Governing Body Spotlight

Spotlight on Miro Zgavc

Governing Body Member of the Toronto CISO Community

Miro Zgavc

CISO

HomeEquity Bank

Miro has spent over 20 years in technology, more than 10 of them in cybersecurity. He's driven by a simple habit: wanting to understand exactly how things work, sometimes to the point of obsession, and that habit has shaped most of his career.

He's always played defense, from football growing up to cyber today. It's a mindset that runs in the family too, with a background in both law enforcement and computers making cybersecurity feel like a natural fit rather than a career choice. That combination still defines how he approaches the work: methodical, protective, and always asking how something could break.

Learn more about the Toronto CISO community here.
 

Give us a brief overview of the path that led to your current role.

I started in IT support, where I learned that turning it off and on again works about 60 percent of the time, and nobody reads the email explaining how to avoid the problem they just called about. That trial by fire led me to a systems administrator role, where I went from fixing one person's printer to being blamed for the entire network, and developed a deep, personal hatred for sticky notes with passwords on them.

Naturally, that made cybersecurity feel like home. As a security analyst, I spent my days chasing phishing emails and explaining to executives why "Password123!" isn't a strong password, which turned out to be excellent training for doing the same thing later with a bigger title and bigger risks.

That's exactly what happened in security leadership, where I traded alerts for meetings and learned to speak a language executives actually understood: risk. Turns out nobody cares about your firewall rules, but everybody cares about what happens to the business if they fail. And, learning to frame it that way is what really moved me from "the security guy" to someone leadership trusted in the room.

Twenty years after my first ticket about someone's mouse not working, I'm now CISO, proof that if you're paranoid enough for long enough, and you learn to talk risk instead of tech, someone eventually pays you for it.
 

What is one of your guiding leadership principles?

I see the role of CISO as being in service of the enterprise. Security isn't something to enforce from a distance, it's something to build alongside the people doing the work. That belief shapes how I lead: by example first.

If I expect diligence, I show up diligently. If I expect calm under pressure, I stay calm under pressure. 

Leadership, to me, isn't a title you hold, the actions you perform every day in full view of the people counting on you, and the accountability expected from a CISO.
 

What is the greatest challenge CISOs face today, and how are you addressing it?

One of the hardest challenges for a medium-sized business is staying agile while still growing up as an organization. Governance exists for good reason, but too much of it too early can quietly kill the exploration and ingenuity that got the business moving in the first place. The real work isn't choosing between control and creativity; it's finding where the two can coexist.
 

What is the key to success for someone just starting out as a CISO?

Listening. Above everything else, listening. When you step into a C-level role, it's tempting to lead with answers, but the real key is hearing what people are actually saying and taking a moment to see it through their eyes. That shift, from being heard to truly understanding, is what wins hearts, not titles or authority. People don't follow you because of the seat you sit in. They follow you because they trust that you actually get where they're coming from.

Being okay with living in the grey matters just as much. You don't always have to have the answer right away, and pretending otherwise does more harm than good. Some of the best decisions come from sitting with uncertainty long enough to actually understand the problem, rather than rushing to fill the silence with a confident answer that turns out to be wrong.
 

How do you measure success as a leader?

Success for a CISO isn't just measured in incidents avoided, it shows up in the day to day: fewer surprises, a steady message, and a team that anticipates before being told. Those three things, in a lot of ways, are the real scorecard.

Fewer surprises come from visibility, from actually knowing what's happening across the business instead of hoping nothing's wrong. A steady message builds trust over time, people believe what security tells them, good news or bad, because the tone never swings with the moment. And a team that anticipates is the clearest sign a program has matured past reacting.
 

What is the value of being a member of Gartner C-level Communities?

The real value is connection, getting in a room with peers who are dealing with the same pressures you are, without the need to perform or oversell. It's a place to trade ideas, swap war stories, and be honest about what's actually happening in cybersecurity -- the wins, the near misses, and the mistakes that taught you the most. There's something valuable about talking to people who get it without a long explanation first. Those conversations, more than any report or framework, are often where the best thinking happens.

 


Governing Body members share their insights and leadership perspectives to shape the agendas and topics that address the top priorities impacting business leaders today.