Chris Wheeler is the CISO at Resilience. He has a long history in cybersecurity: a threat researcher and analyst at Efflux Systems and then threat analytics manager at Arbor Networks. He joined Resilience as threat intelligence lead but left in 2020 to become VP and SOAR lead at Morgan Stanley. He returned to Resilience four years later, first as VP of information security, and subsequently CISO.
It is fair to suggest he has security in his blood. His father was a university IT administrator. “He was always kind of tinkering with these different systems, and I inherited the same kind of curiosity and interest in information technology.”
Cybersecurity and becoming a leader
Navy training
Wheeler’s focus on the security side of IT emerged after he joined the US Navy in 2010. He stayed for six years, describing the Naval Academy as effectively ‘an undergraduate institution’; and the time spent as three years of traditional sailing on destroyers and three years of cyber operations (which the Navy called ‘information warfare’ at the time).
He was especially attracted to one particular information warfare exercise: the Navy was required to keep an NSA red team out of its networks for a week. The result was scored on network uptime, red team detections and expulsions, and digital forensics.
But the Navy didn’t simply focus his interest on cyber; it also taught him how to be a leader. There’s an old maxim that is very important in the military: ‘it’s up or out’.
“Ultimately,” he explains, “that’s the path you’re on. Whether you’re a senior noncommissioned officer, a mid-level noncommissioned officer, or a commissioned officer, you end up leading teams of people. Almost straight from school, I was leading a division of 15 sailors on a ship.” At the same time, the military also instills an overwhelming sense of mission and purpose.
He later came to understand how much the concept of mission and purpose underpins an individual’s identity. It was his time in the Navy that laid the foundation for the cybersecurity leader he became.
The commercial world
Business, however, is not the same as the military, and he was forced to adapt what he learned in the Navy to suit the new priorities. Three things rapidly became apparent: technology advances at breakneck speed, networks are increasingly complex, and the role of the security leader also requires business analysis skills.
It isn’t possible for a single person to simultaneously be the company expert in IT, cybersecurity, and business processes. So, he refined his view of leadership.
“A leader must understand and be able to do the whole job, but more importantly be able to teach others how and where to specialize. The modern security leader is someone who can build a team, and knows when to do something personally, and when and where to teach and guide the team members to do it,” he explains.
Again, it was his Navy training that gave him his personal ability and team leadership skills to do this.
The importance of trust
Wheeler believes the ability to engender trust is the single most important personality trait a CISO can own.
Trust is a two-way street. The CISO must pervade trust otherwise business leaders won’t accept strategic advice on cybersecurity versus business maximization. At the same time, CISOs must have trust in their business peers and the business itself.
Perhaps most importantly, CISOs must trust the security team members that they themselves recruited. “Since it’s impossible for a CISO to know everything, CISOs must know the right questions and the right people to ask.”
While that person could be anyone in the company, it is statistically more likely to be a security team member. The CISO needs to trust the team, but equally the team needs to trust the CISO will always have their back. This two-way requirement for trust places added onus on the process of hiring and team building – but the possibilities are changing with new technology.
Technical expertise is no longer the be-all and end-all of staff recruitment. “In the age of generative AI, there’s been a democratization of the ability to use automation,” explains Wheeler. Just as you no longer need to be a trained programmer to do programming, you no longer need to be a qualified security engineer to do security operations.
“So, you’re looking for people who are future-minded and able to incorporate AI into their workload.” This in turn allows the CISO to focus on the team concept rather than simply individual qualifications. Emotional intelligence and social skills become important factors in building a cohesive team that is rooted in trust of each other and trust in the leader.
The road
Any road journey benefits from signposts. They stop the traveler from getting lost. And they help the traveler reach the destination as smoothly and quickly as possible.
On a career journey, the signposts are usually mentors, and the path is advice. Most CISOs have benefited from good advice along their journey. Wheeler separates the best advice he received into ‘philosophical’ and ‘practical’.
“Philosophically,” he explains, “the advice was that you cannot be an expert if you don’t know the mathematics of your profession.” This goes beyond understanding the underlying structure of IT into understanding the principles that affect security.
“Learning and applying risk quantification is something all CISOs can improve on,” he continues. “Do you have to be perfect at it? No, but you have to know how to reasonably estimate probability, describe uncertainty, and increasingly, map that to financial terms.”
This maps back to the growing need for the CISO to be a business analyst for the company as well as a security expert. The job is not to prevent all security incidents – that would be impossible – but to limit attacks against what matters to the business and to ensure that business continuity is maintained.
Ideally, this could best be achieved with all CISOs being members of the board. We’re not there yet, but it is effectively a core part of the UK government’s Cyber Resilience Pledge launched on July 7, 2026. Whether this has already happened or not, “What we’ve seen is an increase in the number and frequency of briefings to the board,” and the need “to reasonably estimate probability, describe uncertainty, and increasingly, map that to financial terms”.
On the practical side, the best advice Wheeler received was to build a home lab. “That can take many forms beyond just IT hardware these days,” he continues. “Being curious and experimenting with the technology and processes you’re charged with securing can never be undervalued in my opinion. And increasingly, generative AI tools are allowing us to explore, simulate, and try out concepts beyond just hardware.”
A CISO is a mentee on his journey, but a mentor to others – specifically his team – who are starting on their own journey. Wheeler doesn’t give specific advice but prefers to describe the landscape surrounding the journey.
“Traditional security carries a perfectionist complex. We can unintentionally carry that into our interactions with employees and business partners. But every risk-first CISO knows perfection cannot be sustained, even if you have the budget of a nation state. It’s hard to make risk decisions when you’re operating from a position of absolutes (perfection) rather than taking quantitative or financially informed measures.”
To navigate this, he says, “I encourage my team to be empathetic partners to everyone they work with, and to seek both personal and professional balance.”
Empathy and balance is important. “Building relationships with partner teams is crucial to business resilience,” he continues. “It requires listening and sometimes compromise, but it encourages partners to share information, raise issues, and help you act when necessary. Maintaining personal balance allows you to make better relationships and make risk-informed decisions as a CISO or security professional.”
In effect, any specific advice he offers to his team is focused on the personal rather than professional. “Take that vacation; be there for your family; and spend some time on your hobby. Know your own balance and don’t burn yourself out. The work will be here, and it’s only getting more complex.”
Stormy weather
Wheeler is concerned about the rise of agentic AI; but not always from bad actors. “I’m concerned with keeping pace with agentic AI adoption securely and resiliently,” he explains. “On the adoption front, there is increased top-down demand from boards and investors, and bottom-up demand from developers and power users.”
His team is engaged in a secure enablement initiative that brings in many of the principles he previously discussed: listening to employees, building trust, adopting and experimenting personally, and setting guardrails based on risk.
“While there are certainly some new categories of controls, nearly all of them are rooted in a zero trust architecture,” he continues. “For that reason, we are especially increasing investment in IAM, data inventory and categorization, and automation across the board.”
It is clear that Wheeler’s approach to security goes beyond the technology – successful security is rooted in understanding the mathematics of the profession. That mathematics is technology + security principles + business acumen + people empathy = successful cybersecurity.
Related: CISO Conversations: Carl Froggett – Combining CISO and CIO at Deep Instinct
Related: CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker
Related: CISO Conversations: Ross McKerchar, CISO at Sophos
Related: CISO Conversations: Aimee Cardwell
