There’s a significant discrepancy between the length of time that CISOs remain at a company when compared with other C-Suite employees. In this article, we’ll dive into the ket causes that drive this disparity.
The average CISO will hold their position for 39 months (Hitch Partners’ 2025 CISO Security Leadership Survey), compared to CFOs who will, on average, keep their seats for 6.1 years (Russell Reynolds’ 2025 Global CFO Turnover Index). That discrepancy raises the question, what is it that’s cutting the lifespan of the CISO role short? Several trends emerged from the conversations that I’ve had with CISOs this year.
The first concerning trend that has emerged from these conversations is the “resume generating event”. This is the big breach that gets pinned on the CISO (whether warranted or not), sometimes with SEC enforcement looming. This is often a key driver of burnout and feeling overworked.
Finding yourself with a target on your back or getting crushed under the constant pressure of stress and responsibility, alongside lost family time, missing weekends, and looming deadlines is the perfect environment for an unsustainable job role.
Over the course of the Expert Insights’ Q&A series, CISOs have not shied away from sharing their experiences, and their advice.
The Resume-Generating Event
The personal liability of holding the CISO suddenly became a lot more intense in 2023, when the SEC filed charges against not only SolarWinds, but also its CISO Timothy Brown. This had a profound impact on the profession, even though the charges against Brown were dismissed with in November 2025. For the first time, a CISO was personally responsible for events affecting their organization.
Even with the impact this case has on CISOs understanding of their personal risk and liability, many of them are still not well protected. Proofpoint’s 2025 Voice of the CISO report shows that 35% of CISOs globally have not reported any steps taken to protect them from personal liability. In a study by RSAC they found that 12% of Fortune 1000 CISOs were not indemnified by their companies for security breaches, and for smaller organisations (500+ employees) that number jumps to 47%.
This lack of protection is a key factor in why people are leaving the profession. Jeremy Powell, CISO at Sumo Logic, explored this matter in our interview. He asserts that CISOs aren’t burning out due to their own weakness, but due to a structural mismatch that sets them up to fail.
“If you’re going to make the CISO responsible for something,” Powell told me, “and something happens and it becomes a resume-generating event, then you have to have an accountability trail all the way through. And you need real visibility into it.”
Powell’s practical advice for CISOs considering a new seat is to understand with precision. “Get clarity on your mandate, your authority, and the organization’s risk tolerance. Get it all in writing before you take the seat. Don’t sign up for anything you don’t know about.”
For John J. Masserini, now CISO and Founder of SentiCon Security, the shift that came as a result of SolarWinds incident was easy to follow. “CISOs are finally negotiating for the same protections other executives have always had,” he told me. “Directors and officers insurance and formal indemnification are now things people ask for before they sign an offer letter, not after something goes wrong.”
The good news is that the industry appears to be moving in the right direction to improve this issue. Fastly’s 2025 research shows that 93% of organizations are taking active steps to reduce liability risk for CISOs. As to whether these kinds of efforts will translate into real alignment between accountability and authority, only time will tell.
The Lifestyle That Pays The Bills
The second exit is less dramatic but could account for a more significant number of professionals leaving the industry. Burnout is slower and less obvious, but remains a common complaint amongst CISOs.
In Proofpoint’s report, 63% of cybersecurity leaders claimed to have personal experience of either feeling or witnessing burnout in the past year. Sophos’ report puts the number of respondents experiencing cyber fatigue or burnout (either constantly, frequently, or occasionally) over the past year at 76%. The findings of the Devo Cybersecurity Burnout Survey were that 83% of security professionals blamed burnout for errors in their department that led to breaches, while 85% anticipate leaving their role due to burnout.
Burnout doesn’t just come from the pressure in the role, it can also come from how that role affects your personal life. Masserini is candid about the personal cost, explaining: “I’ve always said, ‘I don’t have a career, I have a lifestyle that pays the bills,’ and I meant it. My wife and kids can all share stories of lost weekends, 2 a.m. conference calls, and missed school functions and family gatherings.”
Rinki Sethi, Chief Security and Strategy Officer at Upwind Security and a four-time CISO across Rubrik, Twitter, BILL, and now Upwind, talked to me about the structural causes of the burnout. “The CISO has become a dumping ground for all the things that don’t fit anywhere else in the company, whether that’s privacy engineering, trust, or data governance,” she told me. “That’s also why there’s so much burnout happening.”
According to Steve Cairns, fractional CIO, CTO, and CISO at Freeman Clarke, the role “carries a huge amount of responsibility, protecting an organization’s data, reputation, and often its very survival.” The personal pressure, he told me, can be brutal.
All three CISOs I spoke to are seeing widespread burnout and personal cost across the profession, with CISOs leaving their roles at a rate notably faster than other similar roles in the C-Suite. If this issue isn’t addressed, we’re likely to see concerning gaps in many organizations’ security posture.
What Senior CISOs Are Doing About It
The CISOs I spoke to all have a wealth of experience to draw from. So, if you are entering into a CISO seat and want to be well prepared for what may come, consider these security leaders’ advice:
- Get the mandate in writing before you take the seat – Powell’s advice is straightforward. “Get clarity on your mandate, your authority, and the organization’s risk tolerance. Get it all in writing before you take the seat. Don’t sign up for anything you don’t know about.”
- Negotiate D&O and indemnification upfront – Masserini is direct that this now happens at offer stage, not after an incident. Given how many CISOs aren’t covered by their organization’s D&O policy, the need for negotiation is real.
- Recognise the warning signs before you sign – Masserini offers a clear red flag: if three people have held the seat in the last five years, “that tells you something the job description won’t.”
- Delegate operationally – Cairns is emphatic that the CISO role can’t be run solo. “Responsibility should be shared and delegated into the technology teams. If you work with a managed service provider, part of their job is patching, reporting, and flagging anomalies. Again, taking pressure off the CISO.”
- Reframe the role rather than fight it – Sethi advises that rather than resisting the “dumping ground” expansion, we should name it. “Let’s turn that page. Let’s say, yes, the CISO owns everything, because they are the trust builder with the consumer at the end of the day.” Reframing gives the expansion a purpose instead of leaving it as an accumulation.
- Build the peer network before you need it – Matthew Rosenquist, who built Intel’s first Security Operations Center and now sits on 16 advisory boards, was strong on this stance in his interview. “We have to communicate and collaborate with others. It’s not negotiable. We have to share and learn to avoid the pitfalls that other people have experienced.”
For any CISOs reading this list, these are the insights you should absorb before taking on the CISO seat, to give yourself the very best chance of surviving it. If you’re an executive who employs a CISO, the above advice could be the difference between keeping them in that seat and rehiring for it three times in five years.
Read the full interviews quoted in this article: Jeremy Powell, John J. Masserini, Rinki Sethi, Steve Cairns, and Matthew Rosenquist.