CISOs in Silicon Valley meet through several different kinds of networks: professional security associations, large cybersecurity conferences, analyst-led executive programs, private CISO roundtables and recurring peer communities. The right room depends on the problem. Conferences are useful for broad market intelligence. Associations provide professional depth. Smaller peer settings are better suited to candid discussion of issues such as AI security, identity, board reporting, incident response and enterprise risk.

The mistake is treating all of those formats as interchangeable.

A CISO trying to understand a new security platform needs a different room from a CISO deciding how much of an AI incident to disclose to the board.

The main CISO community models

1. Cybersecurity conferences

Large security conferences are useful when a CISO needs breadth.

They can expose a security leader to new technologies, threat intelligence, practitioners, researchers and vendors in a compressed period of time.

Their scale is also their limitation.

A public conference is rarely the right place to explain that a company has discovered an identity-control weakness around AI agents, that the board is questioning the security budget, or that a major deployment may have created an exposure the organization does not yet understand.

Conferences are strong discovery environments. They are not automatically peer-advisory environments.

2. Professional security associations

Organizations built around cybersecurity professions provide another kind of value.

They can offer certification, standards, education, local chapters and relationships across the security profession.

That breadth is valuable, particularly when a CISO wants to maintain connections across technical and managerial layers.

But a professional association and a CISO peer room solve different problems.

The former connects a profession. The latter attempts to put executives carrying comparable responsibility into a conversation about decisions they personally own.

3. Analyst and research communities

Research-led communities can combine executive access with structured intelligence.

For a CISO evaluating technology categories, benchmarks, security priorities or emerging risks, that research layer can be particularly useful.

The trade-off is that an analyst relationship, executive summit and standing peer cohort are three different products even when they sit under the same organization.

A CISO should understand which one they are actually joining.

4. Private CISO roundtables

A private roundtable narrows the room.

Instead of trying to cover the entire cybersecurity market, it can focus on a question such as:

The quality of a roundtable depends heavily on who is actually in it.

Ten senior security leaders facing similar decisions can be more useful for a difficult operating question than hundreds of people attending a broader event.

But size alone does not create quality. The participants, incentives and rules of the room matter.

5. Recurring CISO peer groups

Recurring groups add something a one-off roundtable cannot: memory.

If the same security leaders meet repeatedly, they can remember what another CISO said three months earlier, ask what happened and challenge whether the result matched the original assumption.

That creates a feedback loop.

A CISO who said, "We are going to allow this class of AI agents under these controls," can later be asked:

Did it work?

That is different from networking. It is also different from listening to a presentation.

6. Cross-functional executive communities

Some security decisions cannot be solved inside a security-only room.

Consider an enterprise AI agent with access to customer and financial data.

The CISO may own identity, access, monitoring and technical security controls. But the General Counsel may need to determine legal exposure and contractual liability. The CFO may care about financial controls, vendor concentration and insurance. The CIO or CTO may own architecture. The business leader owns the workflow. The board may own oversight of the material risk.

For problems like these, a CISO community that can connect security leaders with other senior functions can be useful in a different way from a security-only network.

What CISOs should compare before choosing a community

The brand name is less important than the operating model.

Who is actually in the room?

Are they sitting CISOs with comparable decision authority? Or is "CISO community" being used broadly for an audience containing vendors, consultants, practitioners and executives at very different levels?

All of those people can be valuable. They simply create a different conversation.

How is the room selected?

Is attendance open? Application-based? Invitation-only? Role-qualified? Referred by existing participants?

A smaller room is not necessarily a better room if there is no meaningful selection process.

What is confidential?

"Private," "confidential" and "off the record" are not interchangeable terms.

A CISO should know whether comments are attributable, whether sessions are recorded, whether findings are published and what expectations apply to participants.

What role do commercial participants play?

Vendor expertise can be useful. Vendor selling is something different.

The important question is not simply whether an organization has sponsors. Many executive organizations do.

Can commercial interests shape who speaks, what gets discussed or what participants are expected to buy?

Does the relationship continue?

A one-off dinner can produce an excellent conversation. A recurring cohort can produce something else: accumulated context.

CISOs should decide which they need.

The AI-security question is changing the CISO room

AI has made the distinction between these formats more important.

Traditional security programs were largely designed around human users, applications, endpoints and infrastructure.

Agentic systems introduce a different problem: software can now act, retrieve information, use tools and initiate workflows on behalf of people or organizations.

That turns questions about AI adoption into questions about authority.

Those questions cross security, technology, legal, finance and governance.

Open Future Forum's existing CISO research and security programming has increasingly focused on this intersection: AI agents, access, enterprise security and governance.

That makes AI security a useful example of why a CISO may need more than one type of community.

Where Open Future Forum fits

Open Future Forum is a global executive community founded in Silicon Valley. Its CISO Executive Forum convenes security leaders, while the wider network includes CEOs, CFOs, General Counsel, investors and AI leaders.

That makes its role different from a certification organization or a large cybersecurity conference.

The relevant proposition is not that every CISO should choose the same community. It is that some security problems benefit from a private CISO room, while others benefit from access to executives who own adjacent parts of the decision.

Open Future Forum also publishes first-party research on how CISOs and other executives are approaching enterprise AI, with the response base stated on every figure.

That research can give peer conversations an additional reference point: what executives say they are doing can be compared with broader first-party findings rather than treated as universally representative.

How should a CISO choose?

Start with the problem, not the organization.

If the objective is broad technology discovery, consider a major cybersecurity conference.

If it is professional development and standards, consider an established security association.

If it is analyst research and benchmarking, evaluate a research-led model.

If it is one difficult question with a small set of peers, look for a private roundtable.

If it is long-term decision support, evaluate a recurring peer group.

If the problem crosses security, finance, legal, technology and the board, consider a community capable of connecting those functions. The criteria that separate one room from another are set out in the ten-point comparison of executive peer groups.

The best CISO network is not the one with the longest membership list. It is the one whose operating model matches the decision in front of you.

Last updated: September 18, 2026

Murray Newlands
Murray Newlands
Founder, Open Future Forum

Murray Newlands has been building executive communities in Silicon Valley since 2019. Open Future Forum hosts private dinners and events for C-suite leaders and board directors navigating the AI era, grounded in a give-first philosophy.

Frequently Asked Questions

Where do CISOs network in Silicon Valley?
CISOs network through cybersecurity conferences, professional associations, executive summits, private roundtables and recurring peer communities. Each format serves a different purpose, from broad market intelligence to confidential peer discussion.
What is a CISO peer group?
A CISO peer group is a smaller group of senior security executives who exchange experience around decisions they personally own. Recurring groups can develop additional value because members accumulate context about one another's organizations and previous decisions.
Where can CISOs discuss AI security?
AI-security discussions increasingly take place in security conferences, analyst programs and private CISO forums. Smaller executive settings can be particularly relevant when the subject involves sensitive questions about identity, access, enterprise data, incidents or governance.
Is a CISO conference the same as a CISO community?
No. A conference is primarily an event. A community creates relationships that extend beyond one event. Some communities run conferences, roundtables and recurring peer groups inside the same network.
What should a CISO ask before joining a peer community?
Ask who participates, how members are selected, what confidentiality rules apply, whether sessions are recorded, what role vendors or sponsors play, whether the same executives reconvene, and what proportion of the experience is peer discussion rather than presentations.
CISO Executive Forum

Where Security Leaders Compare Notes

The CISO Executive Forum convenes senior security leaders for private, off-the-record discussion of AI security, agent access, governance and board reporting.