Back to Home

The B5
Future CISO Programme

A five year graduate pathway into cyber security leadership. You will work directly alongside a sitting vCISO on real client engagements from month one, in a dual CISO arrangement that hands over increasing responsibility as you build it, backed by a structured route through CISSP, CISM, CRISC, EC-Council CCISO and AI security training.

5
Years of structured training and real client work
5
Industry credentials built into the pathway
1
Dedicated mentor from B5's security leadership
1
Outcome, your own clients and your own team

Built for Graduates
Who Were Not Given a Graduate Scheme

Most cyber security graduate schemes sit you in a rotation and hope something sticks. This programme is different. From your first week, you are paired directly with senior security leadership at B5, and you work the same client engagements they do.

We call it a dual CISO arrangement because that is exactly what it is. You are not shadowing from the back of the room. You take on real client responsibility early, with the level of ownership increasing year on year, so that by year five you are not applying for your first security role elsewhere, you are stepping up to lead the clients you have already been serving, with five years of genuine, verifiable experience behind you.

Alongside the work, B5 Cyber supports you through a sequenced path of industry certifications, timed to match the experience you are actually earning, not bought in a single revision weekend.

Direct Mentorship

Paired with senior B5 security leadership on real client accounts from day one, not a rotation scheme.

Certifications, Timed to Fit

CISSP, CISM, CRISC and EC-Council CCISO each have genuine experience requirements. This programme is built to meet them honestly, with B5 supporting exam and training costs.

An AI Security Specialism

B5 is building its AI security practice now. You will train in AI governance and risk alongside traditional security leadership from year one.

The Five Year Pathway

Each year combines a defined client role, a certification milestone, and a measurable outcome. Certification timings below follow the real eligibility rules set by ISC2, ISACA and EC-Council, not a marketing version of them.

Year One, Foundations

Associate Security Consultant
  • Shadow live client risk assessments and vCISO engagements, learning B5 methodology, ISO 27001 and NIST CSF frameworks, and client reporting.
  • Certifications: ISC2 Certified in Cybersecurity (CC), and EC-Council AI Essentials (AIE) as your first AI security foundation.
  • Outcome: able to run a basic risk assessment under direct supervision and produce a first draft client report.

Year Two, Practitioner

Security Consultant
  • Begin owning sections of client engagements directly, with the dual CISO pairing moving from shadowing to co-delivery.
  • Certifications: sit the CISSP exam. With a degree, you need four years of qualifying experience rather than five, and you can sit the exam immediately, becoming an Associate of ISC2 while that experience builds. Also complete the ISC2 AI Security Certificate.
  • Outcome: lead a client risk assessment end to end, with your mentor reviewing before it goes to the client.

Year Three, Risk and Governance

Senior Security Consultant
  • Take named ownership of the risk register and control testing on at least one client account, reporting jointly with your mentor.
  • Certifications: sit the CRISC exam, drawing on real risk assessment and risk response work from this year's client accounts. Begin the Associate CCISO track, now available with CISSP in hand and growing management experience.
  • Outcome: present a risk update to a client stakeholder directly, with your mentor present as backup.

Year Four, Leadership

Dual CISO Partner
  • Co-lead vCISO engagements as an equal partner in client meetings, including board level reporting, with your mentor as escalation rather than lead.
  • Certifications: sit the CISM exam. By now you hold genuine information security management experience, which is the part of CISM that cannot be waived, so the certification reflects work you have actually done. Your CISSP converts from Associate to full CISSP once your four years of qualifying experience are confirmed.
  • Outcome: deliver a board level security update independently.

Year Five, Deputy CISO Readiness

Deputy vCISO
  • Take full named responsibility for at least one client relationship, with your mentor stepping back to a sign off and escalation role.
  • Certifications: complete the full EC-Council CCISO, which by this point you qualify for on genuine experience across its five domains. Your CISM is finalised on the same basis. Review ISC2's dedicated AI security certification, expected to formally launch around 2027, as your next step beyond this programme.
  • Outcome: continue as the named security lead for the clients you have built, with five stacked certifications and five years of verifiable experience behind every one of them.

Beyond Year Five, Build Your Own Practice

This programme is not built to produce people who leave once they are ready. The aim is for you to stay on as the named security lead for the clients you have built across your five years, taking the relationship forward rather than handing it to someone new.

From there, your responsibility grows in two directions. You take over additional existing client relationships as B5's senior leadership steps back to focus on new business and oversight, and you start winning and onboarding new vCISO engagements of your own.

To support that growing client book, you build your own team, bringing in the next cohort of Future CISO graduates and mentoring them the way you were mentored, running their dual CISO pairing and deciding when they are ready for real client responsibility. The programme is designed to repeat itself at every level, not to produce a single promotion and stop.

The Certifications You Will Earn

B5 Cyber supports the cost of exams and accredited training for every certification in the programme.

ISC2 CISSP

The benchmark security leadership credential. Sat in year two as an Associate of ISC2, confirmed in full once your four years of degree qualified experience are banked.

ISACA CISM

Focused on information security management. Built around genuine management experience earned through the dual CISO role, not a waiver alone.

ISACA CRISC

Risk and control expertise, drawn directly from the risk register ownership you take on in year three.

EC-Council CCISO

The executive level CISO credential. You progress through the Associate CCISO track from year three to the full CCISO in year five.

AI Security Training

EC-Council AI Essentials in year one and the ISC2 AI Security Certificate in year two, with ISC2's dedicated AI security certification as a year five and beyond target.

Framework Grounding

ISO 27001 and 27002, NIST CSF, NIST 800-82 and SOC 2 are taught through live client work throughout, not as a separate course.

Who We Are Looking For

This programme is for recent graduates, including those who have not yet found their first role. A background in computer science or security helps, but it is not required.

A UK degree, any discipline, awarded within the last two years, or due to complete this year.

Clear written and verbal communication, you will be client facing from year one.

Genuine interest in cyber security and a willingness to study for professional certifications alongside full time work.

Based in or able to work hybrid from the Surrey and South East England area.

Start Your Five Years
Toward Your Own Clients and Team

Send your CV and a short note on why cyber security, to the address below. Tell us which stage you are at, including if you have already graduated and are still looking for your first role.