Listen to this Post
Introduction: When Cybersecurity Stops Being Just a Job
Cybersecurity is often described as a profession built on certifications, technical expertise, threat intelligence, and years of experience. But for Russ Kirby, the story is more personal. His career suggests that successful security leadership is not simply about knowing how systems work; it is about having the personality, curiosity, discipline, and courage to step into uncertainty and take responsibility when others hesitate.
A Career Built Around Curiosity
Today, Russ Kirby serves as Chief Information Security Officer at Ping Identity. His professional journey has taken him through Creditsafe, ForgeRock, and Hewlett Packard Enterprise, with cybersecurity gradually becoming less of an assigned responsibility and more of a natural calling. Ping Identity describes him as responsible for its global security strategy and execution across cybersecurity, governance, risk and compliance, incident response, and resilience.
From Technology Enthusiast to Security Executive
Kirby belongs to a generation that watched computers move from being specialized machines to becoming fundamental parts of everyday life. His fascination began with technology itself and, more importantly, with what technology might eventually make possible for humanity. That curiosity became the foundation for a career that would ultimately place him at the intersection of technology, business, risk, and security.
Cybersecurity Was Not the Original Plan
Interestingly, Kirby did not deliberately set out to become a CISO. His transition into cybersecurity happened because an organization needed someone to take responsibility for the function. He accepted the challenge, discovered that the work suited him, and continued moving toward increasingly senior security positions.
The Opportunity That Changed Everything
That first opportunity illustrates an important truth about cybersecurity careers: sometimes the biggest career move is not a carefully planned promotion but a problem nobody else wants to own. Kirby was willing to accept responsibility in an unfamiliar area, learn what was necessary, and discover whether he could succeed.
From Hewlett Packard to Creditsafe
Before becoming a CISO at ForgeRock, Kirby worked at Hewlett Packard Enterprise Services in global security roles. Creditsafe later appointed him as Chief Information Security Officer, where he was responsible for information security and helped shape cybersecurity risk management, intelligence, response, security architecture, and IT strategy.
ForgeRock Marked a Major Leadership Step
In July 2019, ForgeRock announced Kirby as its first Chief Information Security Officer. The company said he brought more than 15 years of security and compliance experience across large enterprises and startups. His responsibilities included information technology, global risk and compliance, and security operations.
The Journey Continued to Ping Identity
After spending years at ForgeRock, Kirby eventually moved to Ping Identity. His current role places him at the center of enterprise security, where the responsibilities extend well beyond traditional defensive technology. Security leadership increasingly requires understanding privacy, governance, resilience, identity, product security, business strategy, and the human behavior connecting all of them.
Why Kirby Calls It Luck
Kirby describes his career progression partly as luck. But his definition of luck is more interesting than simple coincidence. In his view, luck is the ability to recognize an opportunity, have enough conviction to pursue it, and possess the courage to act rather than remain comfortable.
Opportunity Means Very Little Without Action
This is one of the strongest lessons in Kirby’s career. Opportunities appear constantly in cybersecurity, but not everyone responds to them. A person may encounter a new technology, an unexpected leadership gap, or a difficult security problem and decide that it is someone else’s responsibility.
Courage Creates Career Momentum
Kirby’s approach is different. When a challenge appears, he tends to move toward it. That willingness to accept responsibility can create a reputation long before someone receives an official leadership title. People begin turning to the person who repeatedly steps forward when difficult situations emerge.
Leadership Often Comes Before the Job
Kirby’s story challenges the traditional idea that people become leaders only after receiving a management position. In cybersecurity, leadership frequently develops informally. Someone coordinates an incident, organizes a response, mentors colleagues, or creates structure during chaos. Eventually, the organization notices.
Bringing Order to Chaos
Kirby describes himself as someone who naturally enjoys creating order, discipline, and structure. That personality appears particularly compatible with cybersecurity because security teams routinely operate in environments characterized by uncertainty, incomplete information, competing priorities, and rapidly changing threats.
The Human Side of Security Leadership
Technical knowledge is essential, but cybersecurity is ultimately performed by people. A CISO must understand how individuals behave under pressure, how teams communicate, where expertise exists, and how different personalities respond to responsibility.
Mentorship Is Part of the Job
Kirby places significant value on mentoring people within his teams. His objective is not simply to fill positions but to understand how individual employees can contribute their strongest abilities. That requires recognizing that two highly skilled professionals may need completely different management approaches.
Building the Right Security Team
When recruiting cybersecurity professionals, Kirby looks for technical knowledge and awareness of security concepts. But enthusiasm matters enormously to him. His reasoning is straightforward: cybersecurity changes too quickly for someone to remain effective if they have no genuine interest in the subject.
Certifications Are Not the Whole Story
A candidate can possess numerous certifications and still lack curiosity. Another candidate might have fewer formal qualifications but maintain a home laboratory, contribute to GitHub projects, experiment with security tools, or spend personal time understanding how systems work.
Curiosity Is a Security Skill
The distinction matters because cybersecurity does not remain static. Tools change, operating systems change, cloud environments change, attack methods change, and now artificial intelligence is accelerating the rate of change even further.
The Passion Advantage
Someone who genuinely enjoys cybersecurity is more likely to continue learning when nobody is forcing them to do so. That creates an advantage that cannot easily be measured on a résumé.
Listening May Be the Most Important CISO Skill
Kirby’s most important personality trait for senior security leaders is the ability to continue listening when someone challenges their existing beliefs. That is an unusually important lesson for executives because authority can easily become an obstacle to learning.
Every Company Is Different
A security strategy that worked perfectly at one company can fail at another. The technology may be different, the risk appetite may be different, the employees may be different, and the business model may introduce completely different threats.
The Macro and the Micro
Kirby emphasizes the importance of seeing the macro picture before diving into the micro details. A CISO must understand the organization’s strategic objectives and then determine how security controls, processes, technologies, and people contribute to those objectives.
Security Cannot Be Managed From a Template
One of the biggest mistakes a new CISO can make is arriving with a prebuilt security philosophy and assuming the organization needs to conform to it. Strong leadership requires adapting the strategy to the environment rather than forcing the environment to fit the leader.
Is Cybersecurity Reactive or Proactive?
Kirby’s answer is nuanced: cybersecurity is inherently reactive, but the CISO’s objective should be proactive. Vulnerability scanning may technically react to the discovery of a vulnerability, yet its purpose is to identify and remediate the problem before an attacker exploits it.
Proactive Intent Matters
The same principle applies to penetration testing, hardening, threat hunting, security monitoring, and resilience planning. These activities exist because organizations know that attacks will eventually happen. The objective is to move the organization into a stronger position before the attack arrives.
Incident Response Is Reactive by Nature
There are situations where reaction cannot be avoided. Once an incident begins, defenders must respond. But even incident response contains a proactive element because the response seeks to contain the attack, reduce damage, protect critical systems, and prevent the next stage of compromise.
The Cybersecurity Agility Gap
The modern threat environment makes this balance even harder. Attackers can rapidly adopt new technologies, automate reconnaissance, discover vulnerabilities, and scale social engineering. Defenders must therefore become faster without sacrificing accuracy.
AI Is Changing the Equation
For Kirby, artificial intelligence is currently one of the biggest sources of concern. The issue is not simply that AI is another technology that needs security controls. AI is evolving rapidly while simultaneously becoming embedded in software development, business processes, identity systems, security operations, and decision-making.
The Question Behind the AI Anxiety
The deeper question is not whether AI is useful. It clearly is. The question is whether organizations understand the risks created by deploying increasingly capable systems faster than security teams can evaluate them.
AI Can Help Defenders Too
Kirby does not view AI only as a threat. He argues that organizations can use AI themselves as part of preventative security measures. This creates a technological race in which defenders can potentially use the same acceleration that benefits attackers.
Education Becomes a Defensive Control
One of
AI Is Not the First Technology to Cause Security Fear
There is also historical perspective in
The Pattern Repeats
The technology changes, but the security cycle remains remarkably consistent: adoption creates new capabilities, new capabilities create new attack surfaces, attackers experiment, defenders respond, security controls mature, and the industry eventually moves on to the next challenge.
AI May Eventually Become Ordinary
Kirby’s prediction is that in a few years, people may stop treating AI as something extraordinary. It could simply become another normal layer of computing infrastructure. When that happens, cybersecurity professionals will almost certainly be worrying about something else.
The Whack-a-Mole Problem
Cybersecurity has always resembled a technological version of whack-a-mole. A new attack technique appears, defenders respond, another weakness emerges, and the cycle continues.
What Changes With AI
What makes AI different is the speed of that cycle. AI can help attackers automate tasks that previously required significant human effort. It can also help defenders process information, identify patterns, generate detections, automate analysis, and improve response.
Burnout Is a Leadership Problem
Cybersecurity’s constant urgency creates another challenge: burnout. Security teams operate under the uncomfortable reality that success can be invisible while failure can be catastrophic.
The
A security leader may spend months building defenses that prevent incidents nobody ever sees. Yet one successful attack can instantly attract executive attention, regulatory scrutiny, customer concern, media coverage, and internal pressure.
Passion Can Become a Protective Factor
Kirby says he has avoided burnout partly because he genuinely enjoys cybersecurity. His point is not that passion magically eliminates stress. Rather, enjoying the underlying work can provide psychological resilience when the job becomes demanding.
Support Networks Matter
He also emphasizes the importance of maintaining relationships with other CISOs and security professionals. Senior security leaders frequently face decisions that cannot simply be delegated, making trusted peers an important source of perspective.
Protecting the Security Team
Kirby believes CISOs have a responsibility to protect their teams from unreasonable pressure. That can mean recognizing when someone has worked too long, encouraging employees to step away, and making it clear that personal life cannot always be sacrificed for security operations.
Security Leaders Need Boundaries Too
The lesson extends beyond cybersecurity. A team that is permanently exhausted cannot maintain high-quality judgment indefinitely. Security requires attention to detail, and exhaustion eventually becomes a security risk in itself.
What Keeps This CISO Awake?
When asked the classic question about what keeps him awake at night, Kirby points to AI. His concern is not simply malicious use of AI but the rapidity with which organizations are adopting it.
The Real Fear Is Speed
The most important word here is “speed.” Security teams can sometimes understand a technology when it develops gradually. Rapid adoption compresses the time available for evaluation, governance, testing, and risk management.
The Security Industry Is Entering a Faster Cycle
Organizations may deploy AI tools before fully understanding how data flows through them, what permissions they require, what external services they communicate with, how their outputs should be trusted, and what happens when autonomous behavior is introduced.
Identity Becomes More Important
This concern is particularly relevant for an identity-security company. Ping Identity’s current security messaging increasingly focuses on AI-driven identity threats and the shrinking gap between vulnerability discovery and exploitation. Kirby himself has written about AI security and the need for stronger identity controls as AI capabilities accelerate.
The Future Is Not Human Versus Machine
The future cybersecurity battle is unlikely to be a simple confrontation between humans and machines. It will be humans using machines against other humans using machines, with identity, authorization, data, software supply chains, and trust sitting at the center.
What Undercode Say:
1. Passion Is a Strategic Security Advantage
Kirby’s strongest message is surprisingly simple: genuine interest in cybersecurity can become a professional advantage. The field changes too quickly for people who stop learning.
2. Curiosity Beats Complacency
A security professional who constantly asks “How does this work?” is often more valuable than someone who merely knows the answer to yesterday’s security problem.
3. Leadership Starts Before Promotion
The CISO title is often the final expression of leadership rather than its beginning. People who repeatedly accept responsibility can become leaders organically.
4. Opportunity Rewards Preparation
Kirby’s concept of luck is useful because opportunity without preparation rarely produces sustained success. The opportunity arrives, but the individual must still be ready.
5. Cybersecurity Needs Courage
Security leaders sometimes have to make unpopular decisions. The right decision may involve shutting down systems, delaying a product, rejecting a risky deployment, or spending money that the business hoped to avoid.
6. Perfect Can Become Dangerous
The principle that perfection should not prevent good action is particularly relevant during incidents. Waiting for an ideal response can sometimes allow an attack to become worse.
7. Speed Matters During Incidents
When an organization is under active attack, the perfect theoretical response may be less valuable than a fast containment decision that prevents further damage.
8. But Speed Needs Judgment
Being bold does not mean acting recklessly. The best security leaders combine speed with enough understanding to distinguish an acceptable risk from a catastrophic one.
9. CISOs Need Business Awareness
A modern CISO cannot operate exclusively inside the security department. Security decisions influence products, customers, revenue, compliance, engineering, operations, and corporate reputation.
10. Security Must Speak Business
The strongest security programs explain risk in terms that executives understand. Instead of simply saying “this vulnerability is critical,” security leaders increasingly need to explain what could happen to the business if it remains unresolved.
- People Are Part of the Attack Surface
Employees, contractors, developers, administrators, executives, and increasingly AI agents all interact with corporate systems. Security therefore has to consider human and machine identities together.
12. AI Multiplies Both Sides
AI gives defenders powerful capabilities, but attackers can exploit the same technological acceleration. The advantage will go to organizations that integrate AI with strong controls rather than simply adopting AI as quickly as possible.
13. AI Governance Cannot Be an Afterthought
Organizations should not treat AI governance as paperwork added after deployment. Security, privacy, identity, authorization, monitoring, and data protection need to be considered before systems reach production.
14. Identity Is Moving Toward the Center
As organizations adopt autonomous agents, the traditional concept of a user logging in and maintaining a trusted session becomes less sufficient. Machines may act continuously and make decisions across multiple systems.
15. Continuous Authorization Matters
The security question increasingly becomes not only “Who are you?” but “Should you be allowed to perform this specific action right now?”
16. The CISO Must Understand Context
A suspicious action by one identity might be normal behavior for another. Context therefore becomes critical when evaluating identity and access decisions.
17. Security Teams Need Diversity of Thought
Kirby’s emphasis on listening to people who challenge existing beliefs is especially valuable. A team that always agrees with its leader can easily miss blind spots.
18. Dissent Can Improve Security
Security teams should make it safe for people to question assumptions, challenge architecture, and point out weaknesses in plans.
19. Certifications Still Matter
Kirby does not dismiss qualifications. Technical knowledge remains important. His argument is that qualifications should be combined with curiosity and enthusiasm.
20. Home Labs Reveal Curiosity
A candidate who experiments outside formal requirements demonstrates a different relationship with technology. It shows that learning is not entirely dependent on an employer.
21. Mentorship Multiplies Expertise
A strong leader does not simply solve problems personally. The leader develops people who can solve increasingly complex problems without constant supervision.
22. Burnout Creates Security Risk
Exhausted professionals can make mistakes, miss alerts, overlook vulnerabilities, and communicate poorly during incidents. Protecting employees can therefore become part of protecting the organization.
- Passion Is Not an Excuse for Overwork
Passion should make work meaningful, not justify unlimited hours. A healthy security culture needs both commitment and boundaries.
24. Peer Networks Are Valuable
CISOs face decisions involving uncertainty, politics, budgets, legal concerns, and executive pressure. Trusted professional relationships can provide perspective that internal teams cannot always provide.
25. Security Cannot Predict Everything
No organization can anticipate every attack. The goal is not perfect prediction but resilient preparation.
26. Resilience Beats Illusion
A mature security strategy assumes that some defenses will fail. The organization must therefore know how to detect, contain, recover, and learn from incidents.
27. Proactive Security Is a Mindset
Even activities that begin with the discovery of an existing weakness can be proactive if their purpose is to eliminate the weakness before exploitation.
28. The Threat Landscape Never Freezes
Organizations cannot declare victory after implementing a security framework. Attackers continue experimenting, technologies evolve, and business processes change.
- AI Is Part of a Larger Pattern
The current AI security debate should be viewed historically. Technology repeatedly changes the methods available to attackers and defenders.
30. The Next Threat Is Already Forming
While organizations debate today’s AI risks, attackers are experimenting with tomorrow’s techniques. Security leadership therefore requires continuous adaptation rather than a one-time transformation.
31. CISOs Are Becoming Strategic Executives
The
32. Security Can Enable Growth
A strong security program can become a business advantage when it allows an organization to adopt new technology with confidence rather than avoiding innovation altogether.
33. The Best Security Leaders Translate Complexity
Executives do not need every technical detail. They need clarity about consequences, priorities, trade-offs, and decisions.
34. Technology Needs Human Judgment
Automation can process enormous quantities of information, but organizations still need humans to determine priorities and acceptable risk.
35. AI Will Not Eliminate CISOs
If anything, increasingly autonomous technology makes security leadership more complicated. Someone must define boundaries, accountability, permissions, and acceptable behavior.
- The Future CISO Will Manage Machines Too
Security leaders will increasingly have to understand non-human identities, automated agents, software-to-software interactions, and systems capable of taking actions without direct human intervention.
37. Curiosity Will Become More Valuable
As AI automates more routine technical work, the ability to understand unfamiliar systems, ask better questions, and recognize unexpected risks may become increasingly important.
38. Adaptability Is Career Insurance
The cybersecurity professional who learns continuously is better positioned to survive technological transitions. Today’s specialist skill may become tomorrow’s baseline knowledge.
39. Leadership Is Ultimately About People
Behind every control, detection, policy, and incident response plan are people making decisions. Technology matters, but organizational behavior often determines whether security succeeds.
40. The Biggest Lesson Is Simple
Kirby’s career demonstrates that cybersecurity leadership is not built from one ingredient. Technical knowledge, curiosity, discipline, courage, adaptability, communication, mentorship, and genuine passion reinforce one another.
Deep Analysis: The CISO Command Center
COMMAND 01 — Identify the Real Career Signal
The most important career signal in
COMMAND 02 — Convert Opportunity Into Action
Cybersecurity professionals should treat unexpected responsibility as a potential career accelerator. The objective is not to accept every task blindly, but to recognize when a difficult assignment can create meaningful experience.
COMMAND 03 — Build Curiosity Into Recruitment
Security hiring should evaluate how candidates learn, experiment, investigate, and respond to unfamiliar technology—not only what credentials they already possess.
COMMAND 04 — Challenge the Leader
Security leaders should deliberately create environments where experienced team members can disagree. A challenge from an informed employee may reveal a weakness before an attacker does.
COMMAND 05 — Separate Urgency From Panic
Incident response requires speed, but speed should come from preparation and clear decision-making rather than fear. Organizations should establish escalation paths before crises occur.
COMMAND 06 — Treat AI as an Expanding Attack Surface
Every new AI deployment should be evaluated for data exposure, excessive permissions, identity risks, unauthorized actions, dependency risks, monitoring gaps, and potential abuse.
COMMAND 07 — Give AI a Security Identity
As AI agents gain the ability to perform actions, organizations need to know which identity an agent is operating under, what it can access, what it can change, and how those actions can be audited.
COMMAND 08 — Measure Security by Resilience
The question should not simply be whether an organization has avoided every incident. A more useful measurement is how quickly it can detect, contain, recover from, and learn from an incident.
COMMAND 09 — Protect the Defenders
Security teams cannot operate indefinitely under emergency conditions. Leaders should monitor workload, encourage recovery, distribute responsibility, and make sustainable performance part of security strategy.
COMMAND 10 — Never Stop Learning
The cybersecurity environment that exists today will not be the environment that exists tomorrow. The strongest defense is therefore not a static collection of tools but an organization capable of continuously learning and adapting.
✅ Russ
Ping Identity identifies Russ Kirby as its Chief Information Security Officer and says he is responsible for global security strategy and execution across cybersecurity, GRC, incident response, and resilience.
✅ His ForgeRock and Creditsafe Background Is Supported
ForgeRock publicly announced Kirby as its first CISO in 2019 and identified Creditsafe and Hewlett Packard Enterprise Services among his previous employers. Creditsafe also confirmed his appointment as CISO after his time at Hewlett Packard Enterprise.
⚠️ Some Personal Interpretations Are Not Independently Verifiable
Statements about Kirby being a “natural born CISO,” his Enneagram Type One classification, his personal feelings about burnout, and the detailed motivations behind his career are interview-based personal accounts rather than independently measurable facts. They should therefore be understood as Kirby’s perspective rather than objective scientific conclusions. The broader claims about AI risk and cybersecurity evolution are reasonable industry analysis, but specific future outcomes remain uncertain.
Prediction
(+1) AI Will Become a Permanent Part of Defensive Security
AI is likely to become increasingly integrated into threat detection, vulnerability management, identity monitoring, security operations, incident analysis, and defensive automation. The technology will not eliminate cybersecurity work; it will change the speed and scale at which security teams operate.
(+1) Identity Will Become Even More Important
As organizations deploy AI agents and automated systems capable of taking actions, identity and authorization will become increasingly central to security architecture. Knowing which human or machine is performing an action—and whether that action is legitimate—will become more important than simply protecting the network perimeter.
(+1) CISO Roles Will Become More Strategic
The modern CISO is likely to become increasingly involved in technology strategy, AI governance, business resilience, privacy, product security, and executive decision-making. Security will continue moving closer to the center of corporate strategy.
(+1) Adaptability Will Outperform Static Expertise
Professionals who can continuously learn and adapt will have an advantage over those whose expertise depends heavily on one generation of technology. The cybersecurity career path will increasingly reward curiosity as much as credentials.
(-1) The AI Security Gap Could Widen Before It Narrows
Organizations may continue adopting AI faster than they can develop effective governance and security controls. If that happens, the difference between technological capability and security readiness could become a major source of enterprise risk.
(-1) Security Teams Could Face More Pressure
The acceleration of attacks and technology adoption may increase workload and decision pressure for CISOs and their teams. Without better automation, staffing, prioritization, and organizational support, burnout could become an even larger problem.
(+1) The Next Generation of CISOs Will Need Both Technical and Human Intelligence
The strongest future security leaders will likely combine technical understanding with communication, business awareness, emotional intelligence, strategic thinking, and the courage to make difficult decisions under uncertainty.
Final Perspective: Cybersecurity Rewards Those Who Move Toward the Unknown
Russ
The Real Secret Is Not Simply Passion
Passion alone does not create a successful CISO. What makes passion valuable is what it produces: continuous learning, resilience, curiosity, better judgment, and the willingness to keep going when the environment changes.
The CISO of Tomorrow Will Need to Embrace Uncertainty
Cybersecurity will never become a finished discipline. New platforms will replace old ones. AI will evolve. Attackers will discover new techniques. Organizations will adopt technologies before security teams fully understand them.
And That Is Exactly Why the Profession Remains Interesting
Kirby’s perspective ultimately returns to the same idea that shaped his career: technology constantly creates new problems, and cybersecurity exists to understand those problems, reduce their consequences, and find ways forward.
The Career Lesson Is Bigger Than Cybersecurity
The most valuable lesson may therefore be broader than information security. Opportunities rarely arrive perfectly packaged. Sometimes they appear disguised as difficult assignments, unfamiliar responsibilities, or problems nobody else wants to solve.
Step Forward When the Moment Arrives
The people who build remarkable careers are often not those who predicted every turn in advance. They are the people who recognized an opening, prepared themselves, listened to others, accepted responsibility, and had the courage to move.
In Cybersecurity, the Next Challenge Is Already Waiting
And as AI accelerates the pace of technological change, that ability to move forward may become one of the most important qualities a security leader can possess.
▶️ Related Video (70% Match):
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: www.securityweek.com
Extra Source Hub (Possible Sources for article):
https://www.reddit.com/r/AskReddit
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




