The CISO's Guide to Securing a Board Seat

George Kurtz (CEO & Founder · CrowdStrike), Adam Zoller (CISO · CrowdStrike), Phil Venables (Former CISO · Goldman Sachs)

RSA Conference 2025 · Day 2 · West Stage · Keynote

Overview

CrowdStrike CEO George Kurtz made a pointed prediction from the RSA Conference main stage: within a decade, every public company will have a CISO on its board — or will wish it had. Drawing a direct parallel to the CFO revolution triggered by Sarbanes-Oxley in 2002, Kurtz argued that breach-driven regulation is creating the same structural shift for security expertise, and laid out a three-part playbook for CISOs ready to make the leap. The session included candid case studies from CrowdStrike CISO Adam Zoller, now on the board of $20 billion health system AdventHealth, and former Goldman Sachs CISO Phil Venables. ---

Watch on YouTube

Visual summary for The CISO's Guide to Securing a Board Seat by George Kurtz, Adam Zoller, Phil Venables
Visual summary for The CISO's Guide to Securing a Board Seat by George Kurtz, Adam Zoller, Phil Venables

Key moments

  1. 1:21 Cybersecurity ranked #2 board risk globally in 2025
  2. 2:40 Every public company will need a board-level CISO
  3. 4:20 SOX blueprint: breach regulation will seat CISOs on boards
  4. 5:24 50% of global CFOs now hold board positions post-SOX
  5. 6:04 SEC breach regulations materially changed the CISO career arc
  6. 7:35 72% of boards seek cybersecurity expertise; demand outstrips supply
  7. 17:52 CrowdStrike CISO Zoller landed $20B AdventHealth board seat
  8. 18:53 Phil Venables: board success is never just about security

The CISO's Guide to Securing a Board Seat

Speakers: George Kurtz (CEO & Founder, CrowdStrike) · Adam Zoller (CISO, CrowdStrike) · Phil Venables (Former CISO, Goldman Sachs)

Event: RSA Conference 2025 — April 28–May 1, 2025, Moscone Center, San Francisco

Watch on YouTube: https://www.youtube.com/watch?v=lYJnVIRYEEE

Reading time: ~8 minutes

TL;DR

CrowdStrike CEO George Kurtz made a pointed prediction from the RSA Conference main stage: within a decade, every public company will have a CISO on its board — or will wish it had. Drawing a direct parallel to the CFO revolution triggered by Sarbanes-Oxley in 2002, Kurtz argued that breach-driven regulation is creating the same structural shift for security expertise, and laid out a three-part playbook for CISOs ready to make the leap. The session included candid case studies from CrowdStrike CISO Adam Zoller, now on the board of $20 billion health system AdventHealth, and former Goldman Sachs CISO Phil Venables.

Introduction

George Kurtz has given his share of AI keynotes. This was not one of them. "I wanted to give back to the community," he told the audience, "and I wanted to give it from the lens of a CEO — a public company CEO — rather than a security expert." The result was one of the more practically useful sessions at RSA 2025: a frank, structured guide for the security leaders in the room who want to translate their expertise into genuine boardroom influence. Cybersecurity, Kurtz argued, has arrived as a boardroom concern — not because vendors have marketed it there, but because the financial consequences of breaches and the weight of regulatory scrutiny have made it impossible to ignore. The question he put to the audience was not whether CISOs belong on boards, but whether the individuals in the room were prepared to step into that role.

The CFO Precedent: History as Blueprint

Kurtz grounded his argument in institutional history, tracing the evolution of board composition to demonstrate that the CISO's ascent is not unprecedented — it is, in fact, following an established pattern.

▶ Watch: The CFO precedent and Sarbanes-Oxley (4:00)

Fifty years ago, corporate boards were populated almost entirely by insiders: executives with backgrounds in finance, law, and manufacturing, selected largely through personal relationships with the CEO. The modern audit committee, now a fixture of public company governance, did not become mandatory until 1972. The Blue Ribbon Committee of 1999 codified standards for stronger financial controls. And then came Enron, WorldCom, and Tyco — the early-2000s scandals that shattered market trust and compelled a legislative response. Sarbanes-Oxley, passed in 2002, fundamentally changed the arc of the CFO's career. Today, fifty percent of global CFOs hold board positions, and more than two-thirds of audit committees include a CFO.

"This is giving us the blueprint of why I believe a CISO will take their seat at the board table," Kurtz said. The mechanism is the same: threats drive regulation, and regulation drives change in boardroom composition. SEC breach notification rules, enacted in 2023 and 2024, have materially elevated the scrutiny placed on security. The average market cap loss from a public company security breach now stands at $5.4 billion. Cybersecurity is appearing on earnings calls and in shareholder letters. "It's a technical issue and a business event," Kurtz said, "and it's a real problem."

The supply-demand imbalance is dramatic: 72 percent of boards actively seek cybersecurity expertise, while only 29 percent currently have it. "Demand outstrips supply," Kurtz noted. "And from a career perspective, it creates tremendous opportunity now and into the future."

Pillar One: Uplevel Your Business Skills

The first element of Kurtz's board-readiness playbook is the most challenging for many security leaders: genuine fluency in business, not merely an ability to present a risk slide.

▶ Watch: Business skills and the board skills matrix (8:00)

Boards are not looking for another technologist. They are looking for business leaders who happen to bring deep security expertise. That distinction requires a mindset shift. Can the candidate read and interpret financial statements? Do they understand fundamental accounting principles — the difference between revenue and ARR, between expense and capital allocation? Do they understand the actual role of a board versus a management team — that boards provide guidance and oversight rather than operational control?

Kurtz pointed to the board skills matrix included in every public company's proxy statement as the most practical diagnostic tool available. CrowdStrike's own proxy lists eight skill categories: technology, cybersecurity, business strategy, finance, leadership, governance, regulatory, and privacy. "The more boxes you can check here, the greater the probability of actually getting a board seat," he said. Sixty to seventy percent of companies now list cybersecurity or technology expertise as a specific skill in their proxy — which means reading proxy statements is both a research tool and a benchmark for self-assessment.

His advice for candidates targeting a specific company: read the proxy before any conversation. Understand which committees have openings, which skills are underrepresented, and where the board's stated priorities align with your background.

Pillar Two: Speak the Board's Language

The second pillar is translation: converting security expertise into the terms that boards actually use to evaluate risk and make decisions.

▶ Watch: Speaking the board's language — time, money, legal risk (14:00)

Kurtz distilled board conversation into three core currencies: time, money, and legal risk. Time — how long does something take, how quickly can an organization respond, how does security posture affect speed to market — is among the scarcest resources a CEO manages. Money — margin impact, capital allocation, the cost of a breach versus the cost of prevention — connects security investment to financial outcomes. Legal and regulatory risk — translating technical vulnerabilities into exposure to government investigation, class action litigation, and SEC scrutiny — is increasingly the domain where CISOs can provide unique value.

"If you can be the translator, people are gonna want you in the room," Kurtz said. "You need to simplify, not make things more complex." The CISO who enters a board presentation and delivers fifteen minutes of technical detail is less valuable than the one who frames the same information as a business risk, a financial exposure, or a competitive vulnerability. The ability to make that translation fluently — and to stay for the rest of the board meeting rather than presenting and leaving — is what separates candidates from consultants.

Pillar Three: Build Your Brand — and Hang Around the Hoop

The third pillar is the most counterintuitive: board seats are not won through visibility alone, but through the deliberate construction of a professional reputation as a business leader who happens to specialize in security.

▶ Watch: Building your brand and the NACD (16:00)

Kurtz was explicit: this is not about conference speaking or LinkedIn presence. It is about how board members perceive a candidate when a seat opens. Board composition changes constantly — members retire, committees need new expertise, companies add directors ahead of regulatory requirements — and when that happens, boards fill openings through a very direct mechanism: they ask one another, "Who do you know?" The CISO who is known to sitting board members as a business leader, not merely a security expert, will be top of mind when that question is asked.

Practical tactics: attend and join the National Association for Corporate Directors (NACD), obtain the NACD certification, and seek every opportunity to interact with board members in their own environment. The certification signals commitment to governance norms and expands the professional network. More importantly, board members tend to sit on multiple boards simultaneously, which means a single relationship can open multiple doors.

Kurtz shared his own HPE example directly: he was invited to join their board specifically because a committee opening in technology and security needed to be filled, and someone he knew on the board recommended him. "It was out of the need of the committee that they actually reached out," he said. "And it was because I knew someone on the board."

Case Studies: Zoller and Venables

Kurtz brought two practitioners on stage to validate the playbook.

▶ Watch: Adam Zoller and Phil Venables case studies (17:44)

Adam Zoller, CrowdStrike's own CISO, now serves on the board of AdventHealth — a $20 billion revenue, 100,000-employee health system. His path followed Kurtz's three pillars precisely: a master's in IT management to build business fluency, deliberate positioning as a business leader rather than a security functionary in his interactions with boards, and a practice of staying for the full board session rather than departing after his security briefing. The trigger for his AdventHealth invitation was a security incident at another healthcare provider — the board recognized its exposure and recognized that only 29 percent of boards currently have cybersecurity expertise. Zoller was known, credible, and available. He got the call.

Phil Venables, former CISO at Goldman Sachs and now serving on Goldman Sachs Bank's board along with several others, offered a complementary perspective. Boards evaluating security executives, he noted, are assessing a portfolio of capabilities: IT fluency, cloud and AI expertise, risk management, compliance, national security awareness, FinTech understanding, and the track record of leading large organizations. "It's never just about security," Venables emphasized. "It's about the broader strategic value an executive can bring."

Notable Quotes

"Every board now needs a CISO. Not on their company, on their board. And in the next decade, every public company will have a CISO on their board, or they wish they would have." — George Kurtz

"Threats drive regulation, and regulation drives change." — George Kurtz

"Demand outstrips supply. And from a career perspective, it creates tremendous opportunity now and into the future." — George Kurtz

"If you can be the translator, people are gonna want you in the room. You need to simplify, not make things more complex." — George Kurtz

"It's never just about security. It's about the broader strategic value an executive can bring." — Phil Venables

Key Takeaways

  • A structural shift is underway. Just as Sarbanes-Oxley drove CFOs onto audit committees, SEC breach notification rules and the $5.4 billion average market cap loss from breaches are driving cybersecurity expertise into boardrooms. The shift is regulatory, not optional.
  • The supply-demand gap is the opportunity. With 72 percent of boards seeking cybersecurity expertise and only 29 percent currently possessing it, the market for CISO board candidates significantly exceeds the available supply — creating a genuine career inflection point.
  • Business fluency is the prerequisite. Reading financial statements, understanding board governance, and being conversant in accounting principles are not optional additions to a CISO's skill set — they are the cost of entry for a board role.
  • Translation is the differentiator. The ability to frame security risk in terms of time, money, and legal exposure — and to simplify rather than complicate — separates candidates who get board interviews from those who merely get quarterly briefings.
  • Boards fill seats through networks. The most reliable path to a board interview is being top of mind among existing board members. Organizations like the NACD provide the professional infrastructure to build those relationships before a seat becomes available.
  • The homework is concrete. Read proxy statements of target companies. Assess your own skills matrix honestly. Learn board-level financial vocabulary. Position yourself as an operator and business leader — not just a security expert — in every board interaction you currently have.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Kurtz abandons the AI keynote format and delivers something actually useful: a structured, evidence-backed playbook for CISOs who want board seats, with the CFO post-Sarbanes-Oxley precedent as the analytical backbone. The Zoller and Venables case studies are specific enough to be actionable. A career-development session disguised as a keynote — and better for it.

Heather Calloway (CISO) — STRONG ACCEPT

George Kurtz, Stan Zucker, and Phil Venables lay out the operational playbook for CISOs pursuing board seats — drawing on the CFO/Sarbanes-Oxley precedent. 72% of boards are actively seeking cybersecurity expertise. 29% have it.

→ Top-rated talks at RSA Conference 2025

All talks from RSA Conference 2025