{"id":20,"date":"2026-07-30T08:35:00","date_gmt":"2026-07-30T08:35:00","guid":{"rendered":"https:\/\/bayrisk.com.au\/blog\/?p=20"},"modified":"2026-08-08T00:39:36","modified_gmt":"2026-08-08T00:39:36","slug":"the-weight-the-ciso-was-never-meant-to-carry","status":"publish","type":"post","link":"https:\/\/bayrisk.com.au\/blog\/2026\/07\/30\/the-weight-the-ciso-was-never-meant-to-carry\/","title":{"rendered":"The weight the CISO was never meant to carry"},"content":{"rendered":"<body>\n<p class=\"has-medium-font-size wp-block-paragraph\">There is a particular kind of exhaustion that comes from a job where you are invisible when it goes well and the first name mentioned when it goes wrong. That is the CISO\u2019s job. Keep the organisation safe for a year and no one sends a note. Miss one thing, once, and your name is in the incident report, in the board minutes, and increasingly in the regulator\u2019s file. It is a quietly punishing arrangement, and the people living it are telling us, in survey after survey, that it is wearing them down.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The numbers are not subtle<\/h2>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">IANS Research and Artico Search, in their State of the CISO study for 2023 to 2024, found that CISO job satisfaction had fallen ten points in a single year, to 64 percent, and that three in four CISOs were open to leaving their role. Go back to the earlier Nominet CISO Stress Reports and the human cost is starker still. At the time, 88 percent of CISOs described themselves as moderately or tremendously stressed, and nearly half said the role had done real damage to their mental health, close to double the figure of the year before. Those Nominet numbers are a few years old now and are better read as a marker than as today\u2019s precise reading, but anyone who has sat in the seat will recognise the shape of them.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">This is not a resilience problem, it is a structural one<\/h2>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">The reason the role burns people out is not that CISOs are fragile. It is that they are handed responsibility without the authority or the access to match it. The same IANS research found that only 20 percent of CISOs are regarded as genuine C-level executives, and only 15 percent at public companies. Just half engage with their board as often as quarterly. And while 85 percent of CISOs say the board should give them clear guidance on how much risk the organisation is willing to accept, only 36 percent actually receive it. The pattern is almost mathematical: the same study found that 57 percent of CISOs with at least some board contact were satisfied in their role, against just 28 percent of those with none. Cut a person off from the body that sets the risk appetite, then hold them accountable for managing to it, and you have built a machine for burnout.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">And the stakes have just gone up<\/h2>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">For most of the role\u2019s history, the worst case for a CISO who got it wrong was losing the job. That is no longer the ceiling. In the United States, the former chief security officer of Uber, Joe Sullivan, was convicted by a federal jury in 2022 of two felonies over his handling of a 2016 breach, and sentenced in 2023 to three years of probation and a fifty thousand dollar fine, a conviction later upheld on appeal. Around the same time the Securities and Exchange Commission took the unprecedented step of charging a sitting CISO, SolarWinds\u2019 Timothy Brown, personally. It is worth being precise about how that one ended, because the headline and the outcome are different things. Most of the SEC\u2019s claims were thrown out in 2024, and in late 2025 the Commission dropped the case against both the company and Brown entirely. He was charged, not found liable. But the message the profession heard was not the dismissal two years later, it was the charge. A survey by the security firm BlackFog found that the great majority of CISOs said this drift toward personal liability had soured how they feel about the job. When the downside starts to include your own name on a filing, the weight of the role changes character.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Here is the part the anxiety obscures<\/h2>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">In Australia, the law has already decided where that weight belongs, and it is not on the CISO. This is the quiet truth underneath all of it. Our regulatory framework does not make the CISO ultimately accountable for cyber and operational risk. It makes the board accountable. APRA\u2019s prudential standard CPS 234 says it in almost exactly those words, that the board of a regulated entity is ultimately responsible for the information security of the entity. CPS 230, the operational risk standard that came into force on 1 July 2025, places operational resilience squarely on boards and senior management. The Financial Accountability Regime, which has applied to banks since March 2024, names the most senior executives and directors as the accountable people for their areas. And the Security of Critical Infrastructure Act requires responsible entities to adopt and maintain a formal risk management program under board-level oversight.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">If there were any doubt about what that means for individual directors, the country\u2019s own directors\u2019 body has removed it. The Cyber Security Governance Principles published by the Australian Institute of Company Directors, updated in late 2024, state plainly that the board holds ultimate accountability for how cyber risk is governed, that governing it forms part of directors\u2019 existing legal duties, that delegating the work or leaning on expert advice does not absolve a director of accountability, and, pointedly, that a director\u2019s lack of technical cyber knowledge does not lower the standard of care the law expects of them.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"has-medium-font-size wp-block-paragraph\">The accountability already sits with the board. The exhaustion sits with the CISO. Those two things are not supposed to be true at the same time<\/p>\n<\/blockquote>\n<\/blockquote>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">So why does the pressure keep landing on the person the law did not make accountable? Not because anyone designed it that way, but because of a gap. The board is accountable for a risk it often cannot see clearly enough to own, so by default the whole thing rolls downhill to the one person who can see it. Close that gap, give the board a view of the risk they can actually understand and act on, and the weight moves back up to where the law already put it. That is the subject of part two.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Sources<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"has-small-font-size\">IANS Research and Artico Search, State of the CISO 2023-2024 (January 2024)<\/li>\n\n\n\n<li class=\"has-small-font-size\">Nominet, CISO Stress Report (2019 and 2020)<\/li>\n\n\n\n<li class=\"has-small-font-size\">US Department of Justice, sentencing of former Uber CSO Joseph Sullivan (May 2023)<\/li>\n\n\n\n<li class=\"has-small-font-size\">US SEC litigation release, SolarWinds Corp. and Timothy G. Brown (charged October 2023; dismissed November 2025)<\/li>\n\n\n\n<li class=\"has-small-font-size\">APRA Prudential Standard CPS 234 Information Security; CPS 230 Operational Risk Management; Financial Accountability Regime<\/li>\n\n\n\n<li class=\"has-small-font-size\">Australian Institute of Company Directors and CSCRC, Cyber Security Governance Principles, Version 2 (November 2024)<\/li>\n<\/ul>\n<\/body>","protected":false},"excerpt":{"rendered":"<p>There is a particular kind of exhaustion that comes from a job where you are invisible when it goes well and the first name mentioned when&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"pagelayer_contact_templates":[],"_pagelayer_content":"","footnotes":""},"categories":[13],"tags":[17],"class_list":["post-20","post","type-post","status-publish","format-standard","hentry","category-vciso-leadership","tag-board-reporting"],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/posts\/20","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/comments?post=20"}],"version-history":[{"count":3,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/posts\/20\/revisions"}],"predecessor-version":[{"id":23,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/posts\/20\/revisions\/23"}],"wp:attachment":[{"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/media?parent=20"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/categories?post=20"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/tags?post=20"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}