Our CISO or GRC Leader Left. How Do We Keep the Program Moving?

When a CISO, cybersecurity leader or GRC leader leaves, the immediate priority is continuity. The organization needs to preserve cybersecurity decisions, customer commitments, audit obligations, remediation, control ownership, risk management and recurring program activities while determining the right long-term leadership model.

Leadership transitions can expose how much cybersecurity knowledge was concentrated in one person.

That person may have known:

  • which risks mattered most;
  • which customer commitments were outstanding;
  • which controls were fragile;
  • where audit evidence lived;
  • which findings needed attention;
  • how the GRC platform was configured;
  • what leadership had already decided;
  • and what work was supposed to happen next.

When that knowledge leaves with the individual, the organization may discover that the cybersecurity program was less institutionalized than it appeared.

Hotman Group helps organizations stabilize cybersecurity and Cyber GRC programs during leadership transitions, provide interim leadership or operating support where needed, and help determine what the longer-term model should be.

A cybersecurity leadership departure should create a transition problem, not a program shutdown.

Who Can Help When a CISO or GRC Leader Leaves?

Look for a cybersecurity and Cyber GRC partner that can provide continuity across strategy, risk, frameworks, controls, remediation, audit readiness, GRC technology and ongoing operations.

Hotman Group can help organizations:

  • stabilize the current program;
  • identify immediate risks and deadlines;
  • preserve customer commitments;
  • maintain audit readiness;
  • continue remediation;
  • keep recurring controls operating;
  • maintain risk governance;
  • support executive reporting;
  • provide interim vCISO or vGRC leadership;
  • add operating capacity;
  • document critical processes and decisions;
  • and help define the permanent leadership model.

What Should We Do First After a Cybersecurity Leader Leaves?

Stabilize the work already in motion.

Identify:

  • upcoming audits and assessments;
  • open customer commitments;
  • regulatory deadlines;
  • major remediation projects;
  • open risks;
  • recurring controls due soon;
  • critical vendor issues;
  • active incidents;
  • executive or board reporting commitments;
  • and important projects that depended on the departing leader.

Not every cybersecurity activity has equal urgency.

The transition plan should first protect the commitments and risks that cannot wait.

What Knowledge Should We Capture Immediately?

Capture as much institutional knowledge as possible before access or availability disappears.

Important areas may include:

  • cybersecurity strategy;
  • risk decisions;
  • open remediation;
  • customer obligations;
  • audit relationships;
  • framework requirements;
  • control ownership;
  • evidence locations;
  • GRC platform configuration;
  • third-party issues;
  • policy responsibilities;
  • leadership reporting;
  • and upcoming deadlines.

Documentation does not need to be perfect before it becomes useful.

What If the Leader Already Left and We Did Not Get a Transition?

Reconstruct the program systematically.

Start with available sources such as:

  • GRC platforms;
  • risk registers;
  • audit reports;
  • assessment findings;
  • project plans;
  • ticketing systems;
  • policies;
  • customer commitments;
  • meeting records;
  • and conversations with control owners.

The objective is to rebuild an accurate picture of what exists, what is due and what may be at risk.

Should We Immediately Hire a Replacement CISO?

Not necessarily.

The departure creates an opportunity to ask whether the previous role still matches the organization's needs.

Before recruiting, determine whether the real need is:

  • executive cybersecurity leadership;
  • Cyber GRC leadership;
  • technical security leadership;
  • program operations;
  • specialized framework expertise;
  • implementation capacity;
  • or some combination.

Hiring another person against the old job description may simply recreate the old structure.

Should We Use an Interim or Virtual CISO?

That can be a strong option when the organization needs immediate leadership but does not want to rush a permanent hire.

Interim or vCISO support can help:

  • stabilize strategy;
  • manage material cyber risk;
  • support executives and the board;
  • maintain customer confidence;
  • prioritize the team's work;
  • support major security decisions;
  • and help define the permanent leadership role.

See whether you need a vCISO, vGRC, consultant or full-time hire.

What If the Person Who Left Was Our GRC Leader?

The immediate risks may be different.

A GRC leadership departure can affect:

  • audit readiness;
  • framework management;
  • control ownership;
  • evidence collection;
  • risk registers;
  • policy governance;
  • customer security requirements;
  • findings;
  • remediation;
  • GRC technology;
  • and recurring compliance activities.

Interim vGRC or Cyber GRC operating support may provide continuity while the organization evaluates the permanent model.

What If the Departing Leader Was Doing Both CISO and GRC Work?

That is common, especially in smaller and mid-sized organizations.

The departure may reveal that one person was actually covering several roles:

  • executive cybersecurity leadership;
  • risk management;
  • framework management;
  • customer assurance;
  • audit readiness;
  • remediation;
  • GRC platform administration;
  • and day-to-day program coordination.

That does not automatically mean the replacement should be another person expected to do all of those things.

A blended model may be more sustainable.

How Do We Keep the Cybersecurity Strategy Moving?

Preserve the strategic decisions that have already been made.

Identify:

  • major strategic objectives;
  • approved initiatives;
  • budget commitments;
  • risk priorities;
  • customer-driven initiatives;
  • and projects already underway.

Then determine which priorities remain valid and which depended heavily on the former leader's assumptions.

See how to build a cybersecurity strategy that actually supports the business.

How Do We Keep Cyber Risk Management Moving?

Confirm that material risks still have accountable owners.

Review:

  • high or material risks;
  • open treatment plans;
  • accepted risks;
  • recent changes in exposure;
  • and upcoming risk-review commitments.

The cybersecurity leader may have facilitated risk management, but business risk should not become ownerless because that person leaves.

See how to build a cyber risk register leadership can actually use.

What Happens to Risk Acceptance Decisions?

Preserve the record of decisions already made.

Confirm:

  • what risk was accepted;
  • who authorized the acceptance;
  • what assumptions were involved;
  • whether the decision has an expiration or review date;
  • and whether changes in the environment require reconsideration.

Risk acceptance should remain an organizational decision, not disappear with the employee who documented it.

How Do We Keep Executive and Board Reporting Going?

Maintain the reporting cadence, but verify the underlying information before simply repeating old reports.

Leadership should continue to receive visibility into:

  • material cyber risks;
  • major changes in exposure;
  • important remediation;
  • customer and regulatory commitments;
  • major incidents;
  • resource constraints;
  • and significant strategic initiatives.

See how to explain cyber risk to executives and the board.

How Do We Keep Audits From Going Off Track?

Identify every active or upcoming assurance activity.

Determine:

  • the audit or assessment timeline;
  • scope;
  • auditor or assessor contacts;
  • outstanding requests;
  • control owners;
  • evidence status;
  • known gaps;
  • and remediation that must be completed beforehand.

A leader leaving should not cause the organization to lose track of commitments already made to an auditor or assessor.

See how to prepare for cybersecurity audits without constant fire drills.

How Do We Preserve Evidence and Control Knowledge?

Evidence should not live primarily in one person's email, folders or memory.

Confirm:

  • where evidence is stored;
  • which controls it supports;
  • who produces it;
  • how frequently it is generated;
  • and who should own it going forward.

See how to centralize cybersecurity evidence without creating more work.

What If Nobody Knows Who Owns the Controls?

Reestablish ownership quickly.

For important controls, identify:

  • who performs the activity;
  • who is accountable;
  • who produces evidence;
  • who addresses failures;
  • and who has authority over related risk decisions.

See how to create clear ownership for cybersecurity controls.

How Do We Keep Remediation Moving?

Review open findings and remediation plans.

For each significant item, determine:

  • the underlying issue;
  • the risk;
  • the corrective action;
  • the owner;
  • dependencies;
  • target dates;
  • and how completion will be validated.

The departed leader may have coordinated remediation without actually owning the corrective action.

The underlying control owners should remain responsible.

See how to remediate cybersecurity findings.

What If the Former Leader Was the Only Person Who Understood the GRC Platform?

Treat that as an operational continuity issue.

Document:

  • administrator access;
  • framework configurations;
  • control libraries;
  • integrations;
  • evidence workflows;
  • risk records;
  • findings workflows;
  • reports;
  • and recurring platform tasks.

The organization may need temporary platform administration while broader ownership is redesigned.

What If the GRC Platform Was Already a Problem?

Do not preserve a bad implementation simply because the person who built it left.

The transition may be an appropriate time to evaluate:

  • duplicate controls;
  • bad workflows;
  • manual evidence collection;
  • poor framework mappings;
  • unreliable reports;
  • and excessive administrative work.

See what to do when a GRC platform is not working.

What If Our Program Is Mostly Spreadsheets?

Make sure the organization retains access to the files and understands which ones are authoritative.

Then evaluate whether the program has become too complex for that operating model.

See what to do when a GRC program is all spreadsheets.

How Do We Preserve Customer Security Commitments?

Identify customer obligations that depended on the former leader.

These may include:

  • security questionnaires;
  • contractual commitments;
  • certifications;
  • remediation deadlines;
  • customer audits;
  • evidence requests;
  • and recurring security reporting.

Assign temporary ownership before commitments are missed.

See what to do when a customer gives you a new cybersecurity requirement.

What If a Major Customer Requirement Was Still Being Designed?

Preserve both the technical and business context.

Determine:

  • what the customer actually requires;
  • what was already committed;
  • what controls currently exist;
  • what additional investment was being considered;
  • what product or architectural implications exist;
  • and what revenue depends on the decision.

See how customer cybersecurity requirements can become major cost, product and business-strategy decisions.

How Do We Keep Multiple Frameworks Moving?

Do not assign each framework to a different temporary owner and accidentally create more silos.

First understand the shared:

  • controls;
  • owners;
  • evidence;
  • testing;
  • findings;
  • and remediation.

See how to build one cybersecurity program across multiple frameworks.

What If the Team Was Already Overwhelmed Before the Leader Left?

Replacing the leader alone may not solve the problem.

The organization may also need to evaluate:

  • capacity;
  • duplicate work;
  • manual processes;
  • technology;
  • ownership;
  • and work that should sit elsewhere in the business.

See what an overwhelmed cybersecurity and GRC team should consider outsourcing.

What If the Company Has Outgrown the Role the Former Leader Had?

That is an important possibility.

The organization may have grown in:

  • size;
  • risk;
  • customer complexity;
  • technology;
  • framework requirements;
  • product-security needs;
  • and leadership expectations.

The role that made sense three years ago may no longer be the right role.

See what to do when a company has outgrown its cybersecurity program.

How Do We Decide What the Replacement Role Should Be?

Define the capabilities the organization now requires.

Ask whether the company needs:

  • executive cybersecurity strategy;
  • technical security leadership;
  • Cyber GRC leadership;
  • risk management;
  • customer assurance;
  • framework expertise;
  • GRC technology ownership;
  • people leadership;
  • or recurring program operations.

Then determine which of those responsibilities belong in one role and which should be distributed.

Should We Separate CISO and GRC Leadership?

Possibly.

As organizations grow, one person may no longer have the capacity to lead:

  • cybersecurity strategy;
  • technical security;
  • risk;
  • frameworks;
  • audits;
  • customer assurance;
  • GRC technology;
  • remediation;
  • and day-to-day program operations.

Separating responsibilities can create stronger accountability if the interfaces between the roles are clearly defined.

Should We Hire Before We Understand the Future Operating Model?

Ideally, no.

Understand the target model first.

Otherwise, the organization may hire a strong person into a role whose responsibilities are structurally unclear.

See how to build a Cyber GRC operating model.

Can We Use External Support While We Recruit?

Yes.

External support can provide:

  • interim leadership;
  • risk management;
  • audit continuity;
  • framework management;
  • remediation coordination;
  • customer support;
  • GRC platform administration;
  • and recurring program operations.

This allows the organization to recruit thoughtfully instead of hiring under crisis pressure.

Can an Interim Partner Help Define the Permanent Role?

Yes.

Operating the program during the transition can reveal:

  • how much work actually exists;
  • which responsibilities require senior leadership;
  • which responsibilities can be delegated;
  • what expertise is missing;
  • which processes need redesign;
  • and whether one full-time role is enough.

That information can produce a much more accurate permanent job description.

What Should We Hand to the New Leader?

The incoming leader should receive a coherent view of the program.

Ideally, that includes:

  • cybersecurity strategy;
  • material risks;
  • major customer commitments;
  • framework obligations;
  • control ownership;
  • open findings;
  • remediation;
  • audit timelines;
  • technology;
  • important vendors;
  • team responsibilities;
  • and major leadership decisions.

The objective is to transfer an operating program, not a pile of files.

How Do We Avoid This Problem Next Time?

Reduce dependence on individual memory.

Important cybersecurity knowledge should increasingly exist in:

  • clear ownership models;
  • risk registers;
  • documented decisions;
  • operating procedures;
  • GRC technology;
  • governance routines;
  • and accessible evidence repositories.

Mature programs should be resilient to personnel changes.

How Does Leadership Continuity Relate to Cybersecurity Maturity?

A mature cybersecurity program should not depend entirely on one person's knowledge or heroics.

The program should have:

  • clear ownership;
  • repeatable processes;
  • documented governance;
  • accessible evidence;
  • usable technology;
  • and continuity in risk and decision-making.

See what a mature cybersecurity program actually looks like.

How Do We Know Whether the Program Has Stabilized?

Look for:

  • important risks having owners;
  • recurring controls continuing to operate;
  • audit and customer deadlines being managed;
  • remediation continuing;
  • leadership reporting remaining reliable;
  • staff understanding responsibilities;
  • and critical work no longer depending on undocumented knowledge from the former leader.

See how to determine whether a Cyber GRC program is actually working.

How Hotman Group Helps During Cybersecurity Leadership Transitions

Hotman Group can help stabilize cybersecurity and Cyber GRC programs when leadership changes unexpectedly or intentionally.

Depending on the situation, HG can help:

  • assess immediate program risk;
  • identify critical deadlines and commitments;
  • maintain customer assurance activities;
  • maintain audit readiness;
  • continue risk governance;
  • coordinate remediation;
  • preserve recurring controls;
  • maintain leadership reporting;
  • support GRC technology;
  • provide interim vCISO leadership;
  • provide interim vGRC leadership;
  • add Cyber GRC operating capacity;
  • document and improve the operating model;
  • and help determine the appropriate permanent leadership structure.

HG can also support transition to the new permanent leader once that person is in place.

Why Leadership Transition Can Be an Opportunity

A leadership departure is disruptive.

It can also reveal structural problems that were previously hidden by a capable individual.

The former leader may have been personally compensating for:

  • poor processes;
  • unclear ownership;
  • bad technology;
  • fragmented frameworks;
  • weak documentation;
  • or insufficient capacity.

Simply replacing that person may recreate the same dependency.

The transition can instead be used to strengthen the underlying system.

The Larger Philosophy Behind Cybersecurity Leadership Continuity

Strong cybersecurity leaders matter.

But strong cybersecurity programs cannot exist only inside strong leaders.

Accountability, decisions, controls, risks and operating knowledge need to become part of the organization itself.

Cheri Hotman's forthcoming book, Rebuilding Cybersecurity: How to Restore Trust, Leadership, and Real Protection in a Broken System, examines the role of leadership and accountability in creating cybersecurity that stakeholders can actually trust.

Leadership continuity is part of that trust.

The program should remain understandable and operable even when the people responsible for leading it change.

A strong cybersecurity leader should improve the program. A strong cybersecurity program should also be able to survive the leader leaving.

Frequently Asked Questions

What should we do when our CISO leaves?

Stabilize immediate risks, customer commitments, audits, remediation, recurring controls and leadership reporting. Then determine whether the organization needs interim leadership, a permanent CISO, vCISO support or a different long-term model.

What should we do when our GRC leader leaves?

Preserve framework management, audit readiness, evidence, control ownership, risk processes, findings, remediation, GRC technology and recurring program activities while determining the appropriate replacement or external support model.

Should we immediately hire a replacement CISO?

Not necessarily. First determine whether the previous role still matches the organization's current cybersecurity leadership, Cyber GRC, technical and operating needs.

Can a vCISO provide temporary coverage while we recruit?

Yes. A vCISO can provide interim strategy, risk leadership, executive communication and program direction while the organization evaluates or recruits permanent leadership.

Can vGRC provide temporary coverage when a GRC leader leaves?

Yes. vGRC support can help maintain frameworks, controls, evidence, risk, audits, remediation, GRC technology and recurring Cyber GRC operations during a transition.

What if the former leader was the only person who understood the program?

Reconstruct the program from risk records, audits, assessments, GRC technology, control owners, policies, customer obligations and other available sources, then document and institutionalize the knowledge so it no longer depends on one individual.

Can Hotman Group provide interim cybersecurity leadership?

Yes. Depending on the organization's needs, Hotman Group can provide interim vCISO or vGRC leadership, specialized expertise and Cyber GRC operating capacity to stabilize the program during a leadership transition.

Can Hotman Group help us determine what permanent role we should hire?

Yes. HG can evaluate the actual leadership, expertise and operating needs of the cybersecurity program and help determine whether the long-term model should include a full-time CISO, GRC leader, vCISO, vGRC, specialist resources or a blended structure.

About Hotman Group

Hotman Group is a cybersecurity and Cyber GRC professional services firm that helps organizations solve complex cybersecurity, risk, governance and compliance problems.

HG helps organizations maintain cybersecurity continuity when CISOs, GRC leaders or other key security personnel leave, while reducing dependence on individual knowledge and strengthening the underlying operating model.

Hotman Group can provide interim leadership, Cyber GRC operating support, risk and strategy expertise, audit readiness, remediation, GRC technology support and help designing the longer-term leadership model.

Learn more about what Hotman Group is and the cybersecurity and Cyber GRC problems HG solves.