The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
The “CISO carousel” is recurring turnover among chief information security officers. Its main cybersecurity risk is disruption: when leadership changes faster than security programs can mature, priorities, business knowledge, and accountability can be lost during the handoff.
Why do CISOs keep leaving?
SecurityWeek’s September 26, 2023 analysis groups the reasons into four broad themes. They can overlap, and not every departure reflects a failing security program.
Blame after a breach
After an incident, an organization may assign personal blame to the CISO even when the outcome also depended on decisions, resources, or legal constraints outside that executive’s control. The prospect of dismissal—or being dismissed—can make the role difficult to sustain.
Responsibility without enough authority
A CISO may be held responsible for security outcomes without sufficient budget, staff, access to decision-makers, or power to require changes across the business. Sounil Yu, CISO at JupiterOne, described this imbalance as “accountability without authority.”
#1 Best Overall
Stress and burnout
Incident pressure, long hours, concerns about personal liability, and the challenge of demonstrating success when nothing goes wrong can all weigh on security leaders. SecurityWeek cited a Salt Security survey in which 48% of CISOs identified personal litigation as their top personal stressor and 1% reported no personal challenges. The article did not state the survey’s year or methodology, so these are secondary figures rather than a fully contextualized measure of CISO experience.
A better opportunity elsewhere
Some experienced CISOs leave after improving a program because another organization offers a larger mandate, more budget, a bigger team, or greater authority. Turnover can therefore happen even when the leader has made progress.
Rank #2
How long does a CISO typically stay?
SecurityWeek’s 2023 analysis described 18 months as the commonly quoted average CISO tenure. Treat that as a dated estimate, not a universal benchmark: the same analysis cautioned that tenure varies with an organization’s size and security maturity. The figure alone cannot establish whether a particular company’s turnover is unusually high or whether its security program is effective.
What does the evidence say about support for security leaders?
Figures reported by SecurityWeek point to a gap between the responsibility placed on security leaders and the influence they say they have. In an August 2023 BSS survey of 150 UK security decision-makers:
Rank #3
| Survey finding | Reported result |
|---|---|
| Respondents who felt their security role was valued | 28% (BSS, August 2023) |
| Respondents who said they were actively involved in wider business strategy | 22% (BSS, August 2023) |
| Respondents who said cybersecurity was always among the board’s top three priorities | 9% (BSS, August 2023) |
These results describe the surveyed UK decision-makers; they should not be read as a current, global measurement of every CISO’s working conditions. The Advanced Cyber Security Center and CyberSaint report also captured a communication problem: “Board members lament they continue to get overly technical reports from management teams that fail to put governance in business and financial terms.”
How can CISO turnover weaken enterprise cybersecurity?
Long-running initiatives can lose momentum
Security work often involves staged implementations and dependencies across departments. A new CISO may pause, redesign, or abandon an initiative started by a predecessor. A change can be justified, but an unexamined reset can delay improvements or leave partially implemented controls.
Rank #4
Business context has to be rebuilt
A successor needs to understand the organization’s stakeholders, risk tolerance, architecture, and operating constraints. Until that context is established, it can be harder to distinguish urgent exposures from risks the business has consciously accepted, or to make changes that fit how the company operates.
Recommended Free Tools
Ownership can become unclear at handoff
When priorities and responsibilities shift, teams may not know who owns a control, an open risk, or a decision that was deferred. That uncertainty can create gaps in execution and make it harder to determine whether an agreed action is complete.
Best Value
Board alignment can remain weak
If security updates are dominated by technical detail rather than business, financial, operational, or customer impact, directors may struggle to compare risks or decide what to fund. A new CISO may then inherit both a security program and a communication gap that limits its influence.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What can boards do to retain a CISO and protect continuity?
- Give the role real authority. Make the reporting line, decision rights, access to the board, and escalation path clear. A title does not compensate for lacking influence over decisions that affect security.
- Match accountability with resources. Agree on the staffing, budget, tooling, and external support needed for the CISO’s responsibilities, and respond when the leader raises a material risk.
- Make security part of business governance. Ask for reporting that connects exposure and proposed controls to financial, operational, and customer outcomes—not only technical activity.
- Set fair expectations after incidents. Examine decisions, authority, and constraints across the organization rather than treating an incident alone as proof of an individual’s failure.
- Preserve program knowledge. Maintain a documented, multi-year roadmap, decision records, risk ownership, and transition materials so the security program does not depend on one executive’s memory.
BSS director Chris Wilkinson argued that “CISOs need a seat at the table.” The practical test is whether the leader can raise risk early, influence decisions, and secure action on agreed controls—not simply whether they attend meetings.
What should a new CISO do in the first months?
A new CISO should first establish what the organization has decided, what it can deliver, and which risks remain open. The goal is not to preserve every predecessor’s choice; it is to make changes deliberately, with clear ownership and business context.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Quick Recap
- Map authority and stakeholders. Confirm the reporting line, board access, decision rights, key business owners, and escalation routes. Identify where security decisions depend on teams outside the CISO’s control.
- Review the current roadmap and open risks. For each major initiative, establish its intended outcome, status, dependencies, owner, funding, and any decisions already made to accept residual risk.
- Test accountability at the control level. Confirm who operates important controls, who verifies them, and who is responsible for unresolved gaps. Record unclear ownership as a governance issue to resolve.
- Translate priorities for executives. Present material risks in terms of business impact, available choices, resource needs, and consequences of delay. Ask decision-makers to record their response to significant recommendations.
- Plan for continuity. Keep decisions and commitments documented, assign durable owners to work, and ensure the roadmap can be understood by a successor or another executive if leadership changes again.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

