- What: Discussion on CISO code of ethics
- Impact: Cybersecurity professionals are considering ethical guidelines for leadership roles
Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBERSECURITY OPERATIONS CYBERSECURITY CAREERS THREAT INTELLIGENCE INDUSTRY TRENDS Do CISOs Need a Code of Ethics? Kickbacks, no-show jobs, "dirty" VCs, and shelf ware — industry expert Robert "RSnake" Hansen explains why he thinks its time for a CISO code of ethics to ensure cybersecurity bosses aren't engaged in self-dealing that could risk enterprise, and even national, security. Dark Reading Editorial Team June 24, 2026 Dark Reading's Becky Bracken: Hello everyone, and welcome to Dark Reading Confidential. It is a podcast from the editors of Dark Reading bringing you real world stories straight from the cyber trenches. I'm Becky Bracken, senior editor with Dark Reading, and I am here today with Robert "RSnake" Hansen to talk about something that I think is a pretty interesting subject. Welcome, thank you for joining us. Robert "RSnake" Hansen: Thank you for having me, Becky. DR's Becky Bracken: So, we're here today because a post of yours from LinkedIn caught my eye, focused on what you proposed could be a CISO's code of ethics. It was about a year ago and generated a lot of conversation and I've had other conversations around the edges of this topic. And so, I wanted to bring you here today to unpack your proposal from a year ago and talk to us about whether or not your thinking has changed. Maybe we can start, for those of you who don't know, Robert Hansen has been in the industry for a long time. He is a world-class expert and now investor in Grossman Ventures. He's their CTO. So he has a really particular view of this. Related:Stressors, AI Forcing Changes to Cybersecurity Teams RSnake, tell us why you think we need a CISO code of ethics. Robert "RSnake" Hansen: Well ... I don't think we should need one. How about that? I think the world should be a place where we just sort of all know the right thing to do. There are no reasons why anyone would do anything other than what is in the best interest of their company. Because ultimately, what we really should be doing is making sure that the best interest of the company is being met, whatever that is, right? And the company will be the best one to decide for themselves what that is. So, when you're hiring a CISO, I would say most people would have the expectation that the job of the CISO is to provide the maximum amount of security that can be afforded with the budget's constraints and your technical constraints or whatever. And that's it, full stop. That's it. That would be the job, right? And unfortunately, I don't think that that is always the case. And it might be that there's quite a few cases, as a matter of fact, where it's more like whatever the CISO can do to not get fired, which is kind of a low barrier. oftentimes that ... well, yeah, for sure I agree with that. What I mean by being low, is not like reaching for the stars. It's just like trying not to get fired, which is everyone’s job if you think about it. So, it's kind of a low bar. Then beyond that, you think, OK, well, not just that, they're trying to improve the security of the company, reduce the spending in areas where there's been waste in their predecessors or whatever. And what we're finding is at least in many cases that I've been told anecdotally, there's a lot of spend in areas that is either completely antithetical to the security of the company or is shelf-ware. It's just being purchased for whatever reason. And it's never something that the CISO intends to deploy. Now, there could be a wide variety of reasons for that. They get a better deal on something else. And so, they're buying a bucket of things. Related:Operation Escaneo Signals Shift in LatAm Threat Landscape If you remove all those sorts of kind-of-bad, makes-sense type of reasons, we're left with a bunch of bad and bad reasons, such as there might be some kickbacks involved. There might be some sort of backroom dealing with the investors that says, we'll give you a little slice of something down the road or something like that. Or at least that's a theoretical way that that could happen. Maybe it's not a monetary kickback. Maybe it's just like exclusive tickets to a show or something that's got no monetary value because there's no way you could buy any — you can't buy these tickets. DR's Becky Bracken: Yeah, but how does this, the CISO role in this instance, differ from any other corporate officer in charge of an enormous budget? I mean, CISOs in many cases wield enormous purchasing power and people with purchasing power get the royal treatment. And how is that different in the CISO role, you think? Related:EU Gets a Head Start in Developing 6G Network Security Robert "RSnake" Hansen: It is different in the job description sense in terms of the potential of bad actors getting in those positions and abusing their power. I don't think it's different. In fact, I have some pretty good anecdotes of where this happens in HR, for instance. Like big HR firms that want to place people will go and sign specialized agreements with hiring managers and saying, Look, we'll give you some crazy kickback, but you're always hiring from our stable of employees. Similar with CTOs, they will get a lot of different options and work a special deal with me and I'll let you into our company even if we have no interest at all in your technology or technology stack or whatever. So, I don't think it's different in the sense that there could be bad actors and some sort of kickback scheme involved, but I do think the job is significantly different. Some people kind of argued, well, this should apply to everybody. Like, well, yeah, but, I could remove all the security specific things out of the code of ethics that I talked about. But I think the problem is security is one of those very niche areas that has national security implications. It's not just like we, we didn't deploy Salesforce after we bought Salesforce or something like that's annoying. That's a waste of money, but it's not a national security problem. Whereas if you deploy something that you really shouldn't deploy and you know you shouldn't deploy it and you're deploying it in a terrible way, but you're getting a kickback for it, that has big security implications for the company, for national security, et cetera, et cetera. So, in that sense, I think it is meaningfully different, with a massive distinction, with a difference. DR's Becky Bracken: Gotcha. Sure. All right, well, should we go through a few of your recommendations and see where we land on these? Robert "RSnake" Hansen: Absolutely if you'd like. DR's Becky Bracken: All right, OK. So, number one seems straightforward, but I imagine is not. A CISO must abide by their company's NDA code of ethics and employment contract. Why do we need that? Robert "RSnake" Hansen: One would argue we don't, they've already signed it. If otherwise, how would they be an employee there? And yet, I think it's probably the most important one on the list because one of the things you typically sign as part of your employment contract is that you're not going to take gifts or that you must disclose if you are going to take a gift or, and gift is kind of a weird word because it implies something you're given for free that's like a physical object. A gift could also be a contract for your spouse to go work on some side project that never needs to be completed kind of thing. So, there's other forms of kickback that it's not necessarily covered. But in any case, all of that should be disclosed to your manager if you are indeed following the code of conduct. And I'm finding that at least in some of these anecdotes, they're not disclosed. And that could have even led to some terminations, although I was never able to confirm that detail. So, either way, I really do think that number one, have a code of ethics and then have it signed. Like agree to it. And I think by virtue of having an open code of conduct where you know, there's I think there's like 11 things on the list or 10 things on the list or whatever, by having everyone sign it in public it sort of sends a signal to the market that anyone who doesn't sign this, why wouldn't they sign it? It's not like it's particularly difficult to follow the code of conduct you've already agreed to. It's not like I'm asking for any net new things in that line. That should be a throwaway, easy one, should be non-contentious. And yet a lot of people did. They're like, “Well, I already signed it. So why would I sign this again?” I'm like, “OK, you know, do you see why it seems weird to me that that would even be a problem?” Like, well, you've already signed it. DR's Becky Bracken: Yeah. Robert "RSnake" Hansen: Let's just move on past number one. DR's Becky Bracken: Yeah. And it would be helpful, I would imagine, because some people may go into an agreement and say, well, a no-show job for my spouse, that's OK, you know? And it protects everyone on both sides of the transaction. Robert "RSnake" Hansen: Yeah, and I just think that, so the original idea was to have this be like, let's call it a website or like, you know, some standardized — Dark Reading could even run it. You know what I mean? It doesn't have to be owned by me. Just a place where all CISOs can go in and say, “yep, I've signed this thing, I agree with it.” And then they can share it amongst their peers and their peers are looking at it and going, well, but I am not doing all those things. So, I have a choice. I can stop doing all those things and sign this thing. Or I'm going to lie publicly. And now I've inculcated myself or put myself in a very strange position when anyone points out the obvious that I'm not following it. DR's Becky Bracken: A little shame. Robert "RSnake" Hansen: Well, I mea