Yes. In 2024, CISOs faced several pressures at once: persistent threats, expanding executive responsibilities, greater regulatory scrutiny and possible personal legal exposure—often without matching budget, staffing or authority. This is a retrospective on the conditions described for 2024, not a claim that every CISO or organization experienced them equally.
Why was 2024 a difficult year for CISOs?
The CISO’s job was no longer just to prevent intrusions or manage security tools. Security leaders were increasingly expected to help keep the business operating through an incident, explain cyber risk to directors and investors, support regulatory compliance, and weigh security implications of rapid cloud and AI adoption. Those duties arrived alongside persistent attacks and pressure to do more with limited resources.
Threat pressure included cybercrime-as-a-service, ransomware and destructive wipers, geopolitical advanced persistent threats, and AI-assisted attacks. Another concern was “harvest now, decrypt later”: an attacker collects encrypted data today in the hope of decrypting it when future technology makes that feasible. These are different threat paths, but all demand preparation beyond a narrow perimeter-defense mindset.
That combination made the year feel “dire” for many security leaders: their accountability grew faster than their direct control over investment, staffing and business decisions. It does not mean that every organization suffered a material incident or that every CISO faced the same legal or operational risk.
#1 Best Overall
How is the CISO role changing?
Cybersecurity decisions increasingly affect business continuity, privacy, compliance, technology strategy and the use of AI. A CISO therefore needs to translate technical exposures into business consequences: what could stop operating, what information or obligations are at stake, how quickly the organization could recover, and what residual risk leadership is willing to accept.
The right leadership structure depends partly on organizational size and complexity. Smaller organizations may combine CISO duties with a CIO or CTO role; larger organizations generally need distinct leaders so that security oversight does not disappear inside technology delivery. Combining roles can simplify coordination, but it can also create competing priorities when the same leader is responsible for both enabling systems and challenging their risk.
| Operating model | Where it may fit | Key trade-off |
|---|---|---|
| Combined CISO and CIO/CTO responsibilities | Smaller or less complex organizations that cannot support multiple executive roles | Fewer leadership handoffs, but security decisions compete with delivery and operational responsibilities. |
| Separate CISO and CIO/CTO roles | Larger organizations with broader systems, business units or oversight needs | Clearer separation of security oversight from technology delivery, but it requires defined decision rights and coordination. |
Whatever the reporting structure, the CISO needs access to decision-makers and a clear route to raise material risks. The title alone does not provide authority: boards and executives determine budgets, staffing, risk appetite and whether recommended controls are implemented.
What does the SEC’s four-business-day cyber rule mean?
The SEC’s July 26, 2023 release describes a Form 8-K requirement for public companies: generally, a registrant must disclose a cybersecurity incident on Item 1.05 within four business days after it determines that the incident is material. The clock is tied to the company’s materiality determination—not simply to discovering an incident. The rule includes a narrow mechanism to delay disclosure when the U.S. Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsThe rule also adds annual Form 10-K disclosures about the company’s processes for assessing and managing cyber risk, material effects of risks, board oversight, and management’s role and expertise. It is therefore not only an incident-timing requirement; it also asks public companies to describe how cyber risk is governed.
SEC Chair Gary Gensler framed materiality in business terms: “Whether a company loses a factory in a fire — or millions of files in a cybersecurity incident — it may be material to investors.” A cyber event is not automatically material because it is technically serious, nor immaterial because it has not caused a public outage. The issuer must assess its actual and reasonably foreseeable effects in context. The disclosure decision belongs to the company; the CISO should help ensure that incident facts, impact assessments and escalation paths reach the people making it in time.
Can a CISO be held personally liable for a breach?
Personal liability is a contested concern, not an automatic consequence of a breach. A cyber incident by itself does not establish that an individual CISO committed a crime or is civilly liable. Exposure depends on the facts, the person’s role and conduct, applicable law, and what the organization represented or disclosed.
Practitioners quoted in SecurityWeek’s March 7, 2024 Cyber Insights article disagreed about the likely effect of increased accountability. Charles Blauner, CISO in Residence at Team8 and former CISO at Citi, described the role as potentially involving personal criminal or civil liability. Others argued that boards and executives control funding and risk acceptance, so responsibility should not automatically be assigned to the CISO when those leaders choose not to act on advice or resource controls. A counterargument is that accountability can encourage stronger management support and more disciplined disclosure.
The practical distinction is between responsibility to advise and authority to decide. CISOs should give decision-makers accurate, timely assessments and document recommendations and responses; boards and executives should make risk-acceptance decisions explicitly. Documentation does not guarantee protection from liability, but it can clarify what was known, who had authority, and how the organization responded. Legal advice and insurance terms are situation-specific; coverage varies and should not be assumed.
Rank #4
Why is CISO burnout a structural problem?
Burnout is not simply an individual’s failure to cope. Constant incident response, expanding attack surfaces, legal and disclosure pressure, limited staffing, inadequate budgets, and rapid deployment of cloud and AI systems can combine into a sustained workload. Emily Heath described CISO burnout as “a huge problem.”
The Chartered Institute of Information Security’s 2022/23 report records that 22% of professionals worked more than 48 hours per week and 8% worked more than 55 hours per week. These figures describe the report’s surveyed professionals and period; they should not be read as a measurement of every CISO or every country. SecurityWeek also reports the 55-hour threshold as the World Health Organization’s boundary between safe and unsafe working hours.
More hours do not necessarily mean greater resilience. If a security program relies on repeated firefighting and individual availability, it can leave critical work—such as recovery planning, control improvements and succession coverage—under-resourced. Andrew Shikiar, executive director at FIDO, noted that CISOs are often overlooked or short on resources, funding and business support to implement change.
Recommended Free Tools
What should a board do to support its CISO?
Board support means making cyber risk a governed business decision rather than treating it as a technical issue delegated entirely to security staff. Andrew Bayers, director of threat intelligence at Resilience, describes cyber resilience as “being able to withstand the impact of an inevitable cyber incident without significant operational or material loss.” That definition shifts the goal from promising prevention to preparing for disruption and limiting its consequences.
- Set risk appetite. State which operational, financial, privacy and regulatory risks the organization will tolerate, and identify who can accept residual risk.
- Match resources to expectations. If leaders expect particular controls, response coverage or recovery times, provide the budget, staffing and authority needed to support them.
- Give the CISO board access. Make it possible to raise material risks directly and explain them in business terms, including likely operational impact and recovery needs.
- Clarify decision rights. Separate the CISO’s responsibility to assess and recommend from the executives’ and board’s authority to fund, prioritize or accept risk.
- Practice incident decisions. Establish escalation routes and rehearse who assesses materiality, coordinates response, and handles disclosure decisions under time pressure.
- Record decisions and residual risk. Document material recommendations, management responses, accepted risks and the owner of each decision.
- Plan for recovery, not just prevention. Test whether the organization can continue critical operations and restore them after an incident.
A board cannot remove cyber risk, but it can make responsibility and trade-offs explicit. That is essential when security leaders are expected to protect operations without independently controlling the resources or business choices that determine the organization’s exposure.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

