For many security leaders, the biggest challenge isn’t keeping up with the latest threats; it’s ensuring cybersecurity remains aligned with business priorities. Jigar Shah, Chief Information Security Officer at Medusind, believes the most effective CISOs are those who focus less on accumulating security technologies and more on solving real business problems. Drawing on more than two decades of leadership across healthcare, financial services, banking, retail, and consulting, Shah has built his career around connecting cybersecurity, technology, business strategy, and governance.
In this edition of CISO Tips, Shah shares the principles that shape his leadership approach, from evaluating vendors based on business outcomes rather than product features to eliminating “security theater” that adds complexity without reducing risk. He also explains why trust, not technology, is the foundation of every successful security program, and why CISOs should spend far more time preventing tomorrow’s incidents than reacting to today’s.
Complete this sentence: “Before you buy any new security tool, first...”
“...understand the business problem you’re trying to solve.”
Technology should never drive strategy. If you can’t explain the business outcome in one sentence, you probably don’t need another security tool.
“Buy fewer tools. Solve more problems.”
What’s one rule you enforce on your team that other teams would find strict?
“Never bring me a security problem without at least one business-focused solution.”
I don’t want my team to be known for just identifying risks. I want them to be known for enabling the business safely.
What’s a number or ratio that guides how you allocate budget, headcount, or your own time?
I follow a simple rule: 80% enabling the business, 20% fighting fires.
If I’m spending more time reacting than enabling, we’re investing in symptoms instead of resilience. Spend 80% preventing tomorrow’s incidents or issues that can become an incident and 20% responding to today’s.
What’s one line that works when asking the board or CFO for a budget?
I’m not asking you to fund cybersecurity; I’m asking you to protect the business strategy you’ve already approved. That changes the conversation from cost to business enablement.
What should a CISO cut from their program tomorrow with zero regret?
Security theater. Anything that looks impressive but doesn’t measurably reduce risk or improve resilience. Examples include reports nobody reads, meetings without decisions, and controls that create more friction than value.
“If it only checks a box, cut it.”
What’s your 60-second test for whether a vendor pitch is worth your time?
I ask three questions:
What business problem do you solve?
Can you prove measurable outcomes? Give an example of how you turned things around for your customers?
Why are you different from the ten vendors I met this month?
If they answer with features instead of outcomes, the meeting is probably over.
“Features sell products. Outcomes earn meetings.”
What’s one meeting, report, or process you eliminated, and what replaced it?
I eliminated long weekly status meetings. We replaced them with a live dashboard and a 15-minute decision meeting. The goal isn’t to exchange information. The goal is to make decisions and have an action plan with outcomes.
In the first 10 minutes of an incident, what’s the one action teams most often skip?
Defining who’s making decisions. Everyone starts investigating. Very few establish clear incident command. Without decision ownership, technical excellence becomes organizational chaos.
What’s one question every CISO should ask their team this week?
“If you were attacking us tomorrow, where would you start?” It changes the conversation from compliance to adversarial thinking.
Alternative: “What are we doing today simply because we’ve always done it?”
What’s a phrase or framing you use to translate a technical risk for executives?
I rarely talk about vulnerabilities. I ask: “What happens to revenue, customers, operations, or reputation if this control fails?” Executives don’t invest in CVEs. They invest in protecting business outcomes. I frame it in business results, risks, and revenue.
What’s your best tip for surviving the CISO role in exactly five words?
“Build trust before a crisis happens.” Because that’s really the essence of the CISO role. Technology changes. Threats evolve. But the ability to build trust with executives, employees, customers, regulators, and your team is what ultimately determines your success.
More tips from the series:
CISO Tips: Andy Curtis on Turning Cybersecurity Into Business Risk Decisions
CISO Tips: Carlos García Batista on Turning Cybersecurity Into Operational Resilience
CISO Tips: Sergey Tairyan on Thinking Like an Attacker and Leading Through Cyber Risk
CISO Tips: Kristin Lowery on Turning Security Activity Into Measurable Risk Reduction


