There is a ritual that follows every breach that reaches the public. Within a day the coverage narrows from what happened to a single, sharper question, which is whose fault it was, and the answer the headlines reach for, almost without fail, is the security function. The story gets written, the name in the incident report gets circulated, and a room full of people who have never carried the role spend a week explaining what the CISO should have done. You will not find a single one of those stories dissected on this blog, and this piece is about why.
We will not name a breach, on purpose
This is an editorial choice, and it is a deliberate one. The cyber world already knows these stories. The people who would learn something from them learned it within hours of the disclosure, and everyone else is reading for the same reason people slow down at the roadside, which is not insight but spectacle. Raking a named organisation back over the coals months later adds nothing that the industry did not already absorb, and it quietly does something worse, because every public autopsy reinforces the idea that a breach is the story of one function’s failure, when it is almost never that. Dragging these events up again is a waste of the profession’s time and attention, and it feeds precisely the dynamic that this series has been arguing against, that the weight belongs on the CISO. So we would rather point the same attention somewhere far more useful, at the volume of obligation now landing on that function, because that is the real story and it is playing out in real time.
Look at what is on the desk this week
Take an ordinary week in August 2026 and set aside the breach headlines entirely, looking only at what a security leader inside a regulated or critical infrastructure business is being asked to carry at this exact moment. The enhanced Critical Infrastructure Risk Management Program Rules under the SOCI Act were registered and commenced in June 2026, and they do not tinker at the edges, because they require responsible entities to manage an all hazards set of material risks that now expressly includes threats to social and economic stability and to national security, to resolve foreign ownership, control and influence across their suppliers, to lift cyber maturity to Essential Eight Maturity Level Two or an equivalent standard such as ISO/IEC 27001:2023 or NIST CSF 2.0, to segregate networks and deploy phishing resistant multi factor authentication, to map their major suppliers and the vulnerabilities behind them, and to put personnel vetting in place for their critical workers, all of it phasing in across grace periods that are already running down. In the same window, the annual CIRMP report for the year to 30 June has to be prepared, approved by the board, and lodged with an attestation by that board, and it is due by 28 September, which makes it not a distant obligation but this quarter’s work. Sitting alongside all of that on the prudential side, APRA’s targeted amendments to CPS 230 took effect on 1 July 2026, layered on top of a standard whose material service provider obligations only went fully live on that same date, and further out but bearing down, the government’s response to the Slay independent review is moving toward law with new ministerial vendor risk and incident disclosure powers and civil penalties reaching into the millions.
That is not a year’s worth of change. That is the state of a single function’s in tray in one ordinary week, and none of it is optional, none of it is small, and all of it is expected to be evidenced.
The obligations now land on a quarterly cadence. The capacity to meet them, when it comes at all, still arrives once a year.
Now look at what the function is actually given
Hold that cadence of obligation next to the resources the function is handed to meet it, and the imbalance stops looking like anyone’s personal shortcoming. The 2025 Security Budget Benchmark from IANS Research and Artico Search found that security budgets grew at their slowest rate in five years, settling at under eleven percent of the IT budget, and that only 45 percent of CISOs were able to add any net new headcount, down from 67 percent just three years earlier, while the money that did move went to tools rather than people, which is the same pattern we keep returning to, more platforms landing on teams that were already at capacity. The 2025 ISC2 Cybersecurity Workforce Study, drawn from more than sixteen thousand practitioners, put numbers to the strain from the inside, with 59 percent reporting critical or significant skills shortages, a third saying they simply lack the budget to staff their teams adequately, and 72 percent agreeing that cutting security headcount materially raises the risk of a breach. This is one of the lowest resourced functions in the organisation, being handed one of its fastest growing bodies of obligation, and then being named first when the arithmetic does not hold.
Everyone in the seat can feel where the blame lands
The people doing the work are not imagining the imbalance. Proofpoint’s 2025 Voice of the CISO found that 66 percent of security leaders face expectations they consider excessive, that 63 percent had experienced or witnessed burnout in the past year, and that a third do not believe they have the resources to meet their own objectives, all while 76 percent expect a material attack in the coming year. The fear has also become personal in a way it never used to be, with a 2025 survey of security chiefs by Splunk and Oxford Economics finding that three quarters now worry about their own legal exposure, up from around half a year earlier. That is the anxiety this series opened with, and it is worth repeating the point that dissolves it, because in Australia the law has already decided where accountability for cyber and operational risk sits, and it sits with the board, not with the CISO. The CIRMP report is approved and attested by the board for a reason, and CPS 234 and CPS 230 place the responsibility at that same level, yet the pressure keeps rolling downhill anyway, not because anyone assigned it there, but because the risk and the obligation arrive in a form the accountable people cannot see clearly enough to own.
What we choose to do instead
If naming breaches changes nothing, then the useful work is upstream of the headline. It is making this pile of obligation legible to the board that the law has already made responsible for it, so that responsibility has somewhere real to land, and it is giving the security leader a position on their risk that is current and evidence led rather than a point in time assessment that was stale the day it was signed, so that on any given week, including a week like this one, they can say where the organisation actually stands against CPS 230, against the enhanced CIRMP Rules, against whatever lands next, and defend it. Neither of those is a breach story. Both of them are the reason we would rather write about the structure than the spectacle.
That is the whole of our editorial position, and it is the whole of the work. We do not think the CISO community needs another retelling of a bad day at a named company. It needs the responsibility put back where it belongs and a defensible read on its risk that holds up in real time, against a wave of obligation that is not going to slow down, and that is what we spend our words, and our days, on instead.
Sources
- Department of Home Affairs and Cyber and Infrastructure Security Centre, enhanced Critical Infrastructure Risk Management Program Rules under the SOCI Act (registered and commenced June 2026; all-hazards material risks, cyber Maturity Level 2, supply chain and personnel obligations phasing in across grace periods)
- Security of Critical Infrastructure Act, annual CIRMP report and board attestation (due within 90 days of financial year end, by 28 September)
- APRA, final targeted amendments to CPS 230 Operational Risk Management (finalised 30 April 2026, effective 1 July 2026); CPS 230 material service provider obligations live from 1 July 2026; CPS 234 Information Security
- Australian Government response to the Independent Review of the SOCI Act (Dr Jill Slay review, 2026), proposed ministerial directions, vendor-risk and incident-disclosure powers and increased civil penalties
- IANS Research and Artico Search, 2025 Security Budget Benchmark (budget growth slowest in five years; security under 11% of IT budget; 45% of CISOs added net new headcount, down from 67%)
- ISC2, 2025 Cybersecurity Workforce Study (59% critical or significant skills shortages; one third lack budget to staff adequately; 72% link personnel cuts to breach risk)
- Proofpoint, 2025 Voice of the CISO (66% excessive expectations; 63% burnout; 76% expect a material attack)
- Splunk and Oxford Economics, 2026 CISO Report (75% of CISOs worry about personal legal exposure, up from about half a year earlier)
- Australian Institute of Company Directors, Cyber Security Governance Principles (board holds ultimate accountability)