# The CISO Sits at the Table. Nobody Told Them What Game Is Being Played.
Security leaders have shorter tenures than almost anyone else in the C-suite. The reason isn't that they're bad at security. It's that they were hired for security and graded on something else entirely.
This isn't a new observation, but the gap has widened to the point where it's actively breaking careers and organizations alike. The technical leader who spent three years hardening infrastructure, reducing mean time to detect, and passing every audit walks into a board meeting and gets one question: *Why are we spending this much?* They don't have a good answer — not because they've been negligent, but because they've been solving a different problem than the one the board was measuring.
## The Measurement Problem Has a Body Count
For most of the past two decades, CISO success was defined as the absence of disaster. Nothing went wrong. The audit passed. The vulnerability count trended down. The pen test found nothing critical.
That's an impossible job to do well and an invisible job to do right. A surgeon whose patient survives gets credit. A CISO whose company doesn't get breached gets asked why they need next year's budget.
The enterprise buyer research makes this tension concrete: in a 2026 McKinsey survey of more than 3,000 enterprise technology buyers, data privacy and compliance ranked as the single most important purchase criterion — ahead of price, features, and reliability. Security was also the top reason buyers walked away from vendors in the past year.
The market has decided that security is a business driver. The internal org structure at most companies hasn't caught up. Security is still running the same playbook that made sense when the threat model was "keep attackers out" rather than "prove to customers that you're safe to do business with."
## What Gets a CISO Hired vs. What Gets Them Fired
Recruiters evaluate security leaders on technical depth, incident response chops, and organizational experience. Boards evaluate them on cost efficiency, customer trust, and how quickly the security function can stop blocking the roadmap.
These aren't the same job.
The CISO who built their career protecting infrastructure is fluent in threats. They can talk about CVEs, kill chains, and detection coverage with precision. Their board is fluent in revenue, growth, and deal velocity. When budget season arrives, those two languages don't translate — and the CISO who can't cross the gap gets treated as necessary overhead, not strategic leadership.
The CEOs and boards asking hard questions about security ROI aren't being hostile. Enterprise buyers have watched vendors with weak security turn into their own breach incidents. The question "how does our security posture help us win deals?" isn't philosophical anymore. It's operational.
## Compliance Theater Is Making Things Worse
Seventy-two percent of executives in PwC's 2025 global compliance survey said rising compliance complexity had hurt their company's profitability. That number should stop anyone cold.
The compliance treadmill has created a class of security programs that are impressive on paper and brittle in practice. Evidence gets collected once a year. The same controls get documented in six different formats for six different customer questionnaires. Audits get passed. And then a customer's security team asks whether a specific control is working *right now* — and the honest answer is "we checked in January."
That hesitation stalls deals. It creates uncertainty that multiplies across the sales pipeline. And it happens because the program was designed to survive an audit, not to demonstrate continuous, verifiable security.
A clean dashboard from last quarter tells you a control worked on the day someone looked at it. It says nothing about today.
## The Shift That's Actually Happening
The security leaders navigating this well aren't doing anything exotic. They're doing three things differently.
They connected security output to revenue. When they can show that a customer passed security review because of a specific control set, or that a deal closed faster because the company could answer a security questionnaire in hours instead of weeks, security becomes part of the revenue story. That's the frame boards understand.
They made trust legible in real time. Rather than pointing to an annual audit, they built continuous monitoring into something customers and executives could actually see. Shared compliance evidence, real-time dashboards, customer-facing security documentation — the goal is reducing the gap between "we're secure" and "here's proof."
They stopped treating every compliance requirement as a separate project. The organizations doing this intelligently are mapping their controls to multiple frameworks at once, so that the evidence they've already collected answers multiple questionnaires. Less overhead, more coverage, faster response to customer requests.
None of this is revolutionary. But it requires a CISO who thinks like a revenue partner, not just a risk manager.
## Who Owns This Problem?
It would be easy to put this entirely on CISOs to evolve. That framing misses half the issue.
Organizations hire technical security leaders, give them technical mandates, measure them on technical outputs for years, and then suddenly expect them to speak fluent CFO. That's an organizational failure, not an individual one.
The companies that have solved this tend to have two things in common: a CEO who asks the right questions (not "how many alerts did we close?" but "how does security help us grow?"), and a board that has at least one member with enough security literacy to translate between the two worlds.
When that's missing, the CISO is stuck performing for an audience that doesn't understand the show.
## HackWire Analysis
The framing here — that CISOs are hired for technical skills and graded on business outcomes — is accurate but undersells the structural trap these leaders are in.
What's worth noting is the timing. The McKinsey data that buyers now name security as their top switching criterion isn't hypothetical future pressure — it's already reshaping procurement. Large enterprise software vendors are watching deals stall not because of price or features, but because they can't answer security questionnaires convincingly. That's a material revenue event, and it's happening right now.
The pattern that prior incidents confirm: when external pressure finally forces a business function to justify itself in revenue terms, the leaders who survive aren't always the most technically excellent — they're the ones who learned the business language. We saw this with IT after the cloud transition, with data science after the analytics hype cycle cooled. Security is in the same transition, just with higher stakes because the cost of being wrong isn't a bad quarter — it's a breach that ends up on the front page.
The angle that's missing from most coverage of this issue: the compliance complexity problem is being driven partly by the proliferation of frameworks that companies feel obligated to pursue simultaneously — SOC 2, ISO 27001, FedRAMP, NIST CSF, HIPAA, and whatever a customer's specific questionnaire requires. Until the industry converges on shared evidence standards that travel across frameworks, security teams will keep doing duplicate work that satisfies auditors and frustrates everyone else. The CISO's language problem and the compliance overhead problem are the same problem: security was designed as a closed system, and the business now needs it to be open.
Defenders in organizations with a CISO should be pushing for one concrete metric change: ask leadership to track how many deals included a security review, how long those reviews took, and whether security posture was cited in won or lost deals. That data, run for one quarter, changes the conversation.
— HackWire Editorial
## Related Coverage