The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Cyber Security Business
Cyber Security Business artwork

Evolving as a Security Leader

Cyber Security Business · 2025-04-23 · 25 min

0:00--:--

Key moments - from our scoring

Substance score

45 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality7 / 20
Guest Caliber13 / 20
Specificity & Evidence6 / 20
Conversational Craft10 / 20

Alex Cunningham brings substantial leadership experience to a candid conversation about growing beyond the CISO title into effective people leadership. Having started formal leadership training in the British Army's junior leaders program at 16, Cunningham reflects on how his natural drive to lead has been refined through maturity and self-awareness. He emphasizes that successful security leaders must embrace diversity in team composition rather than replicating their own traits, actively solicit feedback as a gift, and develop the emotional intelligence to recognize burnout in themselves and their teams. A critical theme throughout is that CISOs should focus less on reporting structure and more on organizational influence and the strength of executive relationships. Cunningham discusses his own experience with burnout during remote work and credits therapy and direct team conversations about mental health with creating psychological safety. He advocates for security leaders to build trust through vulnerability, operate in shades of gray rather than binary thinking, and recognize that their role is partly cultural change - helping organizations view security as a business advantage rather than purely a compliance burden. Key resources he mentions include Patrick Lencioni's *The Five Dysfunctions of a Team* and *The Advantage* for understanding organizational health. His advice for new leaders centers on observing, listening, and avoiding the trap of believing you have all the answers.

Key takeaways

  • →Security leaders must build trust through vulnerability and openness, recognizing that no individual has all the answers and that collective team strength drives organizational success.
  • →Burnout is real and recognizable through loss of energy and diminished creative output; leaders must model vulnerability about their own mental health struggles to create safe environments for teams to open up.
  • →The CISO reporting structure matters less than the influence the CISO wields within the executive team and the quality of relationships with key stakeholders like the CFO, COO, or general counsel.
  • →Team diversity in thinking styles and backgrounds acts as an amplifier of effectiveness; success comes from creating psychological safety where introverts and extroverts alike can contribute their strengths.
  • →Security leaders must operate in shades of gray, balancing business needs with risk mitigation, and cultivate a risk-aware culture through education that treats people, process, and technology as equally critical.

In this episode

  1. 1From Military to Leadership: Building the Leadership Gene
  2. 2Diversity and Team Dynamics: Leading Beyond Your Own Strengths
  3. 3Evolution of Leadership Style: Self-Awareness and Growth Through Experience
  4. 4Handling Conflict and Stakeholder Alignment: Communication and Listening
  5. 5CISO Reporting Structure and Organizational Influence
  6. 6Recognizing and Overcoming Burnout in Yourself and Your Team
  7. 7Building Trust-Based Leadership and Team Culture
  8. 8Rapid Fire: Unlimited Budget, Skills, and Career Advice

Mentioned

Kevin PouchetKlogixAlex CunninghamAdvisor360Patrick LencioniThe Five Dysfunctions of a TeamThe AdvantageWinston ChurchillInspector RebusIan Rankin

Guests

Alex Cunningham

Topics in this episode

CISO leadership and organizational reportingBurnout recognition and mental health in security teamsTrust-based team building and psychological safetyPatrick Lencioni's Five Dysfunctions of a TeamPatrick Lencioni's The AdvantageSecurity culture and risk awarenessConflict resolution in security stakeholder managementDiversity and inclusion in security team composition

Questions this episode answers

How did Alex Cunningham develop his leadership approach?

Cunningham began formal leadership training in the British Army's junior leaders program at age 16 in 1988, where he learned discipline and commitment. His approach evolved through maturity and experience - he moved from moving too fast early in his career to developing greater self-awareness, actively seeking feedback, and learning from mentors at all levels, including people junior to him.

What does Alex recommend for managing conflict between security teams and business stakeholders?

The key is effective communication and listening to understand the other side's perspective. Security leaders must develop sensitivity to the end user experience, recognize that the business isn't primarily focused on security, and position themselves as collaborative and open to new ideas rather than inflexible.

How should CISOs handle mental health and burnout in their teams?

Create a safe environment through trust and openness where team members feel comfortable discussing struggles. Leaders should recognize burnout in themselves first, model vulnerability by discussing their own experiences, use one-on-ones as opportunities for honest conversations, and treat team members as whole humans with personal lives beyond work.

Who should the CISO report to organizationally?

Cunningham now believes reporting structure matters less than the influence the CISO has within the executive team and which executive can actually get things done in that specific organization - whether that's the CEO, CFO, COO, or general counsel depends on organizational context.

What single investment would Alex make with unlimited budget?

Cybersecurity education and building a risk-aware culture, because technology can fail, but a well-educated workforce that sees security as a business advantage provides resilience when controls break down.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

The episode offers moderate insight density with some genuinely useful observations about leadership philosophy, particularly around building trust, managing conflict through communication, and recognizing burnout. However, substantial portions consist of soft leadership platitudes and personal anecdotes that lack new frameworks or actionable mechanisms. The advice on 'being a sponge,' trusting your team, and living in 'shades of gray' are broadly applicable but not particularly novel for experienced operators.

my general guiding principle from a leadership perspective has always been to lead the way I like to be led
our role is all about living in shades of gray. And our priority is to make those shades of gray as light as we possibly can

Originality

7 / 20

The episode largely recycles standard leadership wisdom without fresh contrarian takes or first-principles thinking. The frameworks about trust, communication, and team diversity are mainstream. The only moderately original note is the nuanced position that CISO reporting lines matter less than actual organizational influence, which is practical but not groundbreaking. Most themes - burnout, mentorship, vulnerability, diversity - are well-trodden in leadership discourse.

I think that diversity is really important. I would hate for us all to be mini versions of myself
where the CISO reports, for me personally, is less of an issue. For me, the importance is what's the influence the CISO has

Guest Caliber

13 / 20

Alex Cunningham is a legitimate practitioner: he's a current CISO at a named fintech company (Advisor360), former CISO Award winner, with 35+ years of career progression including military leadership. He has substantive tenure in security leadership roles. However, he reads more as a seasoned people-manager than a cutting-edge security operator or strategist with novel technical or organizational innovations. His focus is primarily on leadership soft skills rather than security strategy, threat landscape evolution, or operational complexity.

Alex Cunningham, CISO at Advisor360. former CISO Award winner of the year
I joined the British Army actually in 1988 at a mere 16 years of age

Specificity & Evidence

6 / 20

The episode is severely lacking in concrete examples, metrics, or named case studies. There are almost no specific incidents, dollar figures, timelines, or measurable outcomes beyond vague references to 'building culture' and 'teams doing wonderful things.' The one potentially specific example - reporting to general counsel - is generic. Even the burnout discussion lacks specifics about what remediation actually looked like or measurable outcomes. This is heavily abstraction-driven.

I spoke to someone a few months ago, actually, and they were saying they report to the general counsel
I definitely burnt out, I think, last year. As I said before, I'm an extroverted type of personality

Conversational Craft

10 / 20

The host, Kevin Pouchet, asks competent but largely softball questions that don't probe deeply or challenge claims. Most questions are open-ended invitations for the guest to expand on prepared talking points. There are no sharp follow-ups that would test assumptions, request evidence, or push on contradictions (e.g., no challenge to vague claims about 'team culture' or 'making shades of gray lighter'). The rapid-fire section at the end is filler. Some genuine curiosity is evident, but the conversation lacks edge.

That's interesting. And I can't say I'm surprised
Thank God we're recording this because that could be the most thoughtful and pragmatic answer I've ever heard

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

team23security19leader15leaders15leadership11important9organization9alex8back8terms8sure8last8ciso7first7strong7trust7

Episode notes

Kevin Pouche, COO of K logix, sits down with Alex Cunningham, CISO at Advisor360°, to discuss his leadership journey from the British Army to the boardroom. Alex shares how early experiences shaped his leadership style, why diversity builds stronger teams, and how CISOs can drive influence regardless of where they sit in the org chart.

Full transcript

25 min

Transcribed and scored by The B2B Podcast Index.

Hello and welcome to another episode of Cybersecurity Business. As usual, I'm your host, Kevin Pouchet, COO of Klogix. In this episode, we're diving into what it truly means to grow as a security leader, not just in title, but in mindset, resilience, and impact. So today, we sit down with the true leader, Alex Cunningham, CISO at Advisor360.

former CISO Award winner of the year, and he brings a thoughtful and pragmatic perspective on leading high -performing security teams in a rapidly evolving threat landscape, as we all know. Alex, welcome to the podcast. Thank you, Kevin. Delighted to be here.

So, Alex, think back 2002, where you got your first leading... role in your career. I'm interested to start this off by understanding how you became a leader. What I mean by that is you have someone like Steve Jobs who he's famous for saying that the best leaders and managers are people who frankly aren't interested in leading and managing people.

Were you one of those people who had these aspirations always to be a leader and you were going to do whatever it takes to get to that point because you knew you had what it takes? Or were you in a position where somebody came to you and said, Alex, you are doing a fantastic job. I want you to lead and I want you to manage these people. And begrudgingly, you started going down that path.

It's kind of funny, actually, the way you've phrased that question going back to 2002. I guess that was the first time I actually had leader in my title. I never actually thought about it that way. From my perspective, I've always been attracted and I've always wanted to lead, whether it's people, programs, companies, whatever it may be.

I definitely think I've always had that leadership gene. And I'll actually take you further back. I joined the British Army actually in 1988 at a mere 16 years of age. And I joined their junior leaders program, which was basically designed to bring the next generation of military leaders, whether it's sergeant majors or senior officers or whatever it may be.

So I guess that's where my first, if you like, formal leadership training came about. But the one thing I would say throughout my career and regardless. of how junior I was or how senior I was, I've always enjoyed the ability to find myself in a position of leadership, whether it's managing a project, a simple task or whatever it may be. I've always, and I don't mean to sound arrogant by this, but I've always seemed to find, right, we need someone to lead something.

And more often than not, I've been given that opportunity. So yeah, it's definitely something I enjoy. It's something that I'm... that I've always wanted to do.

And to date, I've been fairly successful with it. That's interesting. And I can't say I'm surprised, you know, you mentioned the British Army. When I think of the Army, I think of qualities like discipline and courage and commitment and respect and those.

qualities, I think, are the building blocks of a leader. And so when you go to hire people and build your team, do you look for people that have those same qualities in that same background? I would say 100 % absolutely not, because I think we all have different makeups, and I think diversity is really important. I would hate for us all to be mini versions of myself, because I don't think as a team we'd be effective enough.

But I think if people have different ways of thinking, different experiences, I think when you bring that all together, the diversity is an amplifier. My general guiding principle from a leadership perspective has always been to lead the way I like to be led. I do like having ownership, again, of a project, a task, whatever it may be. I like the autonomy that comes with that.

I like the responsibility and I like the accountability. Not everyone likes those things. So again, the diversity of thought and experiences will help. I'm very much focused on the team as opposed to the individuals.

I've always said as well in terms of my mantra is that leaders lead. And our first job as leaders is to get our staff and our team to take their head off the pillow in the morning. Again, some people naturally do that by default, but should never be seen as a given that everyone immediately jumps up and immediately... gets ready to rock and roll whatever challenges are coming to them that day.

And has that always been the case in your leadership style or has your leadership style sort of changed and evolved over time? And if so, how has it evolved? I'd like to think I've got better as I've matured and as I've got more experienced. I've always had a strong desire.

I've always had fire in the belly, right? I've always... Had a strong desire to improve the situation where I am and make things better. It's one of the things that attracted me to information security, actually.

But as I have matured and as I have got more experience, I think I've also slowed down. When I reflect early on in my career, I do think at times, with the benefit of hindsight, I do think at the times I was too fast. I had too much fire in my belly. And then...

Often the consequences of that are you're not seen as a leader. You don't have people naturally come and follow you there. And so from an experience and maturity perspective, I'd say I've probably got more self -awareness now. I'm very much an extrovert type of person.

That's not the case with everyone in my team. In fact, most of my current team are very introverted. And so, again, with experience, I think what I've learned is everyone is made up differently. And so how do you get the best out of people who don't have the same traits as you, don't have the same strengths, if you like, as you, don't have the same weaknesses as you?

And I think as you package all that together, and again, with that one team mantra, I think that I have become a better leader, certainly more self -aware. One of the things I'm constantly asking for is feedback. I think it's a gift. I think it's great when people trust you enough to receive feedback, especially if it's not actually something you might necessarily want to hear.

But I think if people do trust you and they are comfortable with it, giving that feedback is hugely important. Was mentorship a part of that growth journey for you along the way? Like, did you have mentors? Yeah, for sure.

Lots. And again, when I reflect all my mentors, they weren't all always necessarily people. who were my immediate boss or more senior to me. In many, many respects, the learnings that I've received are from people who are junior to me, who maybe not even necessarily in information security.

But I think the ability to learn and being receptive and open to learning, particularly learning not only where you're strong, but moreover, where you're weak, where you need to improve. I think that that's huge. The continual need and desire to learn and to improve, I think, is strong in me. And a key component to that is always the ability to receive feedback.

So let's get to teams for a second. You've managed large teams, I'm sure. You've managed small teams, I'm sure. But with every team, right, there's always conflict.

There's misalignment between your team and the business stakeholders. Can you talk a little bit about how you handle that sort of conflict? Yeah. To put it simplistically, when you have those conflicts, when you have that friction, I think a lot of it comes down to communication.

Again, whether it's verbal or nonverbal communication. And in those situations, what I find often... to be a secret to success is the ability to listen. Hear the other opinion.

One thing as security leaders, sometimes we forget that our businesses aren't necessarily in the business of security, right? We aren't necessarily the number one priority for our organizations. And so having a sensitivity to the end user experience, for example, when we apply security, that's really key to our success. And then moreover, ensuring that other teams, other individuals in your organization actually want to collaborate with you.

I think that's hugely important, again, to our success, that they see us as open, that they see us as people who are willing to listen to new ideas, listen to challenges, listen to how security impacts their day -to -day business. I think that really is important. And ultimately, as I say, is our success. Sounds like you're really breaking down departmental barriers.

Do you report to your CEO? No, I have. I have in the past in this organization. We just recently went through a reorganization.

So I report to the CFO stroke COO in the organization. I know in the past you've talked about your belief is that the. CISO and the CIO should be peers and not necessarily part of the reporting structure. And I'm curious if you think that CISOs that do support to a CIO, if that could have sort of any stifling impact on their ability to lead.

I think this is a great question. And this is such a hot topic and it remains such a hot topic. And it talks really to the evolution of the CISO role. What I would say today, because my mindset has changed, what I would say is I've had the pleasure of working with some great CIOs.

And the relationship, it doesn't matter if I was reporting to them or they were reporting to me, between the pair of us, we got things done. That was based on loss of respect, loss of open communication, and a general awareness of each other's priorities, needs, wants, etc. I've also been the opposite. where CIOs just don't understand the need for information security, don't understand our priorities, what we're trying to do.

And that was just a nightmare. What I would say today is where the CISO reports, for me personally, is less of an issue. For me, the importance is what's the influence the CISO has on that person. Presumably it's within...

one of the executive team members. And that's the priority. I spoke to someone a few months ago, actually, and they were saying they report to the general counsel. And in their organization, the general counsel happened to be the person that got things done in their organization.

And so if I was a CISO in that organization, I would probably want to report to the general counsel. Now, in another organization, it might be completely inappropriate. But as I say, as security leaders, I would focus less on who we report to and moreover, what advantages does it give the security program as a whole? And what influence do you have both directly and indirectly across the organization from a security perspective?

Thank God we're recording this because that could be the most thoughtful and pragmatic answer I've ever heard to a very complicated. Hot topic. Thank you. So speaking of another hot topic, it's burnout, right?

We know that there's many people in our industry that do suffer from burnout. And as a leader, I think you really have to have your eye on that. So maybe talk about how you can recognize that in your team. But also, I assume in a leader, you're pulled in so many different directions within your company.

I'm sure you have to say no to some things. You have to recognize burnout in yourself. Yeah, sure. I mean, the first thing I would say is burnout is real.

I think, and it doesn't just apply to security leaders or people in information security. I think across organizations, regardless of your role. And I think what happened during COVID is a lot of potential issues that were hitting are under the surface. came to the surface, cracks appeared, and burnout was definitely one of those I think was amplified.

I think our personal, physical, and mental health is our number one priority. And as leaders, to your point there, Kevin, we need to be sensitive to seeing our team burning out. But moreover, to be effective leaders, to your point, we have to recognize it ourselves. I can tell you...

I definitely burnt out, I think, last year. As I said before, I'm an extroverted type of personality. I need the energy of people physically with me for my creative juices to flow. And there was a period last year where I just, I was getting nothing from the people I was engaging with.

And that was a huge red flag for me in terms of, oh, what's going on and what's going here? I was constantly tired. I just didn't have my mojo. And I spoke to my wife about it.

And I spoke to a professional counselor about it as well in terms of, hey, again, back to my thought earlier in terms of feedback is important. And that counselor gave me some wise advice. Think about this. Think about that.

In this scenario, what would you do differently? And all those things. And what that gave me was... more self -awareness, more tools to recognize even within myself where burnout is happening and apply that to the team as well.

One thing I love about our team is we've built a very, very strong culture. We're very open. We're very direct with each other. And we have lots of fun as well because there's a large amount of trust with our team.

We have lots of fun. There's just lots of jokes and laughs because again, I think that's important. But in those quieter moments when we have one -on -ones, and again, truly a gift, some of my team have opened up and said, hey, I'm struggling with this, I'm struggling with that. And we've spoken about it openly.

And again, creating that safe environment where people do feel vulnerable. And again, I've spoken openly with my team in terms of my experiences with it. I think that really helps. And even a bit of self -care, a bit of self -therapy will go a long, long way.

And then moreover, what is the path? What is the right path for that individual to get through whatever challenges they're going through? Because again, from a pure leadership perspective, one of the things I'd like to pride myself on is I don't see my team as just work colleagues. I see them as human beings.

We all have personal lives. We all have families. We all have tons of things going on, right? And not everyone...

is consistently running at a hundred percent all of the time and so when there are dips because we have a strong trust within ourselves um we feel and i definitely feel comfortable of asking sometimes personal questions and if the person feels comfortable with me more often than not they will generally open say yeah well actually you know my kid was sick last night or we're going through this kind of challenge at home or whatever and again just treating people with empathy, with respect, and creating that trust environment, I think is huge for us as security leaders.

Well, thank you for your honesty and bringing that back to your own personal experience. I think it is a really important topic to socialize. Yeah, I think historically, I think there's been a big stigma, particularly talking about mental health. I'd like to think that that stigma is no longer there.

I'm sure for some people it's... Well, in fact, I know for some people it's a very uncomfortable conversation to talk about. But even in the news last night, you saw the Red Sox player who was opening up in terms of their own mental health issues. I think the more we talk about this, I think the better it becomes.

And even if you're not comfortable at all in opening up, just hearing those stories and hearing that it's not just you who's impacted or going through these issues. I think that helps. And again, the more we talk about it, the less stigma there is. And ultimately, at some stage, we all need help throughout our lives, right?

Absolutely. And this is natural. Again, it's health, right? Whether it's physical, mental, or whatever.

Now, have you got any of sort of this wealth of knowledge and advice from any books? Can you think of any books that you've read that... have impacted your leadership style? I mean, there are so many, I mean, you know.

To be honest with you, Kevin, I've not. It's one of the things I promised myself this year, actually, I'm going to read more books. But what I do do is I read books from leaders and learning from their experiences as opposed to, well, you should do this and you should do that sort of thing. That said, I mean, a couple of books that I have read and I've worked through from a team bonding experience.

is Patrick Lenconi, The Five Dysfunctions of a Team. Again, that book is all about, well, how do you get teams to work better together? And it takes you through that whole process. And likewise, his advantage.

Again, one of the things I'm really keen to continue to learn about is the importance of organizational health. Those are probably the two most recent ones. And when I think about leaders, right? Again, one of the big things for me as a leader is none of us have all the answers all the time, right?

You think of Winston Churchill, right? You would probably say that he wasn't a conventional leader, but he was certainly the right man for the moment, right? Leading the UK through World War II and whatnot. You look at some of the military generals, again, given my background, right?

What advice or what do you think is the best piece of advice for somebody who is either new to a leadership role or is an aspiring leader? My first piece of advice would be a sponge. I say this to most people. Observe, listen before you talk, and just take everything in.

I think that's hugely, hugely important, right? Again, context is critical. As security leaders, we never allow ourselves to have the luxury of living in a black and white world. And what I mean by that is, if I use our audit friends as an example, in many respects, they live in a black and white world in terms of a control of the work, so it doesn't.

As security leaders, we don't have that luxury. Our role is all about living in shades of gray. And our priority is to make those shades of gray as light as we possibly can. So being able to observe, being able to listen, being able to understand what the business is, I think is really, really important.

The other big thing, as I've mentioned a few times now, is build leadership through trust, right? Be vulnerable, be open, and make sure you're never, never in the position to say, hey, I'm the smartest person in the room. Or I have all the answers. Because as I say, no one has all the answers.

That's the whole point of building a team culture. Because as a team, collectively as a unit, you'll do wonderful things. And then moreover, again, back to the trust element. If your team trusts you, then they'll tend to do amazing things.

And for me, that's one of the delights of being a leader. You see people grow. You see them being able to do things that... Even the previous day, you never thought it was possible.

And when you actually observe that, it's absolutely wonderful to see. That's great. Have big ears and be open to others' ideas. Love it.

All right. Are you ready for the next phase of this podcast, Alex? So these are the rapid fire questions. They don't necessarily have anything to do with cyber, but it's just a little bit more of a peek into who Alex is.

Cool. Finally. All right. If your CEO gave you unlimited budget, as much as you wanted to spend for one thing, what would you spend it on?

Cyber education. We often talk about our staff being the weakest link and you get all the best technology. There's many examples out there where organizations that were compromised had all the best technology, but for whatever reason, they didn't have the right mix of people. process and technology.

And so for me, education is critical. So if the technology does fail, if you have a strong risk -aware culture within your organization, that people see security as the business advantage that it is, I think that would be huge. Huge. Okay.

Second question. You may have already answered this one. What? What was the last book you read in general?

So my last book was the latest Inspector Rebus book. I read that over Christmas. That's from Sir Ian Rankin. I'm from Scotland.

I'm from Edinburgh. So any Scots and certainly Edinburgh -based people will know who Inspector Rebus is. I love those books because it allows me to reminisce about the old country. And when they talk about places and this and the next thing, I see them in my mind.

Next question. If you could instantly master any new skill, personally, professionally, what would it be? Mine's guitar. All right.

Well, I'll go on that theme. I've always wanted to learn to play the piano, and I promised myself. I did a master's in information security leadership a few years ago, and I promised myself I would learn to play the piano, and I haven't. So my commitment to you, Kevin, is I'm going to dust off the ivory keys and get back on it.

Okay. I'm still at ground zero too. So let's make a pact to form a band. Let's get the band.

Let's get the band together. A couple last ones here. If you did not have a job in cybersecurity, what would you be doing? Well, I'd be in the band, of course.

All right. Last question. What's one piece of advice that you wish you had when you first started your career? You don't have to take on the world.

That's my earlier point in terms of on reflection. I always thought I was a mature person in my twenties and whatnot. But when I reflect back, I would have toned down my earlier self because you've got to work with people. Well, that's a wrap.

Alex, huge thank you for joining us. You know, I have to say, I think you do seem like one of very few who really is truly a born leader. And, you know, we really appreciate you sharing your time with us and your insight. And of course, our audience, thanks for listening.

If you found today's episode helpful and engaging, which I did. Be sure to subscribe, leave us a great review, and we'll catch you next time on Cybersecurity Business. Alex, thanks so much. Great having you.

Thank you for the opportunity, Kevin. And this has been wonderful. Thanks.

More from Cyber Security Business

All episodes →
  • AI Compute as a Business Risk70 / 100
  • The Path to CISO61 / 100
  • Creating an AI Security Culture63 / 100
  • Future-proofing and Storytelling80 / 100
  • Hungry for CISO Trends72 / 100
All Cyber Security Business episodes →