Phil Venables
CISO (Goldman Sachs, Google Cloud)
Roles and dates
Compiled from the sources listed at the foot of this page. Where a date is unconfirmed in the public record, the entry says so.
- Information security managerBarclays1992–1995
- Global head of technology riskStandard Chartered1995–1996
- Chief Information Security Officer (London)Deutsche Bank1997–2000
- Partner and Chief Information Security OfficerGoldman Sachs2000–2017
- Partner and Chief Operational Risk OfficerGoldman Sachs2017–2018
- DirectorGoldman Sachs2018–2020
- Co-founder, later board memberCenter for Internet Security2000; board 2014–2020
- Co-founder and chairmanSheltered Harbor2015–2020
- Chair, cybersecurity committeeSIFMA2017–2020
- Chief Information Security OfficerGoogle CloudDecember 2020 – March 2025
- Strategic security advisorGoogle Cloud2025–
- Venture partnerBallistic Venturesannounced April 2025
Situation and mandate
FACT Venables took the security chair at Goldman Sachs in 2000 and held it until 2017, then moved to chief operational risk officer (2017–2018) and director (2018–2020) at the same firm [7][8]. In December 2020 he became the first Chief Information Security Officer of Google Cloud, a role he left in March 2025, staying on as a strategic security advisor and becoming a venture partner at Ballistic Ventures in April 2025 [3][4]. On leaving, he described "being a CISO for 30 years spanning 4 CISO roles at some of the world's largest organizations" [3].
Two mandates, both without a crisis. At Goldman: defend one of the most targeted institutions in the world under prudential regulation, with the internal standing of a partner — a structural position most CISOs never hold. At Google Cloud the mandate inverted: the customer, not the employer, was the party whose risk had to be governed, and the chair was partly a product function and partly a public one. Neither job was handed to him by a breach. INTERPRETATION That is how the record should be read: nothing in it was forced, and every decision below was taken in a period when the organization could have done less.
Documented decisions
1. He stayed. Seventeen years in one security chair, thirty across four, is the first documented decision, because every year of it was a choice not to take a different job [3][7]. He later made the reasoning explicit as one of three CISO 2.0 pillars: "CISOs need to be long-term players. We all know many of the security activities and risk mitigation activities that we have to drive are things that just take years — even though we wish they would take quarters" [2].
2. He converted the security role into a risk role rather than leaving it. After seventeen years as CISO he became Goldman's chief operational risk officer, then a director [7][8]. INTERPRETATION The move places information security inside enterprise operational risk rather than inside technology — a structural claim about where the discipline belongs, made by taking the job rather than by writing about it.
3. He built institutions outside his own firm. Co-founder of the Center for Internet Security in 2000 (board 2014–2020); co-founder and chairman of Sheltered Harbor (2015–2020); co-founder of FS-ARC (2016–2020); FSSCC board (2002–2020); chair of SIFMA's cybersecurity committee (2017–2020) [1]. Sheltered Harbor is a sector data-vaulting scheme — competing institutions agreeing to hold restorable copies of customer records. INTERPRETATION This is executive capacity spent on capability his employer could not own exclusively, on the theory that a bank's risk includes the state of the banks around it.
4. He took standing advisory positions in public bodies. NSA Science of Security distinguished expert (2012– ), the NIST Information Security and Privacy Advisory Board (2020– ), the President's Council of Advisors on Science and Technology, and participation in the 2016 Commission on Enhancing National Cybersecurity [1][8]. These seats consume executive time; taking them is a decision about where a security leader's leverage lies.
5. He accepted a customer-facing security chair. Moving to Google Cloud in December 2020 meant a job whose primary audience is the buyer, in which the Office of the CISO functions as an advisory and publishing organization rather than only an internal control function [2][3]. The security leader's output becomes partly a commercial artifact — a real change in the job, and one the course should name rather than admire.
6. He published his reasoning continuously and under his own name. philvenables.com carries a large body of first-person writing on risk, control design and board communication, alongside the Google Cloud "Cloud CISO Perspectives" series [1][2][5][6]. INTERPRETATION Publishing reasoning fixes a dated position that can later be checked against events.
7. He proposed a specific control-measurement mechanism. In "Control Reliability Engineering" (25 July 2026) he argues that breaches typically follow from broken or misconfigured controls rather than novel attacks, that "controls inevitably degrade unless that force is counteracted with disciplined systems," that Control SLIs and SLOs "provide an engineering-standard metric to judge if a control is reliable enough to meet the organization's risk tolerance," and that "by treating a Control Incident (a failed control) with the same gravity as a Security Incident, we force ourselves to remediate structural weaknesses before they become catastrophic" [5].
8. He named the information problem and prescribed a method. In "Do You Really Know What's Going On?" (16 May 2026) he describes a "thermocline of truth": "Organizations are full of cultural, structural, process, and other barriers that stop reality making its way to leadership," and prescribes direct observation — "One of the most important ways to know what is going on is to see for yourself" — rather than better reporting [6].
9. He defined the role in three parts and set a direction of travel. In the Google Cloud post of 20 November 2025 he set out CISO 2.0: CISOs "should realize they're peer business executives" who "lead and educate the business on what opportunities may come about"; they must be "a peer technology leader and have technical empathy," able to "work at a detailed level with the technology and engineering leaders"; and they must be long-term players. The direction of travel: "from a fire station, reacting to disasters, to a flywheel, self-sustaining and continuously enhancing the business" [2].
Reported results
FACT There are no measured outcomes in this record. That is the honest statement of it.
No major breach was publicly reported at Goldman Sachs during his tenure as CISO [8]. This is not evidence of effectiveness. Undetected and undisclosed incidents are unobservable from outside, and the absence of a public event is compatible with excellent security, unremarkable security and luck. Visibility ≠ prevalence; visibility ≠ effectiveness.
Sheltered Harbor exists as a functioning sector institution and the Center for Internet Security is a widely used source of benchmarks — organization-reported facts about the institutions, not measured effects of any one founder [1]. Google Cloud's Office of the CISO publishes on a regular cadence; the volume is verifiable, its effect on customer risk is not [2].
Industry recognition exists (FS-ISAC Critical Infrastructure Award 2017; ISACA Wasserman Award 2019; SINET Innovation Award 2019) [8]. Awards are not evidence, and are listed only so a reader who meets them elsewhere knows they have been considered and discounted.
What is contested or thinly documented
Nothing here is legally or ethically contested; no disputed incident handling or enforcement action appears in the sources reviewed [8]. The contest is evidential, on four points.
Attribution. Seventeen years of a bank's security posture is the product of thousands of people, a regulator, a budget cycle and a threat environment. No public source apportions any part of it to the CISO.
Channel. Much of the material runs through employer platforms — the Google Cloud blog is a company channel and the Office of the CISO is a commercial function [2] — and the rest is self-published [1][5][6]. None of it is independently audited, and the incentive to publish what is defensible rather than what is true is structural, not personal.
Selection. He is documentable partly because he wrote a great deal. A leader with an identical record who published nothing would not appear in this curriculum — the course's own selection bias, operating on the course.
Recency. The Control Reliability Engineering and thermocline posts date from 2026, after his last operating CISO role [5][6]: proposals from a practitioner-turned-advisor, not descriptions of a program he was then running.
What it teaches
Trait Dial (INTERPRETATION, inferred from the decisions above)
INTERPRETATION— all readings below are inferred from documented decisions, not from any assessment of the person.
Urgency ↔ patience: strongly toward patience. Decision 1 and the "long-term player" pillar are a stated preference for multi-year horizons over quarterly wins [2]. The evidence is the tenure itself, not the claim.
Hands-on ↔ delegation: strongly toward delegation, at the Architect end. Decisions 3 and 4 spend executive time on capability that lives outside the employer entirely. A leader who builds a sector vaulting scheme is not optimizing their own perimeter.
Unilateral ↔ consensus: toward consensus. Sector committees, standards boards and public advisory seats are consensus instruments by construction [1].
Innovation ↔ operational discipline: toward operational discipline. Control Reliability Engineering is a discipline mechanism — SLIs, SLOs and a Control Incident classification — built on the unglamorous claim that controls decay [5].
Decisiveness ↔ inquiry: toward inquiry, with a caveat. "See for yourself" is an inquiry instruction [6]; publishing a dated position is a decisiveness behavior. The pair is the point.
Overlays. On Control ↔ Enablement, toward enablement: the CISO who "leads and educates the business on what opportunities may come about" is describing enablement in a risk vocabulary [2]. On Prevention ↔ Resilience, CRE reads as prevention rebuilt on reliability engineering — not "stop everything" but "know which controls are currently working."
Maturity Model
FRAMEWORK The record illustrates Level 4 — Fit, unusually cleanly, because the same executive occupied two structurally different chairs and described how the job changed. At Goldman the CISO was an internal risk officer with partner standing inside a prudentially regulated firm; at Google Cloud, partly a product and public function inside a company selling to other people's CISOs. On Player → Coach → Architect the reading is Architect throughout, with decisions 3 and 4 past the Architect's usual boundary — governance built for a sector rather than a firm.
Fit
Reporting line. Partner status at Goldman is the extreme high-discretion case for a security chair: peer standing granted by the firm's own governance rather than by an org chart. Very few CISOs will have it, which limits what generalizes from the Goldman period. At Google Cloud the line ran inside a cloud business with an external audience — a different discretion problem, in which authority derives partly from customers.
Regulator. Bank prudential supervision plus sector self-regulation (FSSCC, SIFMA) at Goldman; at Google Cloud, largely the customer's regulator, arriving second-hand through assurance requirements.
Stage. Mature, well-capitalized, no burning platform, in both jobs — the "no crisis" comparator to the post-breach mandate, and the condition in which the long-horizon argument has to do all the work.
Information environment
The thermocline post is the clearest statement in either library of the security leader's central information problem: the barriers "that stop reality making its way to leadership" are structural, so the remedy is structural — direct observation, not a better dashboard [6]. Control Reliability Engineering instruments the same idea: a Control Incident surfaces a silent failure before an attacker does [5]. Together they say a program's health is measured by what it detects about itself.
Two-Sentence Test and the Risk Corollary
"We're going to do this" is here a decade-scale sentence: sector institutions and control programs that could not be validated inside one bonus cycle. The second sentence — "I was wrong. Change the plan." — appears in institutional rather than personal form: CRE's Control Incident is a standing admission that a control you certified has stopped working, made routine so that nobody has to be brave to raise it [5]. The Risk Corollary sits in the CISO 2.0 framing: a leader who "leads and educates the business on what opportunities may come about" must be able to say "Yes — and here is the risk we are accepting, priced," or forfeit the seat in the opportunity conversation [2].
Discussion questions
- The Goldman record rests on the absence of a public incident. Write two paragraphs: one arguing seventeen quiet years is meaningful evidence, one arguing it is none. Which was easier, and what does that say about how you evaluate your own program?
- Decisions 3 and 4 spend executive time on capability the employer cannot own. If you proposed the equivalent next quarter, what would you be asked to give up, and could you price the trade?
- CRE treats a failed control as an incident. What happens in your organization in the first month after you adopt that definition — and who resists, on what grounds?
- Name the last thing you learned about your estate by direct observation rather than by report. If you cannot, what does that imply?
- What is the shortest tenure in which the program you now run could be fairly judged — and does anyone above you agree with that number?
Sources
- Phil Venables, "About," philvenables.com — https://www.philvenables.com/about (primary; roles, board seats and dates)
- Google Cloud blog, "Cloud CISO Perspectives: Phil Venables on CISO 2.0 and the CISO factory," 20 November 2025 — https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-phil-venables-on-ciso-2-0-and-the-ciso-factory (primary, company channel; verified 2026)
- The Stack, "Google Cloud's Phil Venables hangs up his CISO spurs," 10 March 2025 — https://www.thestack.technology/google-clouds-phil-venables-hangs-up-his-ciso-spurs-tributes-flood-in/ (departure; December 2020 start; "30 years spanning 4 CISO roles")
- SecurityWeek, "Former Google Cloud CISO Phil Venables Joins Ballistic Ventures," April 2025 — https://www.securityweek.com/former-google-cloud-ciso-phil-venables-joins-ballistic-ventures/
- Phil Venables, "Control Reliability Engineering (CRE): Applying SRE Principles to Cybersecurity Controls," 25 July 2026 — https://www.philvenables.com/post/control-reliability-engineering-cre-applying-sre-principles-to-cybersecurity-controls (primary, self-published)
- Phil Venables, "Do You Really Know What's Going On?," 16 May 2026 — https://www.philvenables.com/post/do-you-really-know-what-s-going-on (primary, self-published)
- Wikipedia, "Phil Venables (computer scientist)" — https://en.wikipedia.org/wiki/Phil_Venables_(computer_scientist) (used only for role dates, cross-checked against [1], [3] and [8])
research/leaders-shortlist.md, §2.1 (compiled role history, recognition list, and the controversy review that found none) — internal research document
Numbered references match the bracketed markers in the text above. Links open the primary source where one exists; internal research files are named as such.