard: “The CISO is the CIO.” In his account, enterprise IT reported into security, allowing security practices to be built into areas such as identity and access management and endpoint security. These are two interviewees’ organizational examples, not universal prescriptions for reporting lines.
Recommended Free Tools
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
For someone evaluating a CISO role or preparing for one, the title alone says little about its influence. Consider whether the security leader:
- Has access to executive decision-makers and a meaningful role in business planning.
- Can work closely with IT operations while retaining authority to raise security concerns.
- Participates early in system and network design rather than reviewing decisions only after implementation.
- Can translate technical risk into consequences and priorities that other leaders can act on.
Winter captures the business-partner mindset this requires: “If you want to get into the CISO realm, you must look at yourself as a business partner – you’re the one bringing the cyber strategy; and that mindset is important.”
Rank #4
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
How to approach compliance and incident disclosure
Marcus sees compliance as useful when it helps an organization understand its obligations and informs sound decisions or investment. He objects to treating it as a checkbox exercise disconnected from strategy and behavior. In practice, that distinction is between using requirements to organize meaningful security work and doing only what is needed to appear compliant.
The interview also discussed the SEC’s cyber-incident disclosure rules and the difficulty of deciding when an incident is material. Winter raised concerns about legal exposure and inconsistent interpretations in the February 2025 conversation. SecurityWeek described a four-day disclosure period after determining an incident is material; that figure is part of the article’s account of the rules, not current legal advice. Organizations should rely on current regulatory materials and qualified legal counsel for decisions about their own obligations.
Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
How security leaders can build a team that lasts
Marcus describes effective teams as a balance: exceptional individual contributors matter, but so do cohesion and varied perspectives. He invokes ikigai to describe work that combines interesting problems, modern tools, autonomy, purpose and fair compensation.
Winter focuses on the conditions leaders create. He recommends empowering and trusting staff, recognizing contributions and giving people room to grow. He also describes cybersecurity as a high-burnout environment, especially during incidents and active vulnerability response. His practical measures include making downtime visible, encouraging staff to disconnect after intense periods and avoiding arrangements in which one person alone owns an entire area. Shared responsibility helps ensure that an incident does not place its full burden on a single team member.
Career advice for aspiring CISOs
Marcus recalls being encouraged not to reflexively turn down opportunities: raise a hand for challenging work and learn by doing it. He also repeats a mentor’s maxim: “Good news should travel fast, but bad news should travel faster.” For security leaders, promptly surfacing difficult information is part of being ethical and trusted—not a failure of the security program.
Winter advises aspiring leaders to broaden their experience beyond their comfort zone and across security functions. Technical skill may open the door to leadership, but the broader perspective and leadership approach are what help someone remain effective at the executive level. As he puts it: “Your technical skills will get you to a leadership position, and your leadership style will keep you there.”
Marcus’s advice complements that: understand the business and its users as customers, develop functions that help them, and build relationships so you know what stakeholders expect. The aim is to make security a credible partner that protects the organization while helping it pursue its goals.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




