In cybersecurity, effective leadership requires more than deploying the right tools or responding quickly to incidents. It requires a mindset built around continuous learning, attacker thinking, and the ability to translate technical risk into business impact. Sergey Tairyan, Chief Information Security Officer at the Technology Management Center of Yerevan City and founder of OmniSec and Oky.ai, brings more than 15 years of experience building and transforming security programs across industries. His expertise spans security operations, SOC leadership, SIEM and DLP, IAM and PAM, endpoint protection, incident response, and emerging areas such as steganography and post-quantum cryptography.
Known for combining hands-on ethical hacking with long-term security strategy, Sergey approaches cybersecurity with a focus on reducing real-world risk while keeping organizations resilient and operational. His advice reflects that philosophy, from researching a vendor before buying its tools and measuring security decisions in business numbers to prioritizing daily learning and clear leadership during a crisis. In this edition of CISO Tips, Sergey shares the principles, habits, and practical approaches that shape how he thinks about security leadership in an increasingly complex threat landscape.
Complete this sentence: “Before you buy any new security tool, first...”
Before you buy any new security tool, first do OSINT on the company behind it.
What’s one rule you enforce on your team that other teams would find strict?
Two non-negotiable rules:
All team members must maintain 24/7/365 availability, including weekends, holidays, vacations, and days off.
Every team member spends one hour daily on learning and research.
In cybersecurity, threats don’t rest and neither does learning.
What’s a number or ratio that guides how you allocate budget, headcount, or your own time?
65% prevention, 15% detection and response, 20% innovation and research.
AI has shifted the balance toward innovation, but the ratio should continuously adapt to business risk, technology, and the evolving threat landscape.
What’s one line that works when asking the board or CFO for a budget?
The board and CFO understand numbers, not technical details. So, I don’t ask for a security budget; I present a business risk calculation, showing the potential financial impact of an incident, its likelihood, and the cost of reducing that risk.
What should a CISO cut from their program tomorrow with zero regret?
With AI and mature open-source solutions, many enterprise security tools (such as SIEM, security scanners, and password managers) can now be deployed faster, customized, and operated at a fraction of the cost.
What’s your 60-second test for whether a vendor pitch is worth your time?
I present the vendor with 2-3 real security challenges and watch how they respond.
I’m looking for honesty, technical depth, and a problem-solving mindset - not marketing. If they ask the right questions and acknowledge limitations, they’ve earned more of my time.
What’s one meeting, report, or process you eliminated, and what replaced it?
I eliminated meetings focused on what we did and replaced them with discussions on what we learned.
Instead of status updates, we focus on new threats, lessons learned, and opportunities to improve our security posture.
In the first 10 minutes of an incident, what’s the one action teams most often skip?
Teams often skip establishing clear leadership.
In a major cyber incident, the CISO becomes the incident commander, directing the CIO, CTO, and other teams to coordinate the response.
What’s one question every CISO should ask their team this week?
What else can we automate to improve our resilience?
What’s a phrase or framing you use to translate a technical risk for executives?
Let’s talk in numbers.
What’s your best tip for surviving the CISO role in exactly five words?
- Learn. Test. Hack. Repeat.
More tips from the series:


