Trying to run an organization’s cybersecurity program single-handedly isn’t just tough, it’s impossible. It could even be a career mistake. One that puts your professional reputation and the safety of the company you work for at real risk.
Across nine interviews for Expert Insights’ Q&A series over the past year, three of these CISOs independently landed on the same phrase to describe what the role now requires: “cybersecurity is a team sport.”
These CISOs weren’t using the phrase as a metaphor, but as a description of how they’ve achieved their success. Cybersecurity, like team sport, it requires shared responsibility, cross-functional embedding, and peer networks.
CISOs still running the role solo are the ones burning out, getting fired, or leaving the profession.
The Message Is Clear
Steve Cairns, a fractional CIO, CTO, and CISO at Freeman Clarke, use the phrase when asked how he handles the personal pressure the CISO role involves. “The first thing I’d say is that cybersecurity is a team sport. It may feel like the head of IT or IT security carries the full load, but responsibility should be shared even at the top.”
Matthew Rosenquist, who built Intel’s first Security Operations Center and now serves as a virtual CISO across sixteen advisory boards, used the same phrase to describe how he believes the industry needs to operate. “Cybersecurity is absolutely a team sport. Not only within your organization and within your partner structure, but across the industry as well.”
Santosh Kamane, founder of Rivedix Technology Solutions and a former CISO across global enterprises in India and the US, closed his interview with the same line. “And remember, cybersecurity is a team sport. Build trust with IT, DevOps, legal, HR, and even marketing.”
Kamane put his own advice into practice during his Zero Trust rollout. His team embedded a security engineer inside each business unit for three months “to guide them hands-on.” According to him, “that reduced pushback and improved adaptation.”
For each of these security leaders, there is a recognition that cybersecurity is such a broad and evolving area that it is essential to bring people with you. That includes board members, people within your security team, and other employees. It’s only when everyone is pulling in the same direction that real change can happen. An executive decision to invest in cybersecurity is just as important as a contractor knowing how to deal with phishing emails.
The Structural Failure
Jeremy Powell, CISO at Sumo Logic, spent nearly three decades in engineering, product, and security leadership, most recently as CTO at LockThreat GRC and CISO at Zyston LLC and Verint. He also publishes on what he calls the “CISO Exodus”, where he argues that CISOs aren’t just burned out, they’re structurally set up to fail.
Powell highlights a gap between accountability and authority, with most CISOs feeling pressure and responsibility over areas that they are not set up to control.
“If you’re going to make the CISO responsible for something,” Powell said, “if something happens and it becomes a resume-generating event, then you have to have an accountability trail all the way through. And you need real visibility into it.”
He offers some clear advice to any CISO considering their role: “Get clarity on your mandate, your authority, and the organization’s risk tolerance. Get it all in writing before you take the seat. Don’t sign up for anything you don’t know about.”
Rinki Sethi, Chief Security and Strategy Officer at Upwind Security and a four-time CISO across Rubrik, Twitter, BILL, and now Upwind, describes the same failure mode from a different angle. “The CISO has become a dumping ground for all the things that don’t fit anywhere else in the company, whether that’s privacy engineering, trust, or data governance,” she told me.
“Let’s turn that page,” Sethi said. “Let’s say, yes, the CISO owns everything, because they are the trust builder with the consumer at the end of the day.” In other words: stop fighting the expansion. Reframe it. The CISO isn’t a collector of random work. They’re the trust builder, and everything they’ve been handed fits under that identity.
The scale and complexity of what CISOs are being asked to manage is what makes that structural mismatch so significant today. Identity, supply chain, AI agents, regulatory exposure: the categories of risk a CISO is now expected to track have multiplied.
When I asked Kamane about his daily challenges, the list was long: phishing attempts, social engineering, poor cyber hygiene, identity-driven and supply-chain-driven attacks, AI-generated phishing, and visibility gaps in hybrid environments. “Every day is a new challenge,” he said.
The Personal Cost
As well as the operational impact of this pressure and responsibility, there’s a personal cost that is often overlooked. For the CISOs themselves, it’s vital to find the balance between authority and responsibility. Yes, a CISO is a high-pressure, technically significant role. But it needs to be one where a CISO is able to succeed, make a difference, and protect their organization.
If the task feels insurmountable or the CISO is blamed for issues outside of their remit, they’ll likely walk away.
Sethi is direct about the scale of the problem. “There’s so much burnout happening. We talk about this a lot in the industry.” She ties it to the structural mismatch: CISOs are stuck being the dumping ground while lacking the mandate to properly manage what they’ve been given. That mismatch, over time, is what drives the exodus Powell writes about.
Cairns was the most explicit about the personal cost. He said the role “carries a huge amount of responsibility, protecting an organization’s data, reputation, and often its very survival,” and that the personal pressure can be brutal.
“With a strong peer network, clear delegation to technical teams, and a board that understands the risks, invests properly, and participates in things like tabletop exercises and playbook planning, the weight doesn’t fall solely on the shoulders of the CISO,” Cairns advised.
Rosenquist made the broader industry point most forcefully. “We have to communicate and collaborate with others. It’s not negotiable,” he said. “We have to share and learn to avoid the pitfalls that other people have experienced.”
“We didn’t share anything. I mean, nothing,” Rosenquist said of cybersecurity’s early days. Reflecting on that time when the role was far more isolated, Rosenquist made his position on the importance of the peer network very clear. It is now an essential part of the job description, one that stops the role from breaking the people in it.
It’s clear from the shared points that these CISO make, that cybersecurity cannot be left down to one person. It is a team sport, requiring talented individuals to perform at a high level, with the right tactics and strategies to succeed.
For CISOs Working In Tough Environments
Not every CISO has the ability to rebuild the role around themselves. Small companies, junior boards, no budget for peer networks; those are all real structural constraints.
Powell’s advice applies here more than anywhere else. If the structure isn’t there and can’t be built, even the most experienced CISOs will choose to walk away. Staying in a role where accountability doesn’t align with authority isn’t loyalty, it’s a professional risk you shouldn’t be carrying.
If your organization treats the CISO seat as a “dumping ground”, to use Sethi’s phrase, you have your answer. The environment isn’t going to change on its own, and the risk of staying is on you.
Actionable Advice For CISOs
If you’re still running the role as a solo function, here’s the practical checklist that emerges from the CISOs quoted here:
- Get it in writing before you take the seat – Mandate, authority, risk tolerance. Make sure they are all named explicitly. Don’t sign up for anything you don’t have a full understanding of (Powell).
- Delegate patching, reporting, and anomaly detection – Technology teams and managed service providers can own operational work that shouldn’t be sitting with the CISO (Cairns).
- Run tabletop exercises with the board – These are simulated incident scenarios where the board practices its role in the response, so that when a real breach occurs, they’ve already worked through the decisions (Cairns).
- Embed a security engineer inside each business unit for a fixed window – For rollouts like Zero Trust, move security into the team doing the work (Kamane).
- Translate technical findings into business impact – Avoid overusing technical language and instead think about how to phrase a concern in a way that makes sense to the business. Rather than sharing the CVE code, explain the projected revenue loss or damage that failing to deal with it could cause (Kamane).
- Build the peer network before you need it – Industry threat intel, war stories, and best practices are inputs the individual CISO doesn’t generate alone (Rosenquist).
- Reframe why you’re doing it – The CISO now owns everything the org can’t place elsewhere, from privacy to trust to data governance. Frame yourself as “the trust builder with the consumer,” and the expansion has a purpose (Sethi).
For more insights form industry experts, head over to our interviews section.