CISO Q&A: John J. Masserini On Why A Breach Doesn’t Automatically Mean The CISO Failed

"I'd rather be measured on how fast we found the problem and how well we contained it, not on a perfect record no organization our size has ever achieved," says John J. Masserini, Founder and Managing Partner of SentiCon Security.

Published on Aug 17, 2026
Mirren McDade Written by Mirren McDade
John J. Masserini

John J. Masserini is a cybersecurity executive whose career has spanned more than 30 years, including two decades as CISO across three different organizations.

Today, Masserini runs SentiCon Security, his advisory and virtual CISO practice, where he does interim CISO and board advisory work for Fortune 1000 companies and private equity portfolios. He is also the founding president of BSides South Florida and writes the Chronicles of a CISO blog.

We spoke to Masserini as part of our ongoing series interviewing cybersecurity professionals to bring you their unique insights into cybersecurity today, the challenges they are facing and the realities of what it takes to defend complex global environments

To start, could you tell me a little bit about yourself and your background?

I’ve spent more than 30 years in cybersecurity, the last two decades of it sitting in the CISO chair at three very different organizations. I started at Dow Jones and News Corp, where I ran security and privacy for The Wall Street Journal, Barron’s, MarketWatch, and Factiva.

From there, I went to Miami International Holdings (MIAX Options Exchange), where I built the cybersecurity and resilience program for a SEC and FINRA-regulated electronic trading exchange essentially from scratch, including serving as the primary point of contact to the SEC, FINRA, FBI, Treasury, and DHS. 

My third CISO role was at Millicom International, a multinational mobile telecom, where I led a global security organization across 12 countries and built the SOX 404 control structure that supported our NASDAQ listing.

Today I run SentiCon Security, my own advisory and virtual CISO practice, where I do interim CISO and board advisory work for Fortune 1000 companies and private equity portfolios, mostly in financial services and other regulated industries. I also sit on a handful of boards, and I’ve served on the security advisory councils for numerous VC/PE firms and startups. 

On the side, I write Chronicles of a CISO, a blog I started in 2019 that’s picked up a couple of industry recognitions along the way, and I’m the founding president of BSides South Florida. If there’s a thread running through all of it, it’s that I care much more about whether a security program actually reduces risk for the business than about how it looks on a slide.

What cybersecurity challenges are on your radar right now, and what do you find most CISOs need to do to set their teams up for success in dealing with them?

Three things are really on my radar right now.

The first is identity, and specifically how fast the definition of “identity” is expanding. It used to mean employees and maybe a handful of service accounts. Now every organization I talk to is standing up AI agents and copilots that need credentials, entitlements, and access to systems, often faster than anyone is tracking them. That’s on top of the third-party and supply chain risk that never really went away; it just got more automated.

The second is the widening gap between what regulators and boards expect from a CISO and the authority that CISO actually has. I’ve lived on both sides of that gap, and it’s not getting smaller. I am still seeing a lot of CISOs being “anointed” as a CISO, with the company thinking it’s an easy fix to an audit finding or regulatory concern. Unfortunately, it doesn’t work like that — just because someone is a great technician or architect doesn’t mean they make a great CISO.

The third is something that I’ve seen evolving over the past 6-12 months, and that is a forced staff reduction in the name of AI automation. While AI plays an important role in the SOC, it is not going to replace security architects, engineers, or anyone else who needs to understand the nuances of a company, their business objectives, and the technical infrastructure. Getting executive leadership and boards to understand that AI is not intelligent is not an easy task. 

Additionally, and this one is getting easier to demonstrate, is that the costs associated with AI are extremely high. Remember, the vast majority of enterprises cannot train and run their own AIs, so the “tokenomics” discussion is a real one that needs to happen early.

I guess, overall, the key point is to understand how to translate your program objectives into business language early and often, so that when you need budget or air cover, you’re not starting that conversation from zero.

Since SolarWinds, personal CISO liability has moved from theoretical to real. What are CISOs doing differently to protect themselves that they weren’t a few years ago?

It’s real now in a way it wasn’t a few years ago. When the SEC named the SolarWinds CISO personally alongside the CFO and other executives, it was the first time most of us had seen a security leader treated that way in an enforcement action, and it got everyone’s attention. Thankfully, all of the accusations have been dismissed, but the impact on the industry is everlasting.

What I’ve seen change is that CISOs are finally negotiating for the same protections other executives have always had. Directors’ and officers’ insurance and formal indemnification are now things people ask for before they sign an offer letter, not after something goes wrong. More CISOs are also pushing to get real authority, not just a title, written into how the role is structured, because the SEC and other regulators are holding CISOs to an executive standard even though the majority of them still don’t report to the CEO, and a majority of them sit inside IT rather than as peers to it.

One of the changes I am happy to see is that many CISOs are taking time to take care of themselves. Burnout is a real thing; I’ve always said, “I don’t have a career, I have a lifestyle that pays the bills,” and I meant it. My wife and kids can all share stories of lost weekends, 2 AM conference calls, and missed school functions and family gatherings. Seeing CISOs prioritize their personal well-being shows how expectations of the role are changing as well.

AI copilots and agentic bots are dominating the security conversation right now. Do you think there are any fundamentals being neglected as a result?

Yes, and it’s not really AI’s fault. AI is just exposing gaps that were already widely systemic in most organizations. I still walk into organizations that can’t give me a clean answer to “what’s on our network” or “who has access to what,” and those same organizations are now bolting agentic AI tools on top of those unknowns. An agent that can take autonomous action is only as safe as the identity and access controls underneath it, and in a lot of shops those controls were shaky before AI ever showed up.

The fundamentals that get neglected are the boring ones: asset inventory, patch and vulnerability management, least privilege, multifactor authentication, and logging that’s actually reviewed rather than just collected. None of that is exciting to talk about at a board meeting compared to agentic AI, but it’s what determines whether an AI incident is a contained event or a headline. My advice is to keep investing in the fundamentals at the same time you’re standing up AI governance, not instead of it.

As a three-time CISO, is there a specific mistake from your first time in the seat that still shapes how you approach the first 90 days now?

At Dow Jones, in my first CISO role, I made the classic new leader mistake. I showed up with a technology roadmap before I really understood the business, the politics, or who actually held budget and decision rights. I assumed that because I had the title, I had the authority to go with it. I spent a lot of energy in year one pushing initiatives that didn’t have real executive sponsorship behind them. They weren’t bad plans, and eventually we executed on them, but the approach could have definitely been handled better.

Now, in the first 90 days, I don’t touch a roadmap or make a suggestion until I’ve done a lot of listening. I meet the audit committee and board members directly if I can get access to them. I map out who actually controls budget, who controls patching, who controls identity, because it’s rarely all sitting with the CISO. I spend time understanding the business’s real goals and risk appetite instead of assuming it matches mine. Only after that do I start building a plan, and even then, I make sure it has a sponsor who isn’t me before I put it in front of the board. It’s a slower start, but it holds up a lot better under pressure.

When a CISO is deciding whether to accept a role, or whether to stay in one, what are the warning signs that the role isn’t set up for the CISO to succeed?

There are a few things I tell people to watch for. If the CISO direct-line reports to the CIO or doesn’t have direct access to the board or audit committee, that’s worth asking hard questions about, because research consistently shows only a small fraction of CISOs get that kind of access, and it correlates with how much real authority the role has. If security sits several layers down inside IT with no separate budget line, that’s another sign the role is structured as a cost center rather than a risk function. And this isn’t something that only occurs during the hiring process. Management shakeups, reorganizations, or mergers can all move the security function under leadership where there ends up being a fundamental conflict.

I’d also pay attention to how the hiring conversation itself goes. If everyone promises unlimited support but nobody can say who actually owns the budget or the incident response decision rights, that’s a company that hasn’t thought through what it’s asking the CISO to do. If a company is hiring a CISO for the first time specifically to sign off on a SOC 2 or a customer questionnaire, and that’s the primary job description, be honest about whether that’s a security program or a compliance artifact. And finally, look at the seat’s history. If three people have held the CISO role in the last five years, that tells you something the job description won’t.

Between your board advisory work and your vCISO practice, you see a lot of different security programs from the outside. What’s the difference between a security program that’s actually reducing risk and one that’s just checking boxes?

From the outside, looking at a lot of different programs through board and advisory work, the difference shows up pretty quickly. In a program that’s actually reducing risk, leadership can tell you their top handful of risks in plain business language, and their metrics move over time in a way that’s tied to real outcomes, faster detection, fewer repeat findings, better third-party visibility, not just an audit pass rate. Incident response gets tested regularly, not just documented and filed away. And when I ask what would happen in a specific bad scenario, I get a real answer instead of a shrug.

A checkbox program looks fine on paper. The policies exist, the certifications are current, the vendor questionnaires are answered. But the security team is disconnected from the business units, the controls that get tested are the ones the auditor is going to look at, and the whole program is optimized around passing the next assessment, rather than around trying to reduce organizational risk. I’ve seen certified companies get breached and poorly certified companies handle incidents beautifully, and the difference almost always comes down to whether risk management is a living practice or an annual checkbox event.

AI agents are being deployed faster than the controls to govern them. From your work with security leaders, what does an identity foundation for safe AI agent deployment actually look like, and what’s the biggest shift in thinking that has to happen to get there?

An identity foundation for AI agents looks a lot like what we’ve spent the last few years building for zero trust, just applied to a new category of actor. Every agent needs its own identity, not a shared service account. Its entitlements need to be scoped tightly to what it actually needs to do, its credentials need to be short-lived and automatically rotated rather than long-standing secrets sitting in a config file, and every action it takes needs to be logged in a way that maps back to a human owner or a business process that’s accountable for it. Organizations also need a real deprovisioning path, because agents get spun up quickly and often outlive the project that created them.

The biggest shift in thinking has to be to start treating machine and agent identities as first-class citizens in the identity program, not as an afterthought bolted onto human identity management. For years, IAM programs were built around people logging in. Now agents are authenticating to other agents, taking actions autonomously, sometimes spinning up more agents, and a lot of that is happening inside business units without security ever seeing it, which is the shadow IT problem from a decade ago except faster and with more autonomy. Until security leaders start counting and governing non-human identities with the same rigor as human ones, agentic AI is going to keep outrunning the controls meant to govern it.

What’s a widely held belief in the cybersecurity industry that you disagree with, or think needs to be challenged?

I disagree with the idea that a breach automatically means the CISO failed. That belief drives some genuinely bad behavior, as we’ve seen with other SEC actions. It pushes organizations toward hiding near misses instead of learning from them, and it pushes some CISOs toward chasing an unrealistic zero incident goal instead of building a program that can actually detect, contain, and recover quickly when something does happen, because something eventually will. A large part of that onus belongs to the CISO and how they articulate the risk, but that doesn’t necessarily equate to failure.

I’d rather be measured on how fast we found the problem, how well we contained it, and how much better the organization was afterward, than on whether we achieved a perfect record that no organization our size has ever actually achieved. Boards that understand this get better security programs, because their CISOs are honest with them instead of managing the narrative.

What advice would you give to fellow CISOs and industry practitioners?

Get a mentor who’s already sat in the seat, and then become one yourself once you’ve got some scar tissue. This industry is small, and it’s a lot healthier when experienced people are actually helping the next group coming up. I mentor recent college grads up through CISO, and while the topics and curriculum are different, having someone to talk to or bounce ideas off of is invaluable. This is also why I stay involved with groups like Cyversity and BSides South Florida.

Also, they need to protect themselves early. Understand your indemnification and D&O coverage before you take the job, not after something goes wrong. Get genuinely fluent in how your board and audit committee think about risk, because that fluency is what turns you from a cost center into a trusted advisor. Don’t let AI hype pull your attention off the fundamentals like identity, patching, logging, and incident response readiness are still what separate the programs that hold up from the ones that don’t. And play the long game. I’ve been doing this more than 30 years, and the CISOs I respect most are the ones who built their reputations slowly, on judgment and consistency, rather than trying to make a splash in year one.

This field is for validation purposes and should be left unchanged.

FREE NEWSLETTER

Cyber Weekly

Get curated cybersecurity news, threats and insights delivered free every Thursday.

Written By Written By
Mirren McDade
Mirren McDade Journalist & Content Writer

Mirren McDade is a senior writer and journalist at Expert Insights, spending each day researching, writing, editing and publishing content, covering a variety of topics and solutions, and interviewing industry experts.

She is an experienced copywriter with a background in a range of industries, including cloud business technologies, cloud security, information security and cyber security, and has conducted interviews with several industry experts.

Mirren holds a First Class Honors degree in English from Edinburgh Napier University.