CISO Q&A: Ali Waezzadah On Why Technical Skills No Longer Make A Successful CISO

"The tools you're choosing between today will change in two years anyway. The business skills won't," says Ali Waezzadah, CISO at iCOUNTER.

Published on Sep 22, 2026
Mirren McDade Written by Mirren McDade
Ali Waezzadah CISO Interview

Ali Waezzadah is a cybersecurity executive whose career has spanned more than two decades of building and rebuilding security programs across government, media, telecom, and cybersecurity products.

Waezzadah has held senior security roles at Kroll, CBS, Paramount, and Frontier Communications, most recently serving as SVP and CISO at Frontier, where he rebuilt the security organization as the company came out of filing for Chapter 11. That turnaround ended in Verizon acquiring Frontier for $20 billion in early 2026.

Today, Waezzadah is CISO at iCOUNTER, a cybersecurity company that came out of stealth earlier this year. He is also an author and long-time mentor to the next generation of cybersecurity professionals.

We spoke to Waezzadah as part of our ongoing series interviewing cybersecurity professionals to bring you their unique insights into cybersecurity today, the challenges they are facing, and the realities of what it takes to defend complex global environments.

Q1. To start, could you tell me a little bit about yourself and your background?

Like a lot of security professionals of my generation, I started in a technical field, in my case as a system and network engineer in the late 90s. Cybersecurity was around before that, but less structured outside of  defense departments and big financial institutions. After the dot-com era, it started to become  more mainstream, and I saw an opportunity to shift my focus.

My first foray into building a cybersecurity program was at ICF International, which was going public at the time. This was also around when Sarbanes-Oxley was coming into the picture in the early 2000s, so we were building cybersecurity for the first time at a company standing on its own. A few of us came together from the technology team and built the program from policy through to technical capabilities. 

From there I just became known as the person who comes in and builds or transforms. Every role since, from Kroll to CBS to Paramount to Frontier, has been either something that wasn’t there and had to be built, or something that wasn’t quite right and had to be restructured to meet what the company was dealing with then and going forward.

Q2. You’re three months into a new role with a team you’re still building. What are you dealing with day to day, and how does that contrast with where you were earlier this year at Frontier?

It’s a night and day difference. Frontier was a 100-year-old company that had been mismanaged: 15,000 employees, multi-billion dollars, going through a turnaround. iCOUNTER is a startup that just came out of stealth earlier this year. I posted the first opening about 45 days ago and the hired person , started today — I’m meeting with him right after this.

When you step from a multibillion dollar rcompany with  cybersecurity team to one where it’s just you, things are going to different. The fundamentals of building a security program are the same, but the scale of what you personally handle changes completely. There’s no team where you can say, “this group will handle that, that team will handle this.” You have to come up with the strategy, the plan, the execution, and do all the follow-ups yourself. We just wrapped up our SOC 2 Type 1 and have Type 2 later this year, and it was just me and two of my IT colleagues managing the auditors and the internal work. So, time management becomes much more important. You have to prioritize dynamically, and stretch yourself across strategy, planning, operations, and anything else that comes across your desk.

I actually wanted to take six months off after Verizon to rest and finish my book, “The Cybersecurity Compass”. I’d done multiple CISO roles and turnarounds, and I thought I’d earned a break. Then Joel Molinoff, who I used to work with at CBS, called me. He’d just become COO here, and the founder of iCOUNTER, John Watters is one of the pioneers of the industry. Joel said, “Consider this a break from what you were doing before.” It’s still work, but it’s a chance to be at the cutting edge of building security products and services, with no legacy tech debt. This company is foundationally AI-native. Not every CISO gets to be this close to product development, from the idea to something going to market. That was the intriguing part for me.

Q3. Looking at your security leadership career, a lot of it has been during some kind of structural upheaval. First CISO at Kroll unifying acquired businesses, deputy to CBS’s first CISO building out their security programme, interim CISO through the CBS and Viacom merger, then Frontier through a post-Chapter 11 turnaround and an acquisition. What does that kind of work teach you that a stable environment doesn’t?

There’s going to be a point in my career where I want to sit and just turn the dials and not do anything exhausting. But I’ve always liked building and looking at the possibility of things, so that hasn’t been where I’ve landed so far.

Early in my career, I was fortunate to find mentors and advisors who’d gone through similar journeys, and one of the things they taught me is that, just like exercise, you don’t get stronger doing basic things. If you want to grow and be able to do things most people can’t, you have to put yourself under growing pressure. Your muscles, your body, your mental capacity — all of it. That’s how you tap into what I call hidden capabilities. All of us have capabilities that are just below the surface, but they need something to allow them to break through.

The only way I’ve found to build the professional muscles you need, and to unleash the things you’re not even aware of, is to put yourself in places that are complex and difficult. When you step in there, you have to say, “holy moly, what did I get myself into?” To be honest, that was my reaction in the first week of every role I’ve ever taken. Then you organise yourself and move on.

There’s a saying from an 6h century philosopher that I quote in my book: it’s easy to remain calm when you’re not provoked;  real peace is only seen when you’re provoked. Provoking isn’t a bad thing here — it’s how you keep your abilities sharp. If you want to keep an ability, you have to provoke it.

Q4. At Frontier you rebuilt the security organization while the company was coming out of Chapter 11, so with very little money and a lot of pressure to show results. Plenty of CISOs are working under some version of that. What do you prioritize first when you can’t fund everything?

When I joined Frontier, we were just at the tail end of the COVID madness. The investors had come in and fired the entire board and executive suite, so almost everyone at the top was new when I arrived. They are really accomplished executives and professionals who, l don’t shy away from a challenge.

At my first in-person leadership meeting in Dallas, I had a side conversation with our CEO, Nick. I said, “I can move fast. How fast do you want me to move?” And in his British accent, he laughed and said, “Move as fast as you can, we’ll tell you when to slow down.” That framed everything.

We came up with four principles that shaped our strategy. First, we’re business-focused, because at the end of the day, if the business doesn’t turn around, none of us have a job. Second, we’re risk-based — everything we do has to tie back to tangible risk reduction, not theoretical risk. Third, we’re technology-driven. And fourth, we’re always learning. When we closed the acquisition and the Verizon CISO asked how we’d built our program, I gave her these four principles. She like them and smilingly said, I’ll take these.

The other rule we set was to work on three maybe four things at a time. Every time my management team came to me wanting to do six or seven, I’d say no — tell me the three things you can actually finish. Not that four, five, and six wouldn’t get done eventually, but I’d rather finish three and move on than have ten in flight and none complete after a year. Execution and completion matter much more than a roadmap you never reach the end of. 

I’ve seen a lot of people talk about milestones, and milestones are great, but if they don’t reach an end point, they don’t add up to anything. We drove hard as a team on making sure our milestones actually led somewhere, instead of being milestones for the sake of milestones.

Q5. You told me that security teams are human and emotional beings navigating all this. During the Frontier acquisition, your team would have known their jobs might not survive it. How did you lead through that?

One of the lessons I learned early on is that you have to respect your team’s ability to handle good things and bad things. Don’t try to shield them because you think they might freak out. Your team is not so fragile.

When we got the nod to share the news, we brought the team together and laid out the whole journey. This wasn’t going to be a surprise to anyone. At some point, Frontier was either going to get more capital and acquire other players to become a bigger behemoth itself, or it was going to be acquired by one of the big players. Option A had happened. We now had a 12- to 18-month regulatory approval runway ahead of us, and we all hoped it would get done, but nothing was guaranteed. In the end, it took almost 16 months to go from signing to close because of all the state and federal approvals required for what we do.

What was critical was that nothing about our day-to-day changed during that time. That message came top-down from Nick: there’s a reason somebody wants to buy us — because we’re performing well — and we need to keep doing that all the way through. For everyone working there, the message was: if you want a future in the acquiring company, they need to see the calibre of professional you are. 

I told the security team the same thing. I’d handle the executive-level drama (like  integration planning) and my management team and I would keep them informed along the way. Every month at our team meeting, Verizon was on the agenda, and we answered every question openly based on what we knew. We didn’t shy away from the hard ones. When will Verizon decide about what tools to retire or people they will keep— those conversations happened. But we made trainings and capability development available, so the message was consistent: if you do well, you’re in a good position, whether that’s staying on inside Verizon or moving on to somewhere else.

Once you build that trust, your team keeps focused. Continuous conversation was the key — not a one-off at the start and another one before close, but throughout. To be honest, we had one departure during that period. In fact, another person who had left before the deal actually came back.

Q6. At Paramount, you ran the post-merger integration of the CBS and Viacom security teams. What’s the hardest part of merging two security organizations — is it the tooling, the processes, or the people?

All of the above, honestly. To understand the difficulty, you have to know that CBS and Viacom were culturally very different companies. CBS was more traditional media — Broadcast, Sports, Showtime, Simon and Schuster — and financially very conservative. Our CO/COO, Joe Ianniello, who briefly became acting CEO after Leslie Moonves left, was known for being disciplined.

Viacom was the cool comp: MTV, VH1, the cable brands, Paramount Studios. Their financial discipline was different.. In relative term they had spent more and had higher budget. . At CBS, we’d go through a more intensive process: how does this fit our investment strategy? How does this look over the next three to five years?

So right off the bat, we noticed that Viacom had a lot more tools than we did. Bringing the teams together meant telling the CBS side, “Let’s be a bit less conservative, we need to move faster,” and telling the Viacom side, “Let’s slow down a bit. Before we buy that thing, or implement that change, take some time to figure out what it actually means, especially now that we’re bringing everything together.”

Because of that, the culture clash was real. The Viacom team felt like they were being slowed down, and the CBS team felt like they were being hurried. Trying to take the best of each and build a new one was the hardest part. There were strong people across managers, directors, and VPs on both sides, and there was genuine emotional attachment to specific tools, consultants, and providers.

You have to listen, understand the differences, and do your best to reach consensus. But you also have to know that at some point, you just have to step in and say, “This is how we’re going, and everybody comes along.”

Q7. You’ve been the first CISO at a company more than once. What do you know now about starting a security programme from nothing that you didn’t the first time?

One of the things I learned early on is that you have to have conversations across all levels of the organization, all the way up to the board, at the very beginning. In my earlier roles, we just started building things. Then we’d go to the business with what we’d built, and they’d have questions and concerns and we’d have to go back and rework it. I know spending time on those upfront conversations can feel like a waste or like diplomatic nonsense to some people, but it’s essential.

There are really five simple questions you should ask each executive stakeholder (the CFO, the CEO, HR). Firstly, ask them what cybersecurity means to them. Ask what they think of the existing cybersecurity team, and how it has or hasn’t helped them. Ask what they think we should be doing less of, and what we should be doing more of. And finally, ask how they want to be involved, where they get their cybersecurity information, and whether they want to be an active participant or just be kept informed.

Then, when you come back with a strategy, it should map to conversations they remember and can connect to. And when you’re having these conversations, sit quietly and listen. Even if what you hear seems completely irrelevant in your opinion, listen without judgment. That executive may end up being your strongest supporter down the road.

The other thing I now do in the first 90 days of every role is set up what I call a Cybersecurity Council. Its members are executive representatives from finance, HR, legal, technology, and the business. It meets every two months, or every quarter. We talk about what’s been done, what’s coming, what the challenges are, and how they can each support the program.

The key thing is to put an executive in the chair, not the CISO. You want the Council to be seen as a business function, not a security team’s initiative. In my roles, the chair has been the CEO, the CFO, or someone reporting directly to the CEO. That sets a completely different precedent for executive engagement. And it means that if someone in the department  raises a concern about something the security team is doing, that executive can say, “I know about this. I was involved. Continue working on it.” That’s how you avoid escalations that stop you dead in your tracks.

Q8. You’ve said the technical skills that got most CISOs into the field aren’t what will make them successful today. What has to replace them?

When I was coming up, you couldn’t go to school and get a cybersecurity degree. Most of us came out of some technical field — development, engineering, infrastructure — and shifted into security as it grew. Now you can graduate with a cybersecurity degree and dive straight into the profession. The technical stuff is certainly important, but it’s not what makes a successful security professional, whether you’re an analyst or a CISO. That’s actually the core premise of my book.

If you strip the job down, what is the discipline of cybersecurity really for? People say things like “protect the company” — but what does that actually mean? At the end of the day, you can’t protect the company from everything that’s out there. So, the role becomes three things.

First, you’re a risk advisor. Your job is to bring visibility to the risks the organization faces, and to do it clearly. Even if there’s nothing that can be done, you still bring visibility, because you don’t want the business coming back later saying, “Had you told me this, I would have done X.”

Second, you’re a solution provider. You explain the options for dealing with that risk. Some are expensive, some are cheap, some are more process oriented. 

And third, you see it through. Sometimes something gets approved and then it hands off from department to department, and by the time it finishes, no one is entirely sure whether it actually got done. That end-to-end ownership is on you.

So today, the skills that separate a successful security professional from a struggling one are business acumen, financial understanding, communication, team management, risk management, and to some extent conflict resolution. Those are what make or break the career of someone on the CISO path. The tools you’re choosing between today will change in two years anyway. The business skills have longer life. 

Q9. You told me the fundamentals are still relevant, but the strategy and management around them needs to adapt. What specifically has to change, and what should stay exactly as it is?

I hear a lot of people at gatherings right now saying everything is upended and that we don’t need to do this or that anymore because AI has made it irrelevant (data classification is one I hear used as an example). But I disagree.

Take vulnerability management. It is still fundamental, but done differently now. Historically, patches would come out at regular intervals, you’d take the CVE scores from MITRE, push them out to the organization, and try to get a clean bill of health. That’s going to be hard to implement going forward. There are just so many vulnerabilities coming out now, in part because AI is uncovering more than anyone can get their hands around. When someone says, “There’s a vulnerability, it’s a CVE 9.5, it’s exploitable” — okay, what does that actually mean for your operations? Much more work has to happen to map that severity score to what actually matters, and the speed of patching has to increase. So, the fundamental is the same, but the mindset and method has to change.

Same with security awareness. It’s also still a fundamental, but today it’s not enough to run a static annual training programme, do your phishing tests once, and be done. The next generations coming into the workspace have shorter attention spans and will remember less from that kind of training. You have to be much more engaging and dynamic.

At Frontier, we did a nice example of this. Our training lead, Benjamin, wanted to make our monthly awareness content more relevant as AI took off. So, he created a cybersecurity radio segment: two voices having a natural conversation about a trending security topic. Both voices were AI, but it was completely convincing. Only afterwards did we reveal that the hosts weren’t real. 

The point was to show the audience what AI-generated content can now do, and how unreliable their instincts for spotting what’s real had become. So, the how, the agility, and the prioritization all have to be revisited. The fundamentals stay; the method around managing them has to evolve.

Q10. Coming into a new organization this year, was there anything you’d been doing for years that you decided not to carry over?

This is one I want to say carefully because it’s about talent management. What I’ve stopped doing is giving longer runways for senior people to prove themselves.

Earlier in my career, I’d give people more chances, particularly at senior level. But if you’re in a place that needs a turnaround or a build-out, the luxury of waiting is not really there. What I’ve found is that when a senior member isn’t operating at the level you need in their first six months to a year, the likelihood of them turning it around is low. Cybersecurity is not for the faint of heart or for the average. If a senior person can’t operate at that level from the start, keeping them in place sets a bad example and pushes burden onto the teams that are actually doing the work.

For juniors, it’s completely different. You want to give them time and space to learn. But for senior hires, in an agile or build environment, drawn-out personnel decisions cause more harm than the difficult conversation of making a change earlier. I actually wrote about this in my book — one of the things I said I’d do differently in the future is not wait too long to make those decisions.

Q11. What advice would you give to fellow CISOs and industry practitioners?

Most of my advice for fellow CISOs is on the human side, not the technical side, because a lot of CISOs I know are smarter than me on the technical stuff. 

Every year, there’s another article about burnout at the CISO and leadership levels, and I know CISOs who have simply left.

The thing your team looks to you for is the ability to live and do this job at the same time. That doesn’t mean everyone has to have an awesome sense of humor and go to sararis, but show them your lighter side and how you disconnect.  Connect with your team on an emotional and human level. In my monthly meetings, I’ll often talk about something goofy I did that was semi-embarrassing, and people laugh about it. It’s okay to show that you’re human, that you fail, that you make mistakes. When your team sees that same person turn around and drive something significant forward, they understand that your perceived weaknesses or vulnerabilities don’t take away from your ability to execute something hard.

Do it genuinely, though. Don’t try to be funny if it difficult and you have to force it.. What I’ve seen is that the security teams that stay are the ones whose leadership have connected with them beyond just the financial and transactional sides of the job. Retention is best when the team connects with their leadership, especially with the CISO, on an emotional and human level. If you’re always on, always serious, and you come across as difficult to approach, it takes a toll on you, and it takes a toll on your team.


This field is for validation purposes and should be left unchanged.

FREE NEWSLETTER

Cyber Weekly

Get curated cybersecurity news, threats and insights delivered free every Thursday.

Written By Written By
Mirren McDade
Mirren McDade Journalist & Content Writer

Mirren McDade is a senior writer and journalist at Expert Insights, spending each day researching, writing, editing and publishing content, covering a variety of topics and solutions, and interviewing industry experts.

She is an experienced copywriter with a background in a range of industries, including cloud business technologies, cloud security, information security and cyber security, and has conducted interviews with several industry experts.

Mirren holds a First Class Honors degree in English from Edinburgh Napier University.