The CISO Masterclass in Power, Purpose, and Performance
Imagine standing in the White House, building a national office from the ground up, and asking every single job candidate one jarring question: “What is the purpose of your power?” For Chris Inglis, the first-ever National Cyber Director and former Deputy Director of the NSA, this isn’t a philosophical exercise, it’s the litmus test for leadership. In a world where technical vulnerabilities grab the headlines, Inglis argues that the most successful CISOs aren’t just masters of code; they are masters of culture, translation, and service.
If you want to stop being treated like a “cost center” and start being treated like a strategic partner, it’s time to move beyond the silos. Drawing from Inglis’s decades of service, from flying C-141s to advising Presidents, here is the ultimate guide to transforming your security leadership.
1. The Cincinnatus Shift: Power as a Service
The traditional view of power is often about control, but Inglis suggests a return to the classics. He points to Cincinnatus, the Roman general who was granted absolute dictatorial power to save the Republic, only to hand it back and return to his plow once the job was done.
The CISO Recommendation: Stop viewing your authority as an entitlement and start viewing it as a “sacred trust”. Your goal should be to leave your organization better than you found it, which often means empowering others to the point where your own direct intervention is no longer needed. When your team says, “We did it ourselves,” you have achieved the highest level of leadership.
2. Speak the Lingua Franca: Bury the Word “Cyber”
One of the most radical suggestions Inglis offers to CISOs is to stop using the word “cyber” for an entire week. Why? Because the board doesn’t speak “cyber”; they speak “business”. Most boards view technology as a commodity, like a motor pool of cars that should just work, rather than an existential dependency.
The CISO Recommendation:
Audit your language: Instead of talking about “vulnerabilities” and “patches,” talk about “business commitments” and “customer promises”.
The Dashboard Flip: Redesign your Security Operations Center (SOC) dashboard. Instead of leading with a map of inbound threats, lead with a list of the company’s strategic goals. Security only matters if it protects the digital infrastructure that the business is existentially dependent upon.
Become the Translator: Your job is to sit at the “sweet spot” where technology, people, and doctrine meet. Translate the technical “red and blue lines” of the SOC into the language of business aspirations and outcomes.
3. Culture: The Strategy Eater
You can walk into an organization and tell within ten seconds if you are in “Mordor or Nirvana”. A toxic culture waits for orders and fears initiative, whereas a healthy culture empowers every member to act as an enabler and connector.
The CISO Recommendation:
Hire for Values, Not Just VIM: Inglis recalls a pediatric dentist who joined the National Cyber Director’s office; despite having no IT experience, her understanding of power-as-service made her an enormous success.
Avoid the “Smartest Person” Trap: If the premise of your leadership is that you are the smartest person in the room, the organization will fail the moment you aren’t there.
Bias for Initiative: It can take years to change a culture from one of “waiting for orders” to one of “accepting accountability”. Start by explicitly defining the “envelope” within which your team can operate with full discretion.
4. The Snowden Lessons: Reconciling Realities
The 2013 Edward Snowden incident remains one of the most significant insider threat case studies in history. Inglis, who was in the “ring” during that “hard summer,” walked away with three critical lessons for any CISO managing internal risk.
The CISO Recommendation:
Tell Your Story First: If you don’t define your mission and its limits, a malicious actor will tell a viral, “titillating” story for you. You cannot go second in the court of public or corporate opinion.
Inform the Workforce: Don’t assume your employees understand the “why” behind your security policies. If they can’t defend their work to their own families, they are vulnerable to disillusionment.
The Holistic Insider Program: True security is the reconciliation of three domains: Personnel, Physical, and Virtual. Snowden had a “personnel incident” (he got angry) and physical anomalies (logging in when not on campus), but because these systems didn’t “tip and queue” each other, the IT system remained blind to the threat. Ensure your HR, facilities, and IT security systems are talking to one another.
5. AI: Snuggling with the Beast
As organizations “snuggle up” with AI, we risk losing human accountability. Inglis shares a cautionary tale of “Lisa”, an AI that could improve code instantly but couldn’t explain why or what “improved” actually meant.
The CISO Recommendation:
Accountability is Non-Transferable: You can delegate performance to an AI, but you can never delegate accountability. A human must always be “on the loop” to step in when something doesn’t make sense.
The New “Three Rules”: Apply Isaac Asimov’s laws to your generative AI deployments: AI should not harm the organization, it should follow human orders, and it should protect itself, in that specific order.
Teach Critical Thinking: In an age of “credulous” humans facing “sentient-mimicking” machines, your workforce needs better benchmarks to identify when an AI’s output exceeds the “edges” of common sense.
6. The Daily Mission: Your Personal “Why”
At the end of his career, Inglis reflects that leadership isn’t about the medals or the unanimous Senate confirmations; it’s about intentionality. He suggests that most people answer the question of their power every day, even if they don’t consciously ask it.
The CISO Recommendation: Every morning, before you check your emails or look at a threat feed, ask yourself: “What is the purpose of my power today?”. If your answer is to protect the promises your company has made to its customers and to empower the people under your command, you aren’t just a CISO, you are a leader of the highest order.
Are you ready to stop fighting the last war and start leading the next generation? Building a secure future requires more than just better tech; it requires the “Cincinnatus mindset” of service and a relentless focus on the human aspirations that technology is meant to serve. Now, go out there and make your heart, and your board’s, swell with the impact of your leadership.




AI: Snuggling with the Beast: Can’t be said better, it’s time of the hour to realize that it’s non-negotiable, perhaps agents negotiated on their own with no HITL/Human-in-the-loop.
Security leadership really is shifting from tech-first to trust-first. Translating cyber risk into business impact is where CISOs create real influence.