I came up through the technical side of security: penetration testing and IAM at KPMG, standing up the first security program at a global SaaS travel provider, running threat and vulnerability management for one of the largest payment processors in the world, then a year inside a bank's IT audit function seeing how controls actually get tested. That path leaves you with little patience for security theater. A control that cannot be measured is a hope.
As CIO I owned security outright, which is the cleanest way to learn what a CISO needs from the rest of the organization. We built a secure digital core across cloud, network, data, and platform, cut mean time to detect by 75% and mean time to respond by 60%, brought average vulnerability age from 45 days to 12, and took ISO 27001, HITRUST, HIPAA, GDPR, and Cyber Essentials through certification on the first audit with zero critical findings. Those certifications opened more than a billion dollars of revenue. Security done well is a growth function.