Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

CISO Conversations

CISO Conversations: Russ Kirby – Passion Is the Antidote to Burnout

Russ Kirby, CISO at Ping Identity, shares how passion, courage, and “good enough” thinking shaped his path from HP to the C-suite—and what keeps him up at night.

CISO Russ Kirby

Passion for the job is the secret of a successful career.

Russ Kirby has been CISO at Ping Identity since the summer of 2023. Before then he was CISO at Creditsafe, and then CISO at ForgeRock. Prior to that he had been global head and director of enterprise services information security directorate at Hewlett Packard.

A natural born CISO

Asked why he chose cybersecurity as a profession, Kirby answers, “It just feels natural for me.” Asked to expand, he replies, “Turns out I’m Type One on the Enneagram.”

The Enneagram is a framework that describes nine core personality patterns. It is largely self-diagnostic, but the result is fairly accurate. A Type One personality is fundamentally a principled, improvement‑driven person whose core motivation is to be good, responsible, and morally upright. 

“I like order and discipline, and my subtype is ‘protector’,” he continues. “So, cybersecurity appeals: the subject matter is fascinating, the pace of change is intriguing, and the details are interesting. I’m very detail-oriented – I love finding the micro in the macro.”

The journey

Russ Kirby has always worked with technology. “I’m the Gen X generation that came up as computers became the norm,” he says. “Even as a very young man – which is a long time ago – I was fascinated by technology; what it could do now and its potential for the future. Without wanting to sound too grandiose, I was attracted by the potential technology has for humanity. So, I’ve always worked with technology and computers, from the beginning.”

Advertisement. Scroll to continue reading.

But the move from technology generally to cybersecurity specifically wasn’t planned. “It was through necessity,” he explains. “The company I worked for needed someone to take on that role. I like a challenge, so I took it on. Turns out it suited me, I enjoyed it, and I did well. So, after that I took on a similar role in a very large global organization [Hewlett Packard]. I enjoyed it and progressed within the organization.”

He has always liked leading and directing a strategy, so he was good with teams. “I decided to look for a CISO role. I spoke to a few companies, and one decided to give me a shot.”

This was first as CISO at Creditsafe (for two years), and then as CISO at ForgeRock (four years). He moved to Ping Identity in the summer of 2023, where he is global CISO for enterprise security, product security, GRC and privacy. “Everything just sort of fell into place for me. The opportunities came up, and I was lucky that people trusted me to take care of their companies.”

‘Luck’ is an interesting word. It sounds simple: that is, chance. But it’s not that simple. Luck involves a person’s reaction to chance; and different people may react differently. It’s probably more accurate to define luck as a combination of opportunity and response, pointing toward the more extreme view that people make their own luck.

“I think in my context,” suggests Kirby, “luck is having the conviction and courage to take an opportunity when it has become apparent. I’ve always been willing to be bold and go forward. I think that has been my luck, rather than just sitting still. It’s another thing that I like about cybersecurity. It really does support people who are willing to drive forward in technology, in their approach to business and in their approach to security.”

Signposts on the route. Every journey benefits from good signposts. In a career journey, such signposts can often be good advice received on the way. Kirby says he has had many such signposts. “But if I had to pick one – it’s a bit cheesy but it resonates – ‘Don’t let perfect be the enemy of good.’ Striving for that complete perfection will often stop you from doing good.”

He gives a hypothetical example. “Our target is zero disruption from an incident. That’s the ‘perfect’ we seek to achieve. But sometimes, the right solution is to walk downstairs and pull the power. You have to be bold enough to do that.”

A natural born leader

Shakespeare said it first: “Some are born great, some achieve greatness, and some have greatness thrust upon them.” Transpose ‘greatness’ for ‘leadership’ and it remains true: are people born leaders, do they learn leadership, or does leadership become a necessity of life? Whatever the cause, CISOs must be leaders.

“I’ve always been someone who likes to bring order to chaos. That’s just who I am. I like to have rules, order, discipline and things like that. And I’ve found myself able to instill similar into those around me. I enjoy it. I enjoy the coordination of it. I enjoy working with people and structuring teams. I really like mentoring people within my teams – getting the maximum I can from individuals in the team.” 

This is part of his Type One personality. He puts it down to that thing called luck and/or opportunity. “The need was there in many projects in my career, and I took the opportunity to lead when other people didn’t. I think being in that de facto leader role is what has put me in a position where people have asked me to step into the role full time.”

For him, becoming a leader doesn’t fit neatly into the Shakespearean model. Leadership wasn’t something he was born with, nor was it a target he achieved, nor was it something that was demanded of him – it was a natural personality development associated with the habit of grasping opportunities.

Being a CISO

Building the security team. “I look for all the basics: knowledge of technology, awareness of different cybersecurity topics, understanding this subject and that subject – but what I really seek out is enthusiasm. A lot of people jumped into cybersecurity as a way to make money – and you can make good money in cybersecurity. I’m not denying that; but if you want to stick with it for more than a fleeting moment, I think you have to genuinely enjoy it,” he says.

“The level of the role being sought is also relevant. For a more junior role, if I had somebody with all the right qualifications but appeared to be bored with life; versus someone with just some of the qualifications but a genuine interest – the person who goes, ‘Let me show you my GitHub. Let me show you the configuration of my home lab’ – I would incline toward the person with enthusiasm over the person with 100 certifications but looks like they’re on the death march.”

The signpost he offers his team members is the same one he received himself, but with the addition of ‘Keep going and ask questions on the way.’

Most important personality trait. “It’s the ability to keep listening when somebody challenges your own beliefs. I’ve seen people step into a CISO position determined to fashion everything to the way they’ve always done it elsewhere. But every company is different, and every team member is different,” he says.

“To be successful at this level, whether it’s as CISO or any C-level role, you must be able to take the wide view. You need to look at the macro and then work out the micro. And you need to know your team; you need to understand how they function and how to get the best out of them. It’s different for every single person.”

Is the role reactive or proactive? Ultimately, he accepts that security is reactive; but insists that the CISO’s role is to be as proactive as possible. “Even with things like system hardening, penetration tests, and vulnerability scans, you’re trying to proactively identify a problem and close it. The greatest use of AI right now is to assist in being more proactive, more ahead of the game.”

But he adds, “I acknowledge that a vulnerability scan is finding something that isn’t patched, so it’s technically reactive. But the purpose is to fix it before it’s exploited, which makes it a proactive step. Some areas are pure reaction to an event – such as incident response. But even here, the reaction is proactively seeking to limit damage. I think the nature of cybersecurity is a blend: reactive in urgency, but proactive in intent. I certainly wouldn’t say it’s entirely reactive.”

The cybersecurity agility gap plays into this. The agility gap is a term gathering traction to describe how attackers adopt new technologies faster than defenders defend against new technologies. The result is that defenders need to react to new attacks; but this doesn’t change Kirby’s primary hypothesis: cybersecurity must always seek to proactively get ahead of the attackers.

Burnout. Burnout is a recognized and complex problem, largely caused by overwork and stress. It can affect both CISOs and security teams – but it doesn’t affect everyone. The key seems to be whether there is any escape or relief from the stress.

Kirby points out that he tends to be “a very long tenured CISO” – certainly longer than the short tenure of many other CISOs. He has never succumbed to burnout, and he puts this down to his passion for the job. “If I won the lottery and could do anything I want, I’d probably do cybersecurity.”

He isn’t unaware of the pressures that cause CISO burnout. “The role of the CISO is evolving and changing at a dramatic rate. CISOs used to live in the broom closet – now they live in the boardroom. But having a network of friends and other CISOs can support you in making those big decisions that are your own responsibility.”

So, for Kirby, the necessary ‘relief’ from continuous stress seems to be enjoying the work and support from others. Part of his role is to provide similar relief from burnout to his team members. “CISOs need to protect their team. There will always be unreasonable demands from the world. Some people say it’s an unreasonable demand from the board. It’s not. It’s usually the unreasonable demands from the world that affect you most.”

This could be part of the work, such as the speed with which attackers adopt and use new technology; or outside of work, such as domestic pressures or a large mortgage that keeps you trapped in a job that you no longer enjoy. “On occasion, I have taken a team member aside and said, ‘You need to go home and spend some time with your family, your spouse, your loved ones – and if you don’t do it, I’m going to switch your computer off, and you won’t have an option but to stay home.”

The key relief from stress is enjoyment. He looks for a passion for cybersecurity when he recruits his team members, and he seeks to maintain that passion and enjoyment in cybersecurity on the job. It makes for a more efficient team; but it also prevents burnout.

Cliché time: what keeps this CISO up at night?

“You mean apart from caffeine,” he says. “Well, I hate even saying it, but at the moment it’s AI. If I’m honest, it’s the rapid adoption of it that keeps me up at night. Do we fully understand the beast that we are unleashing? I think that would be my simple answer to the cliché question.”

There’s an element of that agility gap here.

He’s trying to respond to the challenge of AI through education. “We educate ourselves, we inform ourselves, and we plan to both prevent and respond to any bad uses of it. We can’t control everything, but we use it ourselves as part of our preventative measures.”

AI is the biggest stressor of our times. It isn’t simply a new and little understood technology; it is continually renewing itself with the speed of its own evolution. The problems that occur now will be worsened in the months and years to come.

But although this is a concern, Kirby doesn’t consider it to be a radically new concern, for either himself or other CISOs. “This is just the repeating cycle that happens with all new technology. When the floppy disk was invented, people were worried about data theft on floppy disks. When the internet was invented, people were worried about losing information over the wire.”

It’s the whack-a-mole game of cybersecurity: attackers with a new technology pop their heads up, and defenders must be quick enough to whack them with a mallet. 

“Progress and technology bring challenge and risk, and it’s different iterations of that challenge and risk on a year-by-year, sometimes day-by-day basis.” AI may be the current stressor, “But it’s part of what makes cybersecurity such an interesting subject,” he says. 

“We get to explore, secure and counter new risks as they arise. Give it another couple of years, and we’re not going to use the term AI. We’re just going to call it computing or something normal. There will be another challenge that we have to overcome, and we’ll embrace and overcome that challenge, and the one after that.”

Related: CISO Conversations: John ‘Four’ Flynn, VP of Security and Privacy at Google DeepMind

Related: CISO Conversations: Maarten Van Horenbeeck, SVP & Chief Security Officer at Adobe

Related: CISO Conversations: Nick McKenzie (Bugcrowd) and Chris Evans (HackerOne)

Related: CISO Conversations: Aimee Cardwell

Written By

Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

PNC Financial Services Group has appointed Christian Winward as CISO.

Brian Gumbel has joined Armadin as Chief Revenue Officer.

EigenQ has appointed Mark Pecen as Vice Chairman and Alexander Truskovsky as CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.