Alyssa Miller is a cybersecurity executive, author, and board director whose cybersecurity journey began in childhood as a hacker and spanned across more than two decades of cybersecurity leadership.
Miller spent 15 years at a financial services company, moving from software developer into pentesting and security leadership, followed by a decade in consulting. She later returned to financial services as BISO at S&P Global Ratings, before joining Epiq Global as CISO. Named a “Board Director to Watch” in 2025, she now serves as a CISO Advisor and Board Member at Epiphany Solution Group, sits on the CxO Advisory Council at Evolve Security, and is on the Board of Advisors for Blue Team Con.
We spoke to Miller as part of our ongoing series interviewing cybersecurity professionals to bring you their unique insights into cybersecurity today, the challenges they are facing and the realities of what it takes to defend complex global environments.
To start, could you tell me a little bit about yourself and your background?
My origin story starts when I was 12. I got a paper route, saved up some money, bought a computer and shortly after accomplished my first hack: I was able to get into a dial-up community service without a paid account. A few years later after the internet became publicly accessible, I found my people in the hacker channels in IRC.
While I was still in college, and in the middle of the dot com era, I was able to secure my first full time job as a programmer at the age of 19. After 9 years of doing software development for a multi-national financial services company, I pivoted into security where I lead their security test team which had responsibility for all penetration testing, application security, and vulnerability management.
Since then, I’ve held roles with increasing levels of leadership capacity in consulting, channel/reseller, startup, and corporate roles. My most recent role for the last four years was as the CISO for New York-based Epiq Global. I also serve on the board for Epiphany Solutions Group and the CXO Advisory Council for Evolve Security.
What cybersecurity challenges are on your radar right now, and what do you find most CISOs need to do to set their teams up for success in dealing with them?
AI has been talked about a lot. Unfortunately, the conversation seems to be heavily focused on the threats of AI. At Epiq, our team was focused on four core pillars.
First was the AI technology in use in our corporate platforms. How do we secure each and every third-party technology that’s bringing some level of AI capability to bear?
Second was our own internal R&D and product development. Epiq has heavily invested in transforming their business through adoption of those capabilities and we needed to be on top of ensuring that those platforms were secure without getting in the way or causing friction as those teams continued to innovate.
Third was the one that everyone seems to be talking about, which is the threat of AI technologies finding and exploiting vulnerabilities and weaknesses. It’s getting a lot of press lately, especially as more and more solutions providers add it to their marketing messages.
Fourth, and the area I was most excited about and that I don’t think gets enough chatter is, is how do we in security make meaningful use and drive business value out of our own AI agents and models? I see a significant field of growth here that’s only just starting to be tapped into.
On LinkedIn you’ve argued the CISO’s job is to simplify complexity and “bring guidance, not raw data” to the board, and that CISOs should stop defaulting to numerical metrics in board reporting. What does a board report look like when a CISO does that well, and what should they stop putting on the deck?
One of the biggest frustrations I’ve heard from directors on boards that I’ve consulted with or even presented to myself have been that CISOs spend too much time in the minutia and technical aspects of the job and fail to understand the business and it’s needs.
When CISOs come to a board meeting with a bunch of numbers about vulnerabilities, mean-time-to-detect, mean-time-to-resolve, etc., it doesn’t speak to what the board is concerned with. The board wants to know how the business is growing, how it’s positioning itself as a leader in the market, where innovation is happening, and what needs to be done to ensure the success of that growth strategy. Yes, risks to that strategy are discussed and must be called out, but they can’t be the only story, and they need to be discussed at that macro level.
I coach CISOs to bring to the board a clear understanding of the business, its growth strategy, the headwinds it faces in the market and a clear narrative of how our security posture can help support that strategy and/or reduce the impact of those headwinds.
Our presentations should present a roadmap for our security program that aligns directly with the goals of the business divisions and shows tangible value beyond risk avoidance or mitigation. CISOs should be speaking in terms of how we’re reducing costs, reducing complexity, driving organizational efficiency, enabling additional revenue channels or growth, improving the customer experience, etc. Presenting and then tracking to that roadmap shows that we understand our role as business executives, not just cybersecurity experts.
In a recent LinkedIn post you pushed back on black-box and point-in-time pen tests, saying they “only serve to handicap ourselves.” What should CISOs be buying instead, and how do they push back on vendors still selling that model?
Over my career I’ve watched the regular point-in-time penetration tests become commoditized. Most organizations engage in penetration testing simply for compliance purposes: a contractual obligation, a regulatory requirement, or an internal policy mandate. However, what gets missed in a lot of organizations is how to turn the results of that testing into meaningful outcomes in terms of improving security posture.
As a pen tester, I had those customers that we’d test year after year and always find the same vulnerabilities, unaddressed from the previous report. Large point-in-time tests result in the same noise and overwhelming laundry list of to-do’s that we get out of our vulnerability scanners. Value comes when discovery and action are a part of our daily operations. “Continuous” pen-testing that feeds automation to prioritize and respond to those discovered vulnerabilities is key. Meaningful engagement in DevOps pipelines that doesn’t introduce friction and gates, but instead accelerates deployment cycles so development teams can be more agile in addressing discovered security flaws. These are tenants we need to focus on, rather than a once-a-year test that costs us 5 to 6 figures and leaves us with limited value.
What’s the specific move a CISO should make in the first 30 minutes of a serious breach, and how do they avoid the classic traps of over-explaining, defending past decisions, or sharing more detail than the moment requires?
In the first 30 minutes it is all about getting the right “first responders” engaged. There is a bias in these situations away from declaring an incident because that brings with it a lot of legal implications. However, failing to recognize it early and accept the reality leads to ad-hoc response activities that can extend the timeline of containment, and in many, cases actually tip off the attackers who then may shift into further detection avoidance and persistence strategies.
During these times, the CISO is going to be pressured by the rest of the executive team and potentially the board to not only deliver a clear picture of the extent of the impact but also the root cause. Obviously, we can’t know those things that early. However, if we have a good, methodical incident response plan and playbooks to point to, and we radically accept the situation we’re in by declaring an incident, we can now point to that process and our progress in executing each of the steps. This helps set reasonable expectations but also helps prevent distractions from the most crucial activities as we work to recover.
Cybersecurity is still commonly framed as an IT function inside most organizations, even though the threats it manages clearly aren’t just technical. What’s the practical move a CISO makes to reset how the business sees it?
It’s important for the CISO to partner with all areas of the business and show the impacts we’re making outside of just technology. For instance, HR teams today are dealing with the real threat of fraudulent remote workers, particularly from North Korea. This is not a technology problem, and it requires a response that spans process changes, technology capabilities, and people- centric education. However, HR Teams don’t usually have a lot of expertise in addressing threats like this, so the cybersecurity team has an important role to play here in leading the effort by demonstrating good threat analysis, creative problem solving, and implementation of mitigations.
As a former CISO now on the board side, what’s the biggest disconnect between how CISOs think they’re coming across to boards and how boards actually receive them?
CISOs focus far too heavily on risk mitigation and reduction. I know many who see risk management as the core of their job responsibility, but that’s just not true. Every C-Level executive in the room is responsible for risk management, that’s just a facet of wearing that title.
However, each executive brings a unique skillset to bear that helps drive overall business success. While a CFO focuses on reducing financial risks, they drive business outcomes through responding to market conditions, interest rate trends, etc. While HR is focused on reducing the risks of running afoul of employment laws and regulations, they drive business outcomes by recruiting highly skilled individuals, reducing the costs of turnover by maintaining a strong corporate culture, etc. CISOs need to look at it the same way.
Yes, we work to reduce the impact of cybersecurity risk, but what are we bringing to the table that directly drives successful business outcomes? That’s what boards want to hear about, and that’s where we find a massive disconnect between the CISO and the board.
AI is now baked into every CISO conversation. What’s the specific AI decision CISOs are getting wrong right now that they’ll regret in 18 months?
I honestly think the over-indexing on the risks of AI and the failure to fully embrace its capabilities will be terribly impactful in the coming year. Not only do we have the opportunity to greatly expand our capabilities through use of these technologies, developing and working with them also equips our teams with very necessary expertise that will allow them to better respond to the threats that everyone is talking about. Unfortunately, it seems like every CISO conversation I’ve been in over the last 6-9 months has focused on the threats of attackers using AI, not excitement over how we can leverage it to our own advantage.
What’s a widely held belief in the cybersecurity industry that you disagree with, or think needs to be challenged?
That technical cybersecurity knowledge is the most important aspect of the CISO’s role. It’s not. We are business executives. Yes, having a level of proficiency in the technical aspects of cybersecurity is important, but that’s not the primary skillset required for a CISO.
CIOs aren’t expected to have deep technical capabilities. They’re expected to lay out a technology strategy that empowers business goals and then build and lead a team of skilled individuals who can implement that strategy. That’s how CISOs need to be seen as well. But unfortunately, I think we have a tendency to be pigeonholed (and maybe it’s self-inflicted as well) as professionals who are constantly mired in the threats of the world around us rather than building out solid strategies that empower the business to grow.
We tell ourselves and our organizations that reducing risk is how we enable the business, but that’s just not a true statement. Unfortunately, we’ve built a ton of messaging on that fallacy, and it has resulted in CISOs not being valued at the same level as other C-suite executives.
What advice would you give to fellow CISOs and industry practitioners?
Get an MBA, read the book “The 10 Day MBA”, or at least find some other way to become more strongly versed in the language, theories, and concepts that business leaders are focused on. We need to be part of the business leadership but if we can’t understand those core concepts that drive business decisions, we’ll always be on the outside looking in.