HomeSecurityThe biggest risk for CISOs? The resignation of department heads

The biggest risk for CISOs? The resignation of department heads

It’s a familiar pattern: too much work and not enough reward and recognition. While CISOs have seen their role take on more importance and responsibility, the same is not true for operational security leaders, who are being asked to do more without reaping the rewards.

See also: CISO: New tools for MCP server security

CISOs

It’s no wonder this leads to increased dissatisfaction with career progression and a greater willingness to leave. For CISOs, this poses a serious risk: when mid-level security managers feel overwhelmed and unrecognized, the impact can undermine resilience, continuity, and innovation. At a time when cyberattacks are becoming increasingly complex and difficult to counter, CISOs cannot afford to lose experienced operational executives.

The issue is compounded by the broadening attack surface with cloud, SaaS and artificial intelligence, which leave operational cybersecurity leaders responsible for risks to third-party dependencies they cannot fully control. “Add to that the 24/7 nature of work and hybrid environments, and it’s no surprise that burnout is escalating.”

Security leaders operate under an unsustainable premise. “We expect our leaders to be right every time, while the attacker only needs to get it right once. This creates a culture of hypervigilance that simply cannot be sustained 24/7/365.”

See also: CISO guide to supply chain attacks using AI

The biggest risk for CISOs? The resignation of department heads

Teams are expected to be on call on weekends and holidays, often without pay, and because a major incident can require a four- to six-week response, personal lives are put on hold. And CISOs are constantly asking their leaders to do more with less.

“With cybersecurity still widely viewed as a cost center rather than a driver of business value, budgets are the first to be cut while the threat landscape expands exponentially,” he says. “This puts managers in an impossible position: being responsible for enterprise-wide risk mitigation without the necessary funding for tools or staff.”

See also: The 10 biggest problems facing CISOs today

EDR

There are steps CISOs can and should take to prevent attrition. The issue is to prioritize people. CISOs need to ask themselves whether functional security leaders are taking on too many roles with too little opportunity for advancement, and whether they are doing enough to support and retain them in the organization. They should also have clear career paths that include promotion criteria and “sponsorship — not mentorship — at the top management level, with visibility and opportunities to be on the board.”

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS