Shift to AI – Episode 4 – CISO, Board Member, Investor: Leadership Lessons From Every Seat at the Table
Presented by Cycode, the Agentic Development Security Platform
Guest: Stephen Ward, former CISO, cybersecurity investor, founder & partner, and board advisor
Roland Cloutier
Hi everyone, welcome to Shift to AI. I’m your host, Roland Cloutier, and this podcast is presented by Cycode.
We spend a lot of time on this show talking about how AI is changing technology – the software factory, vulnerability discovery, automation, agents, and operating models. But there’s another shift that may matter even more for most of the people listening: AI is changing what it means to lead security.
The future security leader won’t be measured only by incidents handled, tools deployed, or budgets managed. They’ll be measured by whether they can translate risk for the board, help the business move at AI speed, build teams that learn faster than the threat environment, and develop successors who are ready for the next shift.
That’s why this episode is about legacy – not legacy as a speech at the end of a career, but legacy as the leadership system you’re building right now. Who are you developing? What expectations are changing? What belongs in the AI-generation CISO job description? And what do boards, investors, founders, and executive teams now need from security leaders that they didn’t need ten years ago?
I’m excited to have this conversation today with a good friend, Stephen Ward. Stephen is a former CISO, cybersecurity investor, founder and partner, and board advisor who’s worked across the operational, executive, and investment sides of security. His background is amazing, and it’s funny how it parallels mine – there aren’t a lot of folks in this industry who started in the military the way we did. He was Coast Guard, I was Air Force, then federal law enforcement, and then this crazy stuff.
What I really appreciate about Stephen is that he can speak from the seat of an operational CISO – something that’s never left him, even in the years he’s spent doing capital – and he can speak from the boardroom, because he’s had to lead companies through really hard problems. Now he’s got this investor’s view of where the market is going and how it’s going to solve some of these hard problems. I think it’s going to be an awesome conversation. Stephen, thanks for voluntolding to do this – I appreciate it.
Stephen Ward
Thanks for asking.
Roland Cloutier
Let me start with the question I ask everyone on this show: walk me through the first thirty minutes of your morning – what you’re looking at before you’ve even had your second cup of coffee – and the last thirty minutes of your day.
Stephen Ward
So I’ve never had a cup of coffee in my life – that’s the first problem. My wife says I just wake up annoying.
My first thirty minutes now look pretty different from when I was a CISO. I’ve got a folder on my phone called Morning Read, and I’ll zip through the New York Times, the Financial Times, the Wall Street Journal, The Information, Business Insider. It’s less about who got popped overnight and more about what’s happening in the world – the macro environment, the geopolitical environment, the financial side of things. I want to know what companies got funded in the last twenty-four hours and whether I have competitors in those categories. If Sequoia did a deal and I didn’t see it, I’m immediately texting Sven: did we miss this? Why didn’t we see it?
When I was a CISO, it was all about: if my board or my CEO sees this in the morning, are they going to ask me about it? So it’s a bit different now.
Last thirty minutes – honestly, I’m not a good model for this. I sleep with my laptop next to me, my phone’s there too.
Roland Cloutier
You’re horrible, man.
Stephen Ward
Yeah, my last thirty minutes is usually email and talking on the phone – founders calling me at 10:30 at night.
Roland Cloutier
Yeah.
Stephen Ward
My wife’s trying to sleep. It’s not healthy, but it’s just how I do it. I can’t turn my brain off, so I have to get through those things before bed or I won’t sleep.
Roland Cloutier
Yeah, I’m getting the same way – I’ve had to get back into reading. I’m probably twenty books deep this year.
Stephen Ward
Amazing.
Roland Cloutier
I have to read, it’s crazy. So, you and I – we just figured it out – 2028 will make twenty years we’ve known each other doing this crazy stuff. We’ve lived through a few resets in security. What feels different about the shift into the AI era?
Stephen Ward
I think now it’s speed – speed to value. Everything is moving fast, and what happens quickly in the consumer world, in the things you use at home, ends up translating into what you want at work. Remember the days of taking a year to roll out an EDR? Nobody has patience for that anymore. It’s: get me an API hook, get me visibility, I want to add value now. That’s really hard to do in complex environments. AI is making it a little easier, but right now the biggest change is immediate time to value, and no patience for anything else.
Roland Cloutier
Probably we didn’t have the patience then either.
Stephen Ward
I think we just had different expectations for how long things would take.
Roland Cloutier
It was manageable. Speaking of managing – CISOs, if we rewrote the CISO job description today, specifically for the AI generation, what’s in, what’s out, what’s still missing? From your perspective, what has to change?
Stephen Ward
I have a bit of a worry right now with CISOs who haven’t figured out how to balance technical acumen with executive presence. Five to seven years ago we weren’t looked at as executives – that’s very different now. We got the pay we wanted, the titles, the reporting structure, the teams. Well, with that comes responsibility, leadership, and accountability.
Roland Cloutier
Accountability.
Stephen Ward
Accountability – you’re an executive now. CISOs have to start understanding: you’re an executive who happens to work in cyber, not a cybersecurity expert. I need you to be an executive and a leader who can communicate properly. I think a lot of them are still struggling with that shift in personality and traits.
Roland Cloutier
I totally agree. One thing I always ask young CISOs: do you know the next five products your company is taking to market? Do you understand the profitability behind that? Do you understand your key supply chain model? A lot of people don’t even understand their own value chain, and I’m not sure how you protect something you can’t articulate. It’s still a gap.
Stephen Ward
I had a boss – the CIO of Home Depot, Matt, good dude. I was complaining that I didn’t know what was going on in the business, that they weren’t letting me in the room. And he used to say, ‘Cyber has to be at the inception of the idea so we can build security in.’ I said that to him once, and he looked at me and said, ‘The business sets the strategy. IT is an enabler of that strategy. Security is a barrier to progress. That’s why we don’t let you in the room. Figure out how to be an enabler the way IT is to the business, and they’ll invite you in. But as long as you’re talking about guardrails instead of rails, we don’t want you around.’ I was so pissed off at him. Then a year later you look back and go, ‘Oh my god, I didn’t get it.’ I wish I’d gotten it faster.
Roland Cloutier
Let’s talk about boards. From where you sit now, with boards and investors – what do boards expect from security leaders that some CISOs aren’t prepared to deliver right now?
Stephen Ward
CISOs have to understand what the board doesn’t want to hear. I made the mistake early on of doing a maturity assessment and walking in to present it: ‘I’m the new CISO, I’ve been here six months, and here’s our new maturity level – you thought you were here, but you’re not, there’s degradation. You’re not a 3.2, you’re at a 2.8.’
Roland Cloutier
You’re not at 3.2, you’re at 2.8, exactly.
Stephen Ward
And then the consulting firms make more money on professional services to help you build the program back out. I did that, and – lesson learned – I didn’t stop to think that everyone on that board had lived through the Home Depot breach. The CIO was there, the CEO was there, the chief legal officer was there. They lived it. And here I am, a year later, telling them the program they thought they’d rebuilt wasn’t actually rebuilt. How arrogant do you have to be to walk in and tell Fortune 500 CEOs on the board of Home Depot something like that, without spending the first year building the trust so they’d actually believe the results?
Roland Cloutier
Right.
Stephen Ward
So now I always tell CISOs: don’t do maturity assessments in year one. They won’t trust you enough to believe them.
Roland Cloutier
Do your own assessment first.
Stephen Ward
Yes – do your own assessment, do it in partnership with others, and know what not to tell people yet.
Roland Cloutier
And educate them on the areas where they’re falling short, so it’s not just ‘development is bad’ – you sit down, show them the gaps, give them the pathway.
Stephen Ward
Yeah, I think you have to reverse it a bit – really sit down and think about what you don’t want to tell the board. I didn’t understand this until I was on the board of Mimecast, a public company at the time. That’s when I realized: I’m a board member now, and I thought, ‘Oh, I don’t want to know that.’ It’s about understanding how to filter and structure information – no gotchas, no surprises. I had a boss who told me, ‘When you go in to meet the board, your goal is to come out level. Your stock will never go up at the end of a board meeting – it can only stay level or go down.’ Once you realize that, you stop with the grandstanding, the surprises, the vulnerability-count theater. They don’t care.
Roland Cloutier
I stopped that a long time ago – firewall drops.
Stephen Ward
Exactly. You’ve got to play the game a bit with them. The board isn’t going to give you more budget. You get that from your peers, your CIO, your CFO – it’s not a board-level discussion.
Roland Cloutier
You learned a lot of this from being punched in the face.
Stephen Ward
That’s apparently the only way I learn.
Roland Cloutier
Did you have a mentor – someone you listened to, a general counsel, a CEO – who helped get you where you needed to be?
Stephen Ward
I always gravitated toward women executives. I don’t know why – my mom hugged me when I was little, so maybe that’s it. I had people who never knew they were mentors to me. Teresa, chief legal officer, still is at Home Depot – I loved her, I always went to her with questions, and she was so patient with me. She knew I cared, but she also knew, as I used to joke, that bringing a New Jersey guy down to Atlanta created a bit of a personality gap. She was phenomenal. Before that, at TIAA, it was Annabelle – she was amazing to me – and at J.P. Morgan it was Guy Shirillo. I always say the best mentors are the ones you never asked for and who never offered – it just happens organically. And a lot of the time it was peers – guys like Craig at BofA – where I’d just call and say, ‘Hey, did I just step on a landmine?’ And they’d say, ‘It hasn’t gone off yet, but I think you did.’ It was great having peers to call and say, ‘Help me out here, where am I making a mistake?’
Roland Cloutier
I want to touch on product, since that’s kind of what you do now – you fund companies that build things. How does the future CISO align security with product velocity, AI adoption, and growth without becoming the department of no? We have to get comfortable being uncomfortable, because AI is changing everything, and the speed at which it’s happening – how do we get out of the way and still do our jobs?
Stephen Ward
I think we’re in a weird spot. We’ve had a couple of moments like this before – the proliferation of endpoints, then cloud, and now AI. Three big shifts over thirty years. CISOs are struggling right now because they’re saturated – too many tools, too many people telling them what they can and can’t do, conferences throwing every new technology in their face. I think they’re struggling to get through the noise. I always say cyber doesn’t have a marketing problem, it has a messaging problem – I can’t tell the difference between one company and another based on their website. They all look alike, and that’s frustrating and taxing for operators who want to move fast and buy things but are confused about what’s actually available. So people default to the platform play – Palo Alto, CrowdStrike, and so on. Fine, you can do that, but those companies are innovating through M&A, not organically – I’ll argue that with anyone. So as an operator, do you wait for the platform to catch up, or do you go around it?
Roland Cloutier
You remember Jim Ralph’s famous line – belong to the ten percent club. Take ten percent of everything you do and focus on startups that will solve the problem before the platforms do.
Stephen Ward
That’s exactly what I did. I think we’re going to be able to move a little quicker. Security’s actually a bit of a laggard here, and that’s fine – we don’t have to be the most innovative. I know that sounds strange, but you can watch the technological shift happening with AI and be a little patient, see what the business application actually is, and then figure out what to build and what to buy. I think that’s why this is a bit of a gap year – budgets aren’t through the roof, people aren’t buying a ton, it’s fairly flat.
Roland Cloutier
There’s a lot of work to do – they’re going to have to clean up all the code first. A couple of years of cleanup, and then, once the foundation models stop changing daily, they’ll get to a place where they can make some real bets.
Stephen Ward
Correct. And I think there are probably five or six of the big platform players – public companies – that shouldn’t be here in two years. People can argue with me all day, but we need a technological shift within security so we’re not still using the same tools we were using when we started. If people are still running the same tools today, that’s a problem.
Roland Cloutier
Absolutely crazy. When you look back at the programs you rebuilt – because that’s kind of what you’re known for, going in and fixing things – what separates a program that compounds over time from one that has to be rebuilt every few years?
Stephen Ward
A lot of these programs get rebuilt every few years because companies keep hiring new CISOs every few years. I do a presentation sometimes, and one thing I talk about is: never dog your successor. Someday that’ll be you. I’ve been on both ends of it – I’ve watched people who helped me build something turn around after I left and rebuild it from scratch, and I think, well, were we wrong then? You helped me build it this way – why is it wrong now that I’m gone? I think the folks coming in need to stop thinking they know everything right away. I got scolded a few times for saying, ‘Well, at J.P. Morgan we did it this way,’ and someone would say, ‘You’re at a Fortune 14 retail company – you want to do that, go back to J.P. Morgan. Learn the environment here first, be patient.’ There’s a lot of knee-jerk rebuilding early on because people think they’ll be rewarded for it. On the other side, some programs just aren’t built with good teams – and I don’t think the technology should get blamed for that. TIAA had one of the best teams I’ve ever had, J.P. Morgan was incredible, Home Depot was awesome – we built good programs there. I’m sure there are places that don’t build good programs simply because they don’t have good leaders. Not good cyber experts – good leaders.
Roland Cloutier
It’d be interesting to get a measure of how many security, risk, and privacy programs have purpose-built leadership development for their people.
Stephen Ward
Yeah – sometimes I’d get sent to more technical schools than management ones.
Roland Cloutier
You’ve got to learn the business side, learn how to be a leader.
Stephen Ward
And I don’t think we do a good job of teaching people how to be good leaders. I’ve always had the rule: you can’t be a good leader if you’re not a good person. I’ve never seen it happen otherwise.
Roland Cloutier
Let’s talk about leadership for a minute – this is key. If a CISO wants to build the next generation of security leaders, what should they do differently starting now? Give me a roadmap.
Stephen Ward
I think they need to become better storytellers. Nobody wants to hear about a problem if you can’t tell them why it matters to them – we live in a Netflix, TikTok world. Tell me a story: a beginning, a middle, an end, a climax. How does it benefit me? I didn’t really learn good storytelling until later – I got to see Spike Lee speak once, and I walked away thinking, I’m an idiot, I need to completely change how I do this.
Roland Cloutier
That’s the point, right – when you’re talking to someone and they don’t seem to get it, you have to stop and ask: what are they actually hearing, and why should they care?
Stephen Ward
Exactly. So: how do you become a better storyteller, and how do you build relationships with your peers – can you be a chameleon? I always focused down into the org – it was a military thing, eat with the troops, you don’t send them on a march, you take them on it. But I ignored my peers and the executives, and it killed me sometimes. At Home Depot there were a couple of times I thought I was going to get fired.
Roland Cloutier
I remember one of those calls.
Stephen Ward
Yeah, you call home and say, ‘Honey, don’t leave me now, we’re in it.’ I think the leadership side is really what we need to focus on. We’re fine on the technical and operational side – these people are great executors. You know the type: you hand them something and think, I don’t have to worry about this anymore, they’ve got it.
Roland Cloutier
Execution-oriented.
Stephen Ward
Exactly, that’s all fine. But the number of people who come to me and say, ‘My boss isn’t a good leader, my boss isn’t a good person’ – it’s irritating.
Roland Cloutier
How bad does it have to get before someone tells you their boss isn’t a great leader? Leadership’s a great topic, because you and I come from the same cloth – blue-collar kids who went into the military because there was no other option.
How did your law enforcement and military background shape the way you think about evidence, judgment, accountability, and leadership under pressure? Do you ever look back on that?
Stephen Ward
I do. The military and Secret Service side taught me: if anything good happens, you did it. If anything bad happens, I did it. That translated well into being a CISO – ‘Hey, we got popped yesterday.’ That’s on me, not on the person in ops or engineering. We needed that. It saved me a lot of accountability.
Roland Cloutier
It’s the same mission – we’re all on the same mission. It happened to us as a company, not to me or you, so let’s go fix it.
Stephen Ward
That mindset also made me maniacal – I knew I was never the smartest person in the room, so I’d just outwork everybody, work, work, work – and in some ways I drove the team into the ground, which I regret. The balance came from having a twenty-year-old son with autism, who showed me what it’s like to find amazing things and amazing people, and it softened me.
Roland Cloutier
It takes a long time to get there, doesn’t it?
Stephen Ward
Yes. I wish it had been earlier.
Roland Cloutier
I’ve got two brilliant daughters – I was a girl dad – and you’d think that would soften you, but really they just find their way into your heart.
Stephen Ward
People sometimes ask who my mentors are, and I’ll say my twenty-year-old with autism – I’ve watched him struggle with the simplest things and then seen the joy on his face when he accomplishes something. It’s a lot like cyber: if you can’t see anything good in someone, that’s on you, you’re not looking hard enough. Figure out the right role for the right person, the right personality for the right role. Balance that with the government mindset of ‘excellence is the only option,’ and – I wish I’d learned it earlier in life.
Roland Cloutier
It takes a long time to find the grace that life gives you.
Stephen Ward
I wish I’d had it in my thirties, when I was an arrogant little bastard.
Roland Cloutier
All right, last question – we could do this all day. If a security leader wants to be remembered not just for the program they ran, but for the leaders they built, what should they start doing differently next Monday?
Stephen Ward
You have to shed the insecurity that you can be replaced. Most people hold back on mentoring others because they’re not secure enough to do it – we’ve both reported to people like that. You have to lose that insecurity, be confident that you belong in the role and aren’t afraid of losing it. In a way, you want to be able to say, ‘I want you to replace me.’
Roland Cloutier
Isn’t that the job – build a bench that can replace us tomorrow if we get hit by a missile?
Stephen Ward
Exactly. You fight tooth and nail to get the role, and then once you have it, you don’t want to lose it – but it’s a selfless thing. I still go back and think about how many people I worked with, or who worked for me, who became CISOs, and I love that. If in any way I helped someone get to do what they wanted to do, that’s great. The best compliment I get is someone telling me, ‘You did something selfless for me, and five or ten years later I did the same for someone else. I still remember it.’
Roland Cloutier
I got a call like that this year – it’s amazing, and it comes back to what actually makes you happy. We talked about this before we started recording: I love what I’m doing because I get to watch these new CISOs become successful and run incredible programs, and getting a call a decade later from someone who worked for you three or four levels down – that’s everything.
Stephen Ward
And I love it even more when they’re better than us.
Roland Cloutier
Yeah – when you look at them and think, you’re doing a much better job than I ever did. Teach me.
Stephen Ward
I absolutely love it. I met one the other night who I think is an incredible CISO, because he’s an incredible human being first – everything else is just reps after that. So: lose the insecurity, be selfless, and find people you want more for than you want for yourself.
Roland Cloutier
Words to live by. So if I can sum this up: the future security leader’s legacy won’t be defined by the program they ran. It’ll be defined by the leaders they built, the judgment they taught, the board confidence they created, and the operating models they left behind. AI is going to change the work, but it’s also going to change the expectations of the role. The next-generation CISO has to speak the language of risk, product velocity, data privacy, governance, and business outcomes – because that’s all we’re really doing, delivering business and agency outcomes. And they need to move fast, as Stephen said at the start. You have to figure out when to challenge yourself, when to challenge others, and when to step back and develop someone else to lead the next discussion. It’s a leadership legacy question: are you building a program that depends on you, or one built on the leaders you’re developing? That might be the most important takeaway here. Stephen, I can’t thank you enough – this is always awesome, we don’t get to do it enough, I’ll come find you again.
Stephen Ward
Yes, over some tequila. We’ll do it.
Roland Cloutier
Thank you, brother.
Stephen Ward
Thank you.