CISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-Suite
Chris Wheeler, currently CISO at Resilience, draws heavily on his extensive experience in cybersecurity and leadership, particularly his time in the US Navy. He emphasizes the importance of trust – both in the CISO-team relationship and between the CISO and business stakeholders – as a cornerstone of effective security. Wheeler believes CISOs need to develop a blend of technical expertise, business acumen, and emotional intelligence to navigate the evolving threat landscape, especially with the rise of agentic AI. He advocates for a ‘mathematics of security’ approach, incorporating risk quantification, business analysis, and a focus on building strong relationships to ensure business resilience and minimize risk.
Chris Wheeler is the CISO at Resilience, and his career path has been shaped significantly by his time in the US Navy. He describes his cybersecurity journey as stemming from a childhood fascination with technology, nurtured by his father, a university IT administrator. Wheeler’s focus on cybersecurity emerged during his six years in the Navy, where he served as part of a cyber operations team – what the Navy termed ‘information warfare’ – and later as a division leader, overseeing 15 sailors. He credits the Navy with instilling a strong sense of mission and purpose, alongside leadership skills and a deep understanding of risk management.
Transitioning to the commercial world, Wheeler recognized that business operations differed significantly from military operations. He identified three key differences: the rapid pace of technological advancement, the increasing complexity of networks, and the need for a security leader to possess business analysis skills alongside technical expertise. He shifted his focus to building a team and fostering trust – a two-way street requiring both the CISO to earn trust from business leaders and to trust the security team members they recruited.
Wheeler believes the ability to engender trust is the single most important personality trait a CISO can possess. He emphasizes that CISOs must understand and apply risk quantification, describing uncertainty, and increasingly, mapping that to financial terms – a growing need as CISOs become more involved in business analysis. He advocates for a ‘mathematics of security,’ incorporating risk quantification, business analysis, and a focus on building strong relationships to ensure business resilience and minimize risk.
He cautions against a ‘perfectionist complex’ often found in security professionals, advising instead that CISOs prioritize empathy and balance, both personally and professionally. He encourages taking time off, prioritizing family, and pursuing hobbies to avoid burnout. Wheeler is also concerned about the rise of agentic AI, not solely from malicious actors, but also due to increased demand from boards and investors. To address this, he’s leading a secure enablement initiative focused on zero trust architecture, incorporating IAM, data inventory and categorization, and automation.
Ultimately, Wheeler’s approach to security goes beyond simply implementing technology. He stresses that successful security is rooted in understanding the underlying principles and applying them with empathy and a focus on building strong relationships – a ‘mathematics of security’ that combines technical expertise, business acumen, and emotional intelligence.