{"id":117,"date":"2026-09-12T00:28:07","date_gmt":"2026-09-12T00:28:07","guid":{"rendered":"https:\/\/bayrisk.com.au\/blog\/?p=117"},"modified":"2026-09-12T00:28:07","modified_gmt":"2026-09-12T00:28:07","slug":"do-your-work-in-the-hallways-a-ciso-the-board-and-the-burnout-nobody-reports","status":"publish","type":"post","link":"https:\/\/bayrisk.com.au\/blog\/2026\/09\/12\/do-your-work-in-the-hallways-a-ciso-the-board-and-the-burnout-nobody-reports\/","title":{"rendered":"Do your work in the hallways: a CISO, the board, and the burnout nobody reports"},"content":{"rendered":"<body>\n<h1 class=\"wp-block-heading\"><strong>TL;DR<\/strong><\/h1>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The best CISOs get heard the same way: trust first, a defendable position that is today\u2019s not six months old, and every pressing risk carried in with a costed plan, all inside the roughly thirty minutes a quarter they get with the board.<\/li>\n\n\n\n<li>Their motto says the rest: do your work in the hallways. The formal board moment confirms an argument you have already won informally, so nothing lands cold in the room.<\/li>\n\n\n\n<li>Everything that playbook asks of one stretched person is why CISO burnout is, in my view, one of the most underplayed and under-reported risks in business.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">I keep coming back to a conversation I had recently with a CISO I have a lot of time for. We were not talking about frameworks or platforms. We were talking about something harder and rarely written down: how a security leader actually earns the right to be heard by a board, and what it quietly costs them to do it well.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What struck me was that none of it was technical. It was about trust, timing and evidence, in that order. I have pulled the thinking together here, anonymised, because the lessons are worth far more shared than kept.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Trust comes before funding, not after<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The first thing they said has stayed with me. If you walk into a board demanding action and funding before you have established trust, you will never build the rapport a CISO needs to do the job properly. The instinct, when you can see the risk clearly, is to raise the alarm and ask for money. But a board that does not yet trust the person raising the alarm hears noise, not signal, and the relationship starts in a hole it rarely climbs out of.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The sequence they described is the reverse. First, tell the board what you are doing and that it is under control. Establish that you are a steady pair of hands. Only then, once trust exists, do you bring real-time facts alongside remediation plans. Earn the standing first, spend it second.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>You have about thirty minutes a quarter, so respect it<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Here is the number that should focus every CISO\u2019s mind. In many organisations the security leader gets around thirty minutes with the board, once a quarter, to raise what matters. A quarter\u2019s worth of nuance, threat and progress has to survive contact with a crowded agenda and a room of directors with a dozen other things on their minds.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Thirty minutes a quarter changes what good looks like. It rules out the forty-slide deck and the technical deep dive. It demands material that is trusted and succinct, a position a board can absorb quickly and act on confidently. If your reporting cannot do that, the time is wasted, and you do not get it back until next quarter.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The position has to be defendable, and it has to be today\u2019s<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This was the sharpest point of the conversation. Whatever you put in front of the board has to be defendable. Their phrase was almost exact: this is the exact position we hold today, not six months ago. A risk picture that was true at the last assessment and has quietly drifted since is not a position you can defend, it is a liability with your name on it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And it cannot float free of the business. Once the position is aligned to the organisation\u2019s actual risks, it should surface the most pressing matters for the board\u2019s attention, and each of those should arrive with a costed remediation plan. Not a problem, a problem with a price and a path. That is what lets a board do the one thing it is there to do: make a funded decision.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>Don\u2019t hand the board a problem. Hand them an investable decision.<\/em><\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Do your work in the hallways<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The line I will remember longest was their motto for the whole craft: do your work in the hallways. The formal board moment is not where you win the argument. It is where you confirm an argument you have already won, quietly, in the corridors and the one-to-ones beforehand. You build alignment informally, you find out where each director stands, you soften the surprises, so that nothing lands cold in the room. By the time the item reaches the table, the people who matter have already nodded to it privately.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is a deeply human insight, and it is the opposite of how risk is often imagined, as a set of numbers that should speak for themselves. They do not. People decide, and people decide more easily about things they have already been walked through by someone they trust.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The risk hiding inside all of this: burnout<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Here is where the conversation took me, and it is the part I feel most strongly about. Look again at everything that playbook asks of one person. Be trusted and steady at all times. Compress a quarter into thirty minutes. Hold a position that is provably current, not a version that was true last quarter. Attach a costed plan to every pressing risk. And do the quiet, constant relationship work in the hallways on top of the day job of actually defending the organisation. That is not one role. It is several, and we routinely ask a single, often under-resourced person to carry all of them at once.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">CISO burnout is, in my view, one of the most underplayed and under-reported risks in business. We treat it as a wellbeing footnote when it is a live operational risk. A burnt-out security leader is a slower detection, a missed obligation, a board briefing thrown together at midnight, a resignation that walks years of context out the door. The role has a punishing shape: personally accountable for outcomes, rarely given the resources to match, and judged in thirty-minute windows on material that has to be flawless. It is little wonder the tenure is short and the toll is high. And almost nobody puts it on the risk register, which is exactly the kind of blind spot the profession is meant to be good at spotting.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Walk in bulletproof, leave the risk where it belongs<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This is where the conversation aligns, deeply, with what I believe at BayRisk. Every part of that board playbook depends on one thing the CISO can rarely guarantee alone: a current, defendable, costed position, ready on any day, not assembled in a panic the night before. Real information, not attestation. Evidence they can stand behind, not a self-assessment they are quietly hoping holds.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That is the whole point of what we do. We keep the position current, succinct and costed, so the CISO walks into those thirty minutes bulletproof, with a picture that is genuinely today\u2019s and a plan against each pressing risk. And when they present it, the risk goes exactly where it belongs, with the board, who own it and decide on it. That is not the CISO dodging accountability. It is the CISO doing their actual job: surfacing a clear, honest, defendable position and letting the people who own the risk make a funded decision about it. Handing the board a real choice is not obfuscation. It is the job done properly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Do that, and two things happen at once. The board gets better decisions, made on today\u2019s facts. And the CISO is relieved of the one burden that quietly breaks them, the relentless, invisible work of keeping the position provable while everything else is on fire. The risk stays theirs and the board\u2019s. The work of keeping it true becomes ours. What is left for the CISO is the human work only they can do, the trust, the judgement, and the hallways.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I am grateful to the CISO who shared this, and I have kept them anonymous deliberately. If you carry this role yourself, I would genuinely like to know: does the thirty minutes ring true, does the hallway work match your experience, and are we, as a profession, being honest enough about what it costs the person doing it?<\/p>\n<\/body>","protected":false},"excerpt":{"rendered":"<p>TL;DR I keep coming back to a conversation I had recently with a CISO I have a lot of time for. We were not talking about&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"pagelayer_contact_templates":[],"_pagelayer_content":"","footnotes":""},"categories":[13],"tags":[17,47,45,36,48,46],"class_list":["post-117","post","type-post","status-publish","format-standard","hentry","category-vciso-leadership","tag-board-reporting","tag-ciso","tag-ciso-burnout","tag-grc","tag-risk-leadership","tag-vciso"],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/posts\/117","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/comments?post=117"}],"version-history":[{"count":1,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/posts\/117\/revisions"}],"predecessor-version":[{"id":118,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/posts\/117\/revisions\/118"}],"wp:attachment":[{"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/media?parent=117"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/categories?post=117"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/tags?post=117"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}