# The CISO Burnout Crisis Has a Structural Cause. Better Perks Won't Fix It.


The average Chief Information Security Officer lasts about 18 to 26 months in the role before leaving — voluntarily or otherwise. Peer networks, executive coaching, and well-being stipends are the industry's current answer to that number. They are, to put it plainly, the wrong answer.


CISO fatigue is real. Ask anyone who's held the title for more than two years. But the framing of it as a wellness problem obscures what's actually happening: organizations have spent the last decade loading legal liability, regulatory exposure, board communication demands, and operational ownership onto a single role — then expressing concern when the person in that seat burns out or walks.


## How the Job Became Undoable


Go back a decade and the CISO was largely a technical role. You owned the security architecture, managed the SOC, and briefed the CTO. The board didn't know you existed unless something went catastrophically wrong.


That version of the job was stressful. The current version is a different animal.


Today's CISO is expected to speak fluent board-room, translate threat landscapes into business risk language for executives who don't want to hear the details, navigate an increasingly aggressive regulatory environment — GDPR, SEC disclosure rules, HIPAA enforcement, state-level privacy laws — and personally absorb accountability when a breach happens on their watch.


The SEC's 2024 enforcement action against SolarWinds CISO Timothy Brown made this concrete in ways no amount of CISO survey data could. Brown faced personal civil charges related to disclosures around the Orion attack. The DOJ had already prosecuted Joe Sullivan at Uber for his role in handling a 2016 breach. Whether or not you think those prosecutions were fair, their effect on the community was immediate: CISOs are now hiring personal legal counsel before accepting job offers. That's not a sign of a wellness problem. That's a profession recalibrating around personal legal risk.


## The Proposals on the Table


The security industry has noticed the retention problem and is responding with a predictable toolkit: better compensation benchmarking, mental health resources, peer support networks, and executive burnout coaching. Some vendors are selling "CISO-as-a-service" fractional arrangements as a structural fix — let someone share the burden across multiple companies.


These are not worthless. Peer networks genuinely help. Knowing that other CISOs are dealing with the same impossible expectations is at minimum validating, and at best produces real tactical sharing. Fractional arrangements make sense for mid-market companies that can't justify or afford a full-time hire.


But none of these touch the core problem: the job's scope has expanded faster than its authority.


Most CISOs cannot approve significant security tooling purchases without jumping through a budget approval process that can take quarters. They often don't have direct control over cloud infrastructure, where the majority of modern attack surface lives. They're accountable for third-party vendor risk, but vendor selection is owned by procurement or business units. They're expected to brief the board, but they frequently don't have a board seat or even direct board access — they brief through the CIO or CFO.


You cannot fix the accountability-authority gap with a meditation app.


## What the Churn Is Costing


When a CISO leaves — under burnout, under pressure, or voluntarily for somewhere quieter — they take institutional knowledge with them. They take understanding of the specific threat environment the organization faces, the internal relationships that made security programs actually work, and the hard-won political capital to push back on risky decisions.


Their replacement, if the organization fills the role quickly, starts from scratch on all of it. Industry estimates put security program setbacks at 6-18 months when CISO turnover happens mid-initiative. In practice, attackers don't pause during leadership transitions.


The high-profile breach pattern bears this out. Several major incidents over the past few years occurred at companies that had recently experienced CISO transitions, or where the security leadership had been reorganized or reduced. This is not coincidence. It's the predictable outcome of a talent pipeline that runs hot until it doesn't.


## What Would Actually Help


The organizations genuinely serious about this — and some exist — aren't focused on perks. They're rethinking the structural conditions that make the role unsustainable.


That means:

  • Real board access, not CIO-filtered briefings. If the CISO is accountable for enterprise risk, they need a direct channel to the board's audit or risk committee.
  • Authority that matches accountability. If the CISO owns the security outcome, they need approval authority over the decisions that drive that outcome — cloud architecture, vendor onboarding, product security gates.
  • Legal clarity on personal liability. Companies are starting to include indemnification provisions in CISO contracts. This is appropriate. Personal liability for good-faith security decisions made with incomplete information should not fall on the individual.
  • Headcount that reflects the scope. The CISO who owns 15 different functions with a team of 8 is going to fail regardless of how resilient they are personally.

  • ---


    ## HackWire Analysis


    The wellness framing of CISO fatigue is not accidental — it shifts the conversation away from organizational accountability and toward individual resilience. If burnout is a personal problem, the fix is personal: coaching, sabbaticals, peer support. If burnout is a structural problem, the fix requires the C-suite and board to give up something — control, budget, single points of accountability.


    Most organizations prefer the former framing because the latter costs something.


    What's being underreported in the "fix CISO fatigue" conversation is the legal liability dimension and its downstream effects. When CISOs started watching peers get personally prosecuted and SEC-sanctioned, the calculus on career risk changed. The most experienced practitioners — the ones who've been through incidents, who've built programs from scratch, who know where the bodies are buried — are increasingly selective about which organizations they'll work for. They're asking about board access in interviews. They're asking about indemnification. They're asking about reporting lines.


    Organizations that can't answer those questions well are going to lose talent to ones that can. The CISO labor market is segmenting: companies with mature security governance are pulling the best people, and companies still treating security leadership as a compliance checkbox are getting the rest.


    The downstream risk of that segmentation is a widening gap between organizations that are genuinely hardening and those running on hope and junior staff. That gap is what threat actors exploit. The burnout conversation, at its most important, is really a conversation about which organizations are going to be in breach headlines three years from now.


    The answer to "is there really a fix for CISO fatigue?" is yes — but it requires organizations to accept that the problem is theirs, not their security leaders'.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)