Last updated: September 3, 2026
By Tom Kenaley, President & Senior Partner, KORE1
CISO interview questions in 2026 should test disclosure judgment, spending under a flat budget, third-party exposure, and one incident the candidate read wrong. Strategy questions no longer separate anybody. Every finalist has that answer polished.
Look at the published question lists and you find the same six prompts everywhere. How do you align security with the business. Describe your risk management framework. How would you build a security culture. Tell us about your first ninety days. They are fine questions. They were fine in 2019 too, which is the problem, because there are now the better part of a decade of blog posts teaching candidates precisely how to answer them.
A regional health insurer outside Charlotte, roughly 900 employees, ran a first-CISO search last year with a five-person committee. Twelve weeks. Three finalists. The one they picked had run security at a company four times their size and told a genuinely good story about a ransomware event he had managed in 2022.
Nobody asked him what he would have filed, or when.
Fourteen months in, a claims-processing vendor got hit. Not them. Their vendor, holding their members’ data. He wanted to wait until the facts settled. Reasonable. It is also the instinct that turns a bad week into a legal problem, and by the time general counsel got pulled in, the company had been sitting on an unanswered materiality question for eleven days. He was not incompetent. He had simply never been the person who had to make that call, and no one in his interview loop had thought to check.
Worth knowing who is talking here. KORE1 places security leadership through our CISO staffing desk, inside a broader cybersecurity staffing practice, and a completed search is revenue for us. Weigh what follows accordingly, then use it anyway. None of it needs a recruiter in the room. Every committee I have walked through this has ended up running it without us. Where the seat itself is still unsettled, our 2026 guide to hiring a CISO handles the scoping and the CISO salary guide handles the band.

The Liability Story Changed Twice, and Most Loops Still Tell the Old Version
Two things happened in November 2025 that should have rewritten these interviews. Mostly they have not. The two point in opposite directions, which is probably why.
On November 20 the SEC voluntarily dismissed, with prejudice, its fraud case against SolarWinds and its CISO Tim Brown. Every security executive in the country had been watching since 2023. That case was a first. The Commission had never before pursued a sitting CISO personally over disclosure language. The Harvard Law School Forum on Corporate Governance called it a U-turn. Relief moved through the profession fast. About a day.
Nine days earlier the Ninth Circuit had declined to rehear Joe Sullivan.
Sullivan is the former Uber security chief convicted in 2022 of obstruction and misprision of a felony for routing a breach payment through a bug bounty program while the FTC was mid-investigation. A three-judge panel affirmed that conviction in March 2025, and the full court refused to revisit it that November. Civil securities exposure got softer. Criminal exposure did not move an inch.
So the honest answer to “can a CISO personally end up in front of a judge over this?” is that one already has, and separately the regulatory case everyone feared evaporated. Both. In the same month.
Ask your finalist what they make of it. Not as a trivia question. As a way of finding out whether they have thought about their own exposure at all, because the ones who have will describe a specific working relationship with a specific general counsel, and the ones who have not will say something warm about transparency.
Open With the Clock, Not the Strategy
Run this exercise whether or not you are public. It works on a private company with an audit committee, it works on anybody carrying a SOC 2, and it works especially well on companies that are certain none of this applies to them.
The SEC’s cybersecurity disclosure rules require an Item 1.05 Form 8-K within four business days of determining an incident is material. Four days from the determination, not from the incident. That distinction is everything. It is also where careful people get into trouble, because the same rule says the determination itself cannot be unreasonably delayed. You cannot protect yourself by refusing to decide.
Build the exercise around that. Write a one-page incident summary and make it deliberately incomplete. A data exfiltration alert that fired Friday afternoon. A vendor confirming unauthorized access but not scope. An internal estimate of “somewhere between 4,000 and 90,000 records.” One line from a business lead saying the affected system is not important. Hand it over. On paper. Then ask three things.
Who made the materiality call at your last company, and were you in the room. What would you need to know before you would say the word material out loud. Who do you call in the first hour, in what order.
Order tells you more than the names do. Strong candidates put counsel early and communications late. Weak ones invert it. Anyone who has genuinely lived through one of these will raise something the frameworks leave out. The forensics firm and the cyber insurer both get engaged before anybody knows what is actually being disclosed. And the insurer usually has opinions about which forensics firm you are permitted to hire.
One follow-up separates people fast. What do you do if the general counsel disagrees with your read on severity? A candidate who says they would simply defer has told you something. So has one who would escalate over counsel’s head. The answer I look for usually involves writing it down.
Assume the Budget Is Flat, Because It Probably Is
One number should reshape your budget question. Here it is.
IANS Research and Artico Search put security budget growth at 4% year over year in their Security Budget Benchmark, the slowest rate in five years, with fewer than half of surveyed CISOs reporting any increase at all. Compensation kept climbing over the same stretch. Budgets did not follow it.
That split is most of the job now. The standard question misses it. “How would you build out our security program” invites a wish list, and every finalist can produce a good one on demand.
Try this instead. Your budget is flat next year, the board wants an AI governance program, and legal wants a third-party risk function that does not currently exist. What comes out?
Then stop talking.
You want a trade. Named specifically, with a consequence attached to it. Dropping a tool whose coverage overlaps something else they already own. Moving 24/7 monitoring to a managed provider and absorbing the slower escalation that comes with it. Killing a compliance workstream that exists only because one customer asked for it in 2023 and never asked again. What you do not want is efficiency language. “We would find efficiencies” is the security equivalent of a shrug. It survives entire interview loops unchallenged. That still surprises me.
Pull a defensible band from our salary benchmark assistant first, not once the conversation has already gone sideways. A candidate you have just asked to defend a flat budget will read your offer as a statement about how seriously the company takes the function. They are not wrong to.

What Weak and Strong Answers Actually Sound Like
Panels struggle to grade CISO answers because most panels contain nobody who has done the job. This is the sheet I hand people.
| Ask this | Weak answer sounds like | Strong answer sounds like |
|---|---|---|
| What did you decommission last year? | A list of things they bought | A tool they turned off, who complained, and what broke |
| How do you know your MFA coverage is complete? | “We have MFA everywhere” | A percentage, the date it was measured, and the exception list |
| What does the board see from you quarterly? | “A risk dashboard” | Two or three metrics they can defend, plus one they stopped reporting |
| Which vendor could hurt you most? | A category, such as “our cloud provider” | A named company, the data it holds, and when it was last assessed |
| Tell me about a control you were overruled on. | “I have good executive relationships” | The decision, who made it, what they wrote down, whether they were right |
| What would your last security engineer say frustrated them? | “I have an open door” | Something specific and slightly unflattering |
Cut five rows out of that table and I would fight hardest for the last one. Security leaders who have genuinely managed people can name the friction. Usually with a small wince. The ones who mostly managed vendors and consultants talk about culture instead.
The Third-Party Question Is Most of the Question Now
Verizon’s 2025 Data Breach Investigations Report, built on more than 22,000 analyzed incidents, found the share of breaches involving a third party doubled year over year, from 15% to 30%. That figure is not about software supply chain attacks specifically. It is partner credential exposure, misconfigured SaaS tenants, and vendors holding standing access that nobody had reviewed since onboarding.
Most CISO interviews still treat vendor risk as a compliance topic and hand it four minutes at the end. Four minutes.
Three questions beat the entire questionnaire conversation. Walk me through what happens on your side the day a vendor tells you they were breached, not the policy but the actual sequence. How many vendors have standing access to production, and how do you know that number is right. Who at your last company could sign a contract creating a data-sharing relationship without you ever seeing it.
The third one gets further than it has any right to. In most midmarket companies the true answer is “marketing” or “about half the department heads,” and a candidate who says so, unhappily, has been paying attention to something real. One who tells you security reviewed every contract is describing a company I have not encountered.
Somebody on your panel will want cost framing. Have it ready. Ponemon Institute research published in IBM’s 2025 Cost of a Data Breach Report put the US average at $10.22 million, a 9% rise to an all-time high, while the global average fell to $4.44 million. American companies pay a regulatory and escalation premium the rest of the world does not.
Ask About the One They Read Wrong
Every experienced security leader has an incident they initially under-called. Every one.
Ask straight out. Tell me about something you assessed as low severity where you turned out to be wrong.
Then wait. Do not rescue them. The pause is most of the test. People who have been through it have the story ready and tell it flatly, without much drama. People who have not will hand you a near miss where their instincts were vindicated in the end, and that substitution is easy to hear once you know it exists.
Grade the correction. Not the miss. Did the triage criteria change afterward? Did somebody get authority they did not previously have? Did an alert everyone had tuned out get untuned? A senior person changes a process. A mid-level person changes their own vigilance. That is not a change. That is a promise.
The best version of this answer I have watched came from a candidate describing a user-reported phishing email she had closed as a false positive on a Thursday in 2023. It turned out to be the first touch of an intrusion her team found nine days later. She had rebuilt how her SOC handled user-reported mail afterward, named the analyst who had triaged it, and pointed out that she had trained him on that exact rule, so the rule failed rather than his judgment. Offer went out that week.
Let Them Interview You, and Grade the Questions
The reverse questions tell you as much as anything you ask. CISO candidates ask better ones than any other executive population I recruit for, and it is the cheapest signal in the loop.
The IANS numbers are worth a second look here. Their 2026 benchmark, built from 662 CISOs surveyed between April and November 2025, found executive-level titles now dominant across company sizes, up from 33% to 47% among large enterprises since 2023. And yet 64% of CISOs still report into IT leadership rather than to a CEO, COO, general counsel, or chief risk officer. Title and authority have drifted apart. Candidates know this. They go looking.
Questions you should hope to hear. Who signs off when I say no to a business unit? Is there D&O coverage, does it name me, and can I read the indemnification language before I sign anything? What happened to the last person in this seat, and who made that decision? How often does the board see security, and do I present or does somebody present on my behalf?
The insurance question makes some hiring managers flinch. It should not. After the last three years, a CISO who does not ask about their own coverage either has not been paying attention or is desperate, and neither is what you are shopping for. More than half of the CISOs in the IANS survey said their scope has grown past what they can reasonably manage. They ask because the job kept expanding and the protection did not automatically expand with it.
If nobody asks you anything in that category, that is also data.
Six Things That Should Worry You About a Finalist
- Fluent frameworks, no numbers. They can walk NIST CSF 2.0 end to end and cannot tell you their own patch compliance rate at the last place.
- Every story is a win. Real security careers contain at least one bad quarter. Somebody with none has either been in the chair a short time or is editing.
- Tooling as strategy. When the ninety-day plan is essentially a procurement list, you are hiring a security architect and paying executive money for it.
- No opinion on the reporting line. Anyone who has done this twice has a view about who they should report to, and will offer it unprompted.
- Certifications carrying the conversation. CISSP and CISM are entry conditions at this altitude. The work done while earning them is the part that matters.
- Agreement with all four of your stated priorities in the first meeting. That is a sales instinct. You will hear it again in a year, when the board asks something hard.
Point four deserves more room. A candidate with no opinion on where the CISO should report has probably never had to argue for one. That argument is the entire job on the days it matters, which is the day a VP of sales escalates around them to a CIO who outranks them and wants the friction gone by Friday afternoon.
Sequencing the Loop
Four rounds. Five if the board insists, which it will.
Round one is a forty-five-minute screen with the hiring executive, and its real job is checking team size against ambition. Somebody who has run forty people walking into a team of four is a genuine risk, and so is the reverse. Round two is the incident summary exercise with counsel in the room. Round three is the flat-budget trade with the CFO, who can grade that answer without anyone translating it. Round four puts the finalist in front of two business leaders they will need constantly and cannot manage at all.
Skip the technical panel. A CISO screened like a senior engineer will either coast through it or resent it, and neither outcome tells you anything. Where you do need somebody who can architect detection and response, that is a separate hire, and our security engineer interview questions handle that altitude properly.
Scheduled tightly, the whole loop takes about three weeks. A full CISO search runs eight to twelve weeks kickoff to signed offer, and almost none of that is interview time. It is calendars and indecision.
The Objections We Hear Most
We are not a public company. Does the disclosure exercise still apply?
It applies more than you would guess, and it may be a better test for you than for a registrant. Private companies still face state breach notification deadlines, contractual notice terms, and cyber insurance conditions, and frequently nobody owns any of it. The exercise finds out whether a candidate can hold a clock they were never formally handed. Run it with your general counsel in the room and watch both people.
Our whole panel is non-technical. Are we even qualified to run this?
More qualified than you think, because none of the exercises above ask you to grade a technical answer. A CFO can grade a budget trade. A general counsel can grade a disclosure sequence. That is the whole reason for putting a document in front of somebody instead of asking them to describe a philosophy.
Should we test them on AI security?
One question, and make it governance rather than technical. Ask who approved the last generative AI tool that reached production at their company and what the review actually consisted of. A candidate who answers with model architecture has misread the seat. The 2026 version of this job is largely about who is allowed to say yes.
How much should a fractional CISO change the loop?
Cut it roughly in half and keep the disclosure exercise intact. You are buying judgment by the hour rather than a program builder, so incident sequencing and third-party questions carry nearly all the weight. Our guide to fractional CISO services covers when that structure fits, and we maintain a current list of fractional CISO firms.
Is it a red flag if they will not name their current employer’s gaps?
It is the opposite of one. A candidate who walks you through their present employer’s unpatched systems will describe yours somewhere else in eighteen months. Ask about a previous company instead, or about a gap that has since been closed.
Do we need a search firm to run this?
Not for the interview. Everything above works without one. Where a firm earns the fee is the part before it, which is producing eight credible sitting CISOs who were not looking, and nearly seven in ten of them told IANS they were open to a move within the year. That is a sourcing problem rather than an interviewing problem.

Before You Schedule Anything
Write down what would need to be true a year from now for this hire to count as a success. One paragraph, plain language. Then check whether the loop you have designed could detect any of it.
Most cannot. The questions test articulation. The paragraph almost always describes judgment exercised on a deadline with incomplete information in front of people who outrank the person making the call, which is a completely different capability and does not survive contact with a strategy question.
One counterweight to the bias I flagged at the top. We have staffed eight verticals since 2005, and 92 percent of the people we place are still in the seat a year later. No assessment tool produced that number. It came from asking a great many people to describe the worst call they ever made, then paying close attention to which ones could.
Handing the search off is a legitimate call, and where you land there, talk to a KORE1 recruiter. What makes that first conversation useful is knowing three things. Whether this is a first CISO or a backfill. The number you are cleared to pay. Why the last person left. Say that third one plainly. We have heard worse.
Where the seat has to be permanent from day one, direct hire staffing is the right structure. And where the req is still a paragraph sitting in somebody’s inbox, start with the CISO job description template before anyone schedules a single round.

