CISO Burnout: When Accountability Outweighs Authority
Chief Information Security Officers are increasingly reporting burnout, and a key driver appears to be a mismatch between accountability and authority. CISOs are often held responsible when breaches or security failures occur, yet they frequently lack the organisational power to enforce the changes needed to prevent those failures in the first place.
This dynamic puts security leaders in a difficult position: they are expected to protect the business, but decisions about budget, staffing, and risk tolerance often sit with other executives or the board. Over time, this gap between responsibility and control can wear down even experienced professionals, contributing to high turnover in security leadership roles.
For small and medium businesses, this trend is worth watching even if you don't have a dedicated CISO. It's a reminder that whoever manages cybersecurity in your organisation — whether an IT manager, an outsourced provider, or an owner wearing multiple hats — needs genuine backing from leadership to make and enforce security decisions, not just the blame when something goes wrong.