Overview
Gary Hayslip serves as Field CISO and Executive in Residence at Zenity[1] and holds the position of Strategic Advisor at Halcyon[4]. Hayslip's career spans more than two decades at the intersection of cybersecurity, technology operations, and executive leadership, with experience serving as CISO, CIO, CSO, Field CISO, and Operating Partner across federal government, global enterprise, financial services, telecom, and high-growth technology environments[2]. Hayslip holds an MBA in Business from San Diego State University[11] and a Professional Certificate in Managing Risk in the Information Age from Harvard University[12]. Hayslip serves on multiple boards of advisors and directors, including positions at iVerify[7], the San Diego Cyber Center of Excellence[8], San Diego State University's Management Information Systems program[9], and Nisos[10], and co-founded CISO DRG Publishing[6].
Profile introduction
I've spent more than two decades at the intersection of cybersecurity, technology operations, and executive leadership and I've learned that the best security programs aren't built on fear. They're built on strategy, trust, and a clear-eyed understanding of the business. My career spans every dimension of the security executive role. I've served as CISO, CIO, CSO, Field CISO, and Operating Partner across federal government, global enterprise, financial services, telecom, and high-growth technology environments. I've built security programs from the ground up, modernized inherited ones under…
Career history
- VP, CISO in Residence (Field CISO)Jul 2026 to presentZenity
- Strategic AdvisorMay 2026 to presentHalcyon
- VP, CISO in Residence (Field CISO)Sep 2025 to May 2026Halcyon
- Co-Founder & Member, Board of DirectorsApr 2015 to presentCISO DRG Publishing
- Member of the Board of AdvisorsJan 2026 to presentiVerify
- Member Board of DirectorsDec 2025 to presentSan Diego Cyber Center of Excellence (CCOE)
- Management Information Systems (MIS), Member of the Board of AdvisorsSep 2024 to presentSan Diego State University
- Member of the Board of AdvisorsMar 2023 to presentNisos
Education
MBA, Business2011 - 2013San Diego State University
Professional Certificate, Managing Risk in the Information AgeSep 2020 - Dec 2020Harvard University
- Navy Network/System Certifier Certification, Fully Qualified Network Validator - Advanced2008 - 2008Naval Postgraduate School
Insights & ideas
The through-line
Everything Hayslip says circles back to a single conviction: security leadership is a collective craft, and the people doing it owe each other help. He tells CISOs facing a new year of decisions to "go back to the community to your peers who are actively in the seat who are actively doing this" rather than working in isolation, because "you're not in this alone" [1]. The same instinct produced his books, his work with transitioning veterans, and his running list of executive recruiters he shares with people he knows are ready [2]. The second, quieter through-line is a refusal to treat the job as rule-following. His experience moving from the military to civil service to a city government to private industry taught him that the answers are situational, that no organization achieves total security, and that humility is part of the leadership skill set [2].
On not doing it alone
Asked what advice matters most going into a new year, he starts from the assumption that peer networks already exist and are underused: "you should already be actively in the community talking with your peers cuz everybody right now is dealing with us," comparing project lists, open problems, and vendor conversations [1]. The point is not general networking but talking to people currently holding the same seat, so the exchange is about live work rather than theory [1]. He extends the same logic to people entering the field, where the barrier is usually pride: "don't be afraid to go ahead and say that you need help," because everyone who has made the same transition asked for guidance, and "you don't always have to do it all yourself" [2]. The value of the ask is that the people ahead of you have already burned themselves. "We've already made mistakes. We already know, you know, uh, things that have kind of screwed up," and they are willing to say so [2]. He credits his own progression to mentors "who didn't have a problem smacking me upside the head and saying, 'No, that's not really a good idea. What the hell are you thinking?'" drawn from CIOs, CISOs, and executives outside security [2]. That framing of knowledge sharing as mentorship rather than pronouncement is a subject he has explored directly, questioning whether what the community actually needs is thought leadership or thought mentorship [11], and he has discussed how mentors themselves need to adapt as the role changes [9].
On writing the CISO Desk Reference Guides
He resists being cast as the sole authority. "First off, I'm not the only guy," he says, naming co-authors Matt Stamper and Bill Bonney and insisting the work was done as a team [2]. The origin was accidental and social: he had been writing articles to help military brothers and sisters understand what working in cyber and leading civilian teams would be like, and at a startup event, over fish tacos and beer, Stamper proposed they write it together [2][10]. "Then and then we realized, oh, we had committed to writing a book," he says of the 2014 to 2015 period when the first volume took shape [2].
The structural discovery was that three voices per chapter beat one. "Having three points of view you know for each chapter work really well," he explains, because "where Bill was really really strategic I was very practitioner," giving readers genuinely different views of the same problem [2]. The purpose was never commercial. "It wasn't to go ahead and make anybody rich or anything like that at all because, you know, you don't really get a lot from writing books" [2]. What validates it for him are the encounters: readers in multiple countries and languages, and a dinner conversation with the CTO for MGM who described using the book in 2015 while at Army Cyber Command to figure out what a private-sector CISO job would even involve [2]. The books were never meant as doctrine. He wanted to hand somebody "a uh a point of reference, you know, of where to start," on the assumption that "they'll just adjust it to their journey" [2].
On working in the gray
The recurring lesson he presses in his practitioner writing is that the job resists binaries: "in all of the books I've written from the practitioner level, I'm constantly telling people it isn't black and white, it's gray" [2]. What makes it gray is that the work is inseparable from managing teams, politics, and risk trade-offs rather than executing a checklist [2]. He contrasts this explicitly with military structure, where "these are the rules. You must follow the rules or else," and with DoD environments organized around directives where "you either are on or you're off. You know, there is no in between" [2]. Alongside that sits his acknowledgement that no organization gets to 100% security, and that humility is a requirement of security leadership rather than a nicety [2].
On transitioning out of the military into cyber
His advice to service members is to start absurdly early. "Don't wait till you are like a month out," he says. "You should be planning you know five years out honestly" [2]. That head start should go into professional organizations, luncheons and meetings, and not only veteran networks but the professional communities of the field being entered, because "it helps you understand the kind of jobs that are being hired, the skill sets that people are looking for," and lets you fine-tune education and pick up extra classes before you need them [2]. Certifications matter only insofar as they are the right ones for the target role, which he worked out by mind mapping: deciding he wanted to be a network architect, then breaking that backwards into required experience and credentials [2]. He credits the military itself for teaching him this method, "being a systems thinker and how to break, you know, problems down into pieces, you know, that are manageable so that you and your team, you know, can get focused" [2].
He is candid that the transition is frightening for practical reasons. In uniform much is taken care of; on the outside, bills, spouse, and children all arrive at once, and retirement pay "isn't enough. You know, it's it's not really designed for that" [2]. He also names his own gap. Going into civil service after twenty years and finding himself dealing with admirals, deputy secretaries and very large budgets, "I was kind of scrambling you know because I knew right away I was in a different playing field here and I needed to go ahead and learn what the new rules were," which is what drove him to do an MBA before moving deeper into board and executive work [2]. He remains active with veterans groups and with the Military Cyber Security Professional Association's community [2], and has talked elsewhere about how his own path into information security began [4].
On silos and what government service teaches you
Six years in civil service as a CISO and deputy CIO for the US Navy left him alert to organizational self-protection. "You do get these you know these silos you know and a lot of times I think the services are kind of designed that way you know they each of them protect their funding" [2]. Doing network auditing for the inspector general's office meant crossing those boundaries, where "sometimes, you know, they kind of looked at you from a hostile point of view. Who are you? You know, you're not from our group" [2].
City government was the opposite problem and, to him, the more interesting one. As the first CISO for the City of San Diego, "you had a lot more freedom to be able to go ahead and do things," unconstrained by DoD directives [2][10]. The famous exchange came when he asked his CIO which framework to follow and was asked in return, "what's a framework?" His first reaction was fear, then opportunity: nobody would know if he made mistakes, and he had real lateral movement to design the program [2][10]. The environment was not small. Twelve thousand employees, forty departments, a multi-billion dollar operation, twenty-five networks, over a hundred thousand endpoints, and connections running to organizations from Europol to the Marshals Service to the FBI. "None of it was documented" [2]. The outsourcing contract ran ninety pages with three paragraphs on one page covering security, and there was almost no budget, because the prevailing assumption was "hey, we're going to go ahead and hire a siso and we'll be safe" [2]. His answer was that hiring a leader is not a control: "we actually got to build things" [2]. With little funding but a large local cyber community, he turned to working with San Diego startups, and ended up with a lawyer assigned to his team handling e-discovery and vetting those startups [2]. His affection for startups is longstanding: "I love working with startups and and seeing people build things" [2].
On the CISO as an executive, and what comes after
Across his appearances he keeps returning to how much the role has expanded, discussing the biggest changes and challenges facing CISOs today [3] and the growing complexity of the job and how CISOs adapt to it [9]. The direction of travel he describes is toward genuine executive leadership rather than a technical function [8], with the central skill being the ability to build a risk narrative that executives can act on [6]. He has also addressed how elite security teams stay ahead [5], and pushed against the idea that CISO is the ceiling, discussing career growth beyond the traditional apex on the strength of a path that ran through military service, US Navy civil service, and the City of San Diego [7]. That path is why he treats business fluency as non-negotiable; the MBA was pursued precisely because board directorship and executive team work demanded a vocabulary the technical side does not supply [2].
Takeaways
- Treat peer networks as an operational tool, not a nicety: compare this year's projects, current issues and vendor conversations with people "actively in the seat" rather than solving in isolation [1].
- Security leadership does not run on binaries. "It isn't black and white, it's gray," and the gray is where risk, teams and politics get managed [2].
- Multiple authorial perspectives beat a single authoritative one; the CISO Desk Reference Guides worked because strategic and practitioner views sat side by side in each chapter [2].
- Books and reference material should be a starting point that readers "adjust to their journey," not a template to follow [2].
- Military members should begin planning the move into cyber roughly five years out, joining professional communities early to learn which roles are hiring and which certifications actually matter [2].
- Asking for help is the efficient move, not the weak one: people ahead of you have already made the mistakes and will share recruiter contacts and guidance [2].
- Hiring a CISO is not a security control. Contracts with three paragraphs on security and no budget mean the program still has to be built [2].
- Freedom from a mandated framework can be an advantage, but only if you document what you inherited first; undocumented networks and connections are the real starting position [2].
Media & appearances
- CISO Tradecraft®Apple Podcasts#289 - What's the Best Career Move After Being a CISO? (with Gary Hayslip)On this episode of CISO Tradecraft, host G Mark Hardy talks with Gary Hayslip about cybersecurity career growth beyond the traditional CISO “apex,” drawing on Hayslip’s 25+ years across military service, US Navy civil service, the City of San Dieg
- Hacker Valley StudioApple PodcastsWhat Makes a Great CISO? A Playbook from Gary HayslipWhat separates a great CISO from a great one? In this powerhouse conversation, Ron invites friend and cybersecurity leader Gary Hayslip, CISO at SoftBank Investment Advisers, back on the mic to discuss what it takes to lead in today’s high-stakes digi
- CyberOXtalesApple PodcastsBuilding a Risk Narrative: Gary Hayslip’s Cybersecurity Playbook for ExecutivesBuilding a Risk Narrative: Gary Hayslip’s Cybersecurity Playbook for Executives In this episode of CyberOXtales, host Neatsun Ziv, CEO of OX Security, sits down with Gary Hayslip, CISO at SoftBank Investment Advisors, to explore how CISOs can build ri
- Root To CISOApple PodcastsThe Road to CISO: Lessons from Gary Hayslip’s Career | Root To CISO PodcastIn this episode of The Root to CISO Podcast, we sit down with Gary Hayslip, CISO at SoftBank Investment Advisers, to discuss his journey from the military to cybersecurity leadership. Gary shares insights on the evolving role of the CISO, building resilient security programs, and the importance of mentorship in the industry. He also provides advice for aspiring security leaders and reflects on the challenges of securing global investments. Don’t miss this conversation packed with valuable les...
- The ITSPmagazine PodcastApple PodcastsCyber Wars: How Elite Teams Stay Ahead of the Game | A Conversation with Gary Hayslip | The Soulful CXO Podcast with Dr. Rebecca WynnGuest: Gary Hayslip, CISO, SoftBank Investment Advisors LinkedIn: https://www.linkedin.com/in/ghayslip/ Website: cisodrg.com/biographies/gary-hayslip/ Host: Dr. Rebecca Wynn On ITSPmagazine 👉 https://www.itspmagazine.com/itspmagazine-podcast-ra
- Human-Centered SecurityApple PodcastsComplexity Undermines Security With Bill Bonney, Gary Hayslip, and Matt StamperWhat do CISOs have to say about the security tools their teams use?: “When we introduce a level of complexity in the system, it undermines security. Every moment wasted trying to use a tool effectively benefits the adversary.” - Matt StamperIn this episode, we talk to cybsecurity leaders Bill Bonney, Gary Hayslip, and Matt Stamper about: The ever-evolving role of the CISO and what CISOs care about most.What product teams designing security software need to understand:Security tools need to operate across varied ecosystems (which means your product team needs to understand those ecosystems).Complexity is the enemy of security. Yes, UX matters.Context-switching means security teams waste time. Instead, security tools need to present the right information at the right time.Why CISOs are excited to leverage AI in security tools—and what concerns them the most.Bill Bonney, Gary Hayslip, and Matt Stamper are seasoned CISOs and cybersecurity leaders. They are co-founders of the CISO Desk Reference Guide—a series of books including topics such as security policy, third-party risk, privacy, and incident response—which provide actionable insights for security leaders.
- The Professional CISOApple PodcastsBuilding the Professional CISO: Gary Hayslip on Merging Risk, IT, and BusinessIn this episode, David Malicoat interviews Gary Hayslip, Global Chief Information Security Officer (CISO) at SoftBank Investment Advisors. Gary shares his deep insights on the evolution of the CISO role, discussing how it’s becoming more integrated with risk management, business strategy, and AI. He reflects on his own career journey from the U.S. Navy to becoming a global cybersecurity leader, offers practical advice for veterans transitioning into cyber roles, and explores how the future of cybersecurity leadership is shaping up. Whether you’re an aspiring CISO, a cybersecurity professional, or a business leader, this episode is packed with actionable insights and advice from one of the most respected figures in the industry. Key Topics Discussed: • Gary Hayslip’s Journey: From military service to global cybersecurity leadership. • Professionalizing the CISO Role: Why the CISO role is evolving and how it’s merging with other business and risk functions. • CISO Tenure and Burnout: Understanding why CISO tenures often range from 18 to 36 months and the factors behind this. • Advice for Veterans Transitioning to Cybersecurity: Gary shares how veterans can prepare for civilian cyber roles and why cyber offers a “mission-driven” career. • The Future of the CISO Role: AI, risk management, product security, and why the CISO’s responsibilities are expanding.
- LeaderbookAIApple PodcastsWhy CISOs Are Becoming Executive Leaders | SoftBank's Gary HayslipA seemingly harmless email can steal your data or even lock you out of your computer. So why take that chance? Join us as Gary Hayslip, a seasoned Chief Information Security Officer (CISO), reveals the critical role of cybersecurity leadership in
- Redefining CyberSecurityApple PodcastsDeveloping Personal Thought Leadership Through Passion, Purpose, and Progress: Leading the Way in Cybersecurity Knowledge Sharing | A Conversation with Gary Hayslip | Redefining CyberSecurity Podcast with Sean MartinIn this episode of the Redefining CyberSecurity Podcast, host Sean Martin is joined by guest Gary Hayslip to discuss thought leadership and knowledge sharing in the cybersecurity community. But is it thought leadership we seek or thought mentorship?
- The ITSPmagazine PodcastApple PodcastsDeveloping Personal Thought Leadership Through Passion, Purpose, and Progress: Leading the Way in Cybersecurity Knowledge Sharing | A Conversation with Gary Hayslip | Redefining CyberSecurity Podcast with Sean MartinIn this episode of the Redefining CyberSecurity Podcast, host Sean Martin is joined by guest Gary Hayslip to discuss thought leadership and knowledge sharing in the cybersecurity community. But is it thought leadership we seek or thought mentorship?
- CISO TalksApple PodcastsAdvice for CISOs & Aspiring CISOs Ft. Gary Hayslip | CISO TalksIn this episode of CISO Talks, Gary discusses CISO strategies in parallel with tenures and how the evolving climate has been affecting the averages and strategies as a whole. Whether you are a well established CISO or an aspiring CISO, this discussion will hopefully be of interest to you. Guest in this episode: Gary Hayslip - Global CISO | Board Member | Investor | Mentor | Servant Leader Also available on: IGTV: www.instagram.com/instalepide SoundCloud: bit.ly/2MYHwxR Spotify: spoti.fi/2N0XGXR iTunes: apple.co/2N0sO9P Follow us on Social Media: LinkedIn - bit.ly/2FWHKoM Twitter - bit.ly/2FWNO0C Instagram - bit.ly/2FWMxXj Facebook - bit.ly/2FXb2Ue Additional recording: CISO Talks.
- CISO TalksApple PodcastsThe Growing Complexity of the CISO Role Ft. Gary Hayslip | CISO TalksIn this episode of CISO Talks, we discuss the growing complexities of the CISO role over time. What is becoming more complex and how are CISOs coping/adapting with these changes. We also touch on the mentoring aspects for CISOs and how mentors need to adapt to stay parallel with the evolving role of the CISO. Guest in this episode: Gary Hayslip - Global CISO | Board Member | Investor | Mentor | Servant Leader Also available on: IGTV: www.instagram.com/instalepide SoundCloud: bit.ly/2MYHwxR Spotify: spoti.fi/2N0XGXR iTunes: apple.co/2N0sO9P Follow us on Social Media: LinkedIn - bit.ly/2FWHKoM Twitter - bit.ly/2FWNO0C Instagram - bit.ly/2FWMxXj Facebook - bit.ly/2FXb2Ue Additional recording: CISO Talks.
- CISO TalksApple PodcastsHow The CISO Role is Changing Ft. Gary Hayslip | CISO TalksIn this very special episode of CISO Talks, we sit down with global CISO, Gary Hayslip. We discuss the ever changing role of the CISO and what some of the biggest changes and challenges CISOs are faced with today. Guest in this episode: Gary Hayslip In this very special episode of CISO Talks, we sit down with global CISO, Gary Hayslip. We discuss the ever changing role of the CISO and what some of the biggest changes and challenges CISOs are faced with today. Guest in this episode: Gary Hayslip - Global CISO | Board Member | Investor | Mentor | Servant Leader Also available on: IGTV: www.instagram.com/instalepide SoundCloud: bit.ly/2MYHwxR Spotify: spoti.fi/2N0XGXR iTunes: apple.co/2N0sO9P Follow us on Social Media: LinkedIn - bit.ly/2FWHKoM Twitter - bit.ly/2FWNO0C Instagram - bit.ly/2FWMxXj Facebook - bit.ly/2FXb2Ue Additional recording: CISO Talks.
- CISO Tradecraft®Apple Podcasts#71 - Lessons Learned as a CISO (with Gary Hayslip)On this special episode of CISO Tradecraft, we have Gary Hayslip talk about his lessons learned being a CISO. He shares various tips and tricks he has used to work effectively as a CISO across multiple companies. Everything from fish tacos and beer to how to look at an opportunity when your boss has no clue about cyber frameworks. There's lots of great information to digest. Additionally, Gary has co-authored a number of amazing books on cyber security that we strongly recommend reading. You can find them here on Gary's Amazon page.
- The Cyber Ranch PodcastApple PodcastsDeveloping Leadership w/ Gary HayslipToday, host and CISO Allan Alford interviews friend and fellow CISO Gary Hayslip. Besides being a brilliant business leader, Gary is an author, mentor, and one of the best all-around humans Allan knows! To start the conversation, Allan asks Gary to share about himself and his background in cybersecurity. While he had a natural interest in computers and technology more generally, Gary’s formal entrance to the cybersecurity field came during his time in the military. He developed a love for security, and as he’s climbed within the industry in the years after his military service, he’s also developed a strong network as a colleague and mentor. Allan tapped into this shared community through one of its most-used platforms, LinkedIn, to find out what others in the field would most like to learn from Gary. The first questions deal with topics of leadership and training, and Gary explains his own practices of educating himself and his team. In his own life, he is committed to maintaining up-to-date knowledge of his rapidly changing field through research and reading; such knowledge is necessary if Gary is to lead as effectively as he can. Gary also provides opportunities for his staff to receive continuing education, and he does not worry that he might train employees beyond their roles.
- CISO Talk by James AzarApple PodcastsCISO Talk with Gary Hayslip, CISO at Softbank Investment AdvisorsGary Hayslip joined me for Veteran November and a special CISO Talk episode, we talk about our military service, his outlook on cyber and leadership. Gary shares his views on what CISO’s are experiencing right now and how the industry is evolving and will evolve over the next few years. Don’t miss this amazing talk! Gary’s Bio: While others take pride in meeting all standards set before them, Hayslip's focus is delivering service beyond organizational expectations and creating a collaborative culture. As a leader and subject matter expert in Cybersecurity, Hayslip has had the opportunity to spearhead highly visible projects, drive immediate and long-range goals, and build dedicated high-performance teams to achieve enterprise enablement. With a multi-faceted background that spans both public and private sectors, Hayslip's scope includes working with and guiding global high-growth product and financial service organizations, the US Navy, and the City of San Diego. Combining his business acumen and hands-on approach, he focuses on "getting things done right the first time" with minimal disruption to business operations. As an expert communicator, he has continually demonstrated a high comfort level with publicizing and executing strategic plans as a spokesperson and liaison.
- CISO Talk by James AzarApple Podcasts#VeteranNovember with Gary Hayslip, CISO at Softbank Investment Advisors Part IGary Hayslip joined me for Veteran November and a special CISO Talk episode, we talk about our military service, his outlook on cyber and leadership. Gary shares his views on what CISO’s are experiencing right now and how the industry is evolving and will evolve over the next few years. Don’t miss this amazing talk! Gary’s Bio: While others take pride in meeting all standards set before them, Hayslip's focus is delivering service beyond organizational expectations and creating a collaborative culture. As a leader and subject matter expert in Cybersecurity, Hayslip has had the opportunity to spearhead highly visible projects, drive immediate and long-range goals, and build dedicated high-performance teams to achieve enterprise enablement. With a multi-faceted background that spans both public and private sectors, Hayslip's scope includes working with and guiding global high-growth product and financial service organizations, the US Navy, and the City of San Diego. Combining his business acumen and hands-on approach, he focuses on "getting things done right the first time" with minimal disruption to business operations. As an expert communicator, he has continually demonstrated a high comfort level with publicizing and executing strategic plans as a spokesperson and liaison.
This page shows public professional information only, each fact cited. Is this you? send a correction, or ask for removal within 24 hours, no questions asked.