Life of a CISO in the Frontier AI Era : The Thankless Job With 24/7 Stress and What Must Change - Safe Security

Life of a CISO in the Frontier AI Era : The Thankless Job With 24/7 Stress and What Must Change

Oct 8, 2026 18 minute read

What breach cases, boardroom pressure, budget gaps and AI-enabled attacks reveal about the world’s most exposed executive role

A CISO’s job can feel thankless. The organization expects continuous protection, yet the role rarely controls every technology decision, vendor relationship or business deadline. Successful prevention often goes unnoticed. A single control failure can bring public scrutiny, regulatory questions, litigation and career consequences. Shared executive accountability, clear decision rights, evidence-based risk decisions, continuous third-party monitoring and continuous exposure management give the role the support it needs. One person’s heroics cannot carry that responsibility.

It is 2:13 a.m. and the phone is ringing

The first question is rarely, “Are you okay?”

Usually, it is “What happened?” Then come the other questions: Are we still operating? Was data taken? Do we need to notify regulators? What do we tell customers? Is this material? Was a supplier involved? When did you know?

The CISO has to answer while the facts are still changing. Logs are incomplete, and the attacker may still be inside. Legal counsel needs precision; communications needs a statement. The CEO and board need enough information to make decisions with confidence. Customers want certainty, regulators expect timeliness, and the technical team needs space to investigate.

In years of conversations with security and risk leaders, I have heard versions of this same pressure. The details vary by sector and country. The expectation is familiar: stay calm for everyone else, carry the uncertainty privately, and make a decision that may later be judged using information you did not have at the time.

There is a reason CISOs call it a “24/7 job.” The business runs at night, cloud services change continuously, and suppliers operate across time zones. Attackers do not respect reporting lines or weekends. An on-call team can share the work, but accountability still travels upward. Eventually, the phone reaches the CISO.

Security leaders make consequential decisions and must be able to explain them. But their accountability needs to match their authority, resources and evidence. Too many organizations demand accountability without giving the CISO enough of the other three.

Why the job can feel thankless to many

Cybersecurity has a cruel success metric: a quiet day.

An improvement in margin appears in a finance report. A large sales deal gets celebrated. When a CISO prevents credential theft, blocks an exploit path or persuades a product team to fix a dangerous design, there may be nothing visible to celebrate. The service stays up, customers carry on, and no headline appears. That quiet is the outcome the team worked for.

After one incident, the conversation can change completely. Years of avoided loss fade into the background, and the questions become personal: Why did you not stop this? Why was the board not told? Why did we spend so much on security?

The gap becomes clear when you compare the expectations with the CISO’s control:

What the organization expects What the CISO often controls
No material breach A security program, not every business decision
Immediate certainty during an incident An investigation that develops over hours, days or months
Complete visibility A changing estate spread across cloud, SaaS, code, identities and suppliers
Fast transformation The security conditions under which transformation can proceed
Compliance in every jurisdiction Coordination across legal, privacy, engineering, operations and regional teams
Protection across the supply chain Contract terms, telemetry and cooperation that may sit outside the CISO’s authority

am wary of the phrase “the CISO owns cyber risk.” The CISO leads the cyber-risk program, but the organization owns the risk. Product leaders make product decisions; business leaders accept business risk. Procurement and legal shape supplier obligations, technology leaders operate systems, and the board oversees material enterprise risk. Blur those responsibilities, and every unresolved dependency lands with the CISO.

A normal day is already an incident simulation

The pressure does not begin with the breach call. Look at an ordinary day.

At 8:00 a.m., a dashboard shows thousands of findings. The team needs to know which exposures are reachable, exploitable and connected to a critical service. At 9:00, procurement wants approval for a vendor that the business needs this quarter. At 10:00, the audit committee asks whether cyber risk is going up or down. At 11:00, legal asks whether a new rule changes incident reporting. At noon, an engineer requests a security exception to meet a launch date.

The afternoon brings a cloud misconfiguration, an identity alert, a ransomware claim involving a supplier, a questionnaire from a customer and a budget review. Alongside all of this, the CISO has to retain good people, coach future leaders and explain risk in business language without losing the technical truth.

The World Economic Forum’s 2025 global outlook reported that only 14% of surveyed organizations were confident they had the people and skills they needed, while two in three lacked essential cyber talent and skills. ISC2’s 2024 workforce study found that 37% of respondents had faced cybersecurity budget cuts and 67% reported staffing shortages. Those are survey results, not universal laws, but they describe the operating environment many teams recognize.

The pressure is also visible at the top. In a 2025 survey of 600 CISOs and 100 board members conducted for Splunk by Oxford Economics, only 29% of CISOs said they received the budget needed to achieve their security goals, while 41% of board respondents believed budgets were adequate. Sixty-four percent of CISOs said the threat and regulatory environment made them worry they were not doing enough. Twenty-one percent said they had been pressured not to report a compliance issue.

Together, these findings describe a familiar squeeze: responsibility, visibility and regulatory demands are growing, while confidence in staffing and budget remains low. Even the CISO and board may disagree on whether the team has enough funding.

What happened when the breach became personal

The cases below show how professional accountability can become a personal consequence. They also need careful reading. Charges, convictions and civil judgments are different things, and a dismissed case must be described as dismissed. Even the executive’s title matters.

Joe Sullivan: a criminal conviction, not a simple “CISO was blamed” story

Joe Sullivan held the title of Chief Security Officer at Uber, rather than CISO. It is worth being precise about his role when discussing the case.

In October 2022, a jury convicted Sullivan of obstruction of justice and misprision of a felony in connection with his handling of Uber’s 2016 data breach. In May 2023, he was sentenced to three years of probation and a $50,000 fine. The U.S. Department of Justice said the breach involved records associated with approximately 57 million users and drivers, and that Sullivan concealed it from the Federal Trade Commission and later management. In November 2025, the U.S. Court of Appeals for the Ninth Circuit affirmed the conviction and denied rehearing.

Sullivan’s case concerned his conduct after the incident was discovered: disclosure, representations, payments, documentation and interaction with a government investigation. It does not establish that a security executive goes to court whenever a company is breached. For CISOs, the practical lesson is to have written escalation paths, independent legal advice and preserved decision records. Everyone involved should know who has authority to decide whether and how an incident is disclosed.

Timothy Brown and SolarWinds: the case that changed the temperature, then ended

In October 2023, the U.S. Securities and Exchange Commission sued SolarWinds and its CISO, Timothy G. Brown. The case became a global reference point in discussions about security leaders’ personal liability. Its subsequent developments are just as important to that discussion.

In July 2024, a federal court dismissed most of the SEC’s claims while allowing a narrower claim to continue. On 20 November 2025, the SEC dismissed its civil enforcement action against SolarWinds and Brown with prejudice. The SEC said the decision was an exercise of discretion and did not necessarily reflect its position in any other case.

Brown was not found liable, and the case should not be presented as though he was. Its dismissal does not erase the pressure it created. For more than two years, a sitting CISO was personally named in a federal enforcement action while other security leaders considered what it might mean for their own exposure.

The useful response is a governance process that gives material security representations proper review, supporting evidence and company ownership. If a disclosure describes control effectiveness, known gaps or incident impact, security, legal, finance and executive leadership should be aligned on the factual basis.

Equifax: immediate exits and a governance redesign

After Equifax disclosed its 2017 breach, Chief Information Officer David Webb and Chief Security Officer Susan Mauldin were replaced on an interim basis. The company later said both executives had retired. A U.S. House committee report found structural problems: Mauldin was not a member of the senior leadership team, did not regularly attend its meetings and reported through the legal organization. After the breach, Equifax elevated the new CISO to report directly to the CEO.

There is an uncomfortable mismatch here. An organization may give security a supporting role before an incident, then expect enterprise-level accountability from it afterward.

No reporting line can prevent breaches on its own. What matters is whether the CISO can reach decision-makers in time, escalate unacceptable risk, and use a documented process for the business to accept or fund that risk. Enterprise authority has little meaning if the CISO has no access to the people setting enterprise priorities.

SingHealth: an official inquiry put responsibility beyond the security team

Singapore’s inquiry into the 2018 SingHealth attack found weaknesses in people, process and technology, including failures to act on warning signs. The government accepted the inquiry’s findings and made a broader governance point: trade-offs among security, operations and cost must be made at board and CEO level, not left only to the CISO and technical staff.

Boards should take that finding seriously. Cybersecurity decisions routinely involve trade-offs. A legacy clinical system cannot always be patched like a laptop. A bank cannot take a payment platform offline without consequence. A factory cannot reboot operational technology on demand. A public agency may have statutory duties and procurement limits. These decisions belong to accountable business leadership, informed by the CISO.

The accountability–authority gap

Ask a CISO whether they are accountable for cyber risk and most will say yes. Then ask five follow-up questions:

  1. Can you stop a launch when the residual risk exceeds appetite?
  2. Can you require a business owner to sign a time-bound exception?
  3. Can you see every critical supplier and the supplier behind that supplier?
  4. Can you move budget toward the exposures most likely to cause material loss?
  5. Can you show the board which risk-reduction decisions remain unfunded?

If the answer is no, accountability exceeds authority.

That gap creates pressure well before a breach. A CISO may know where the weak points are without being able to fix them personally. The business owns the process running on an unsupported system. Procurement owns the vendor negotiation. Operations sets the change window for segmentation, and engineering implements the control security has defined. Progress depends on all of them.

Make those dependencies visible. Assign an executive owner to the business risk and a technical owner to the control. Set a decision date and an escalation route if it slips. This gives the CISO a system to lead, with responsibilities the organization can follow through on.

The board conversation that needs to change

Boards often ask a binary question: Are we secure?

A responsible CISO cannot give an unconditional yes. Boards get a more useful conversation by asking:

  • Which business services carry the greatest cyber risk?
  • Which loss scenarios could exceed our risk appetite?
  • What changed this quarter and why?
  • Which controls and investments reduced risk measurably?
  • Which accepted risks are approaching expiry?
  • Where do third- and fourth-party dependencies create concentration risk?
  • What would we stop, isolate or communicate in the first hours of a material incident?

In the United States, public companies must disclose a material cybersecurity incident on Form 8-K within four business days after the company determines the incident is material. The clock does not start automatically at discovery. The materiality determination must be made without unreasonable delay.

That distinction is operationally vital. The incident team needs a pre-agreed materiality process with legal, finance, operations and security inputs. The CISO should provide facts about technical scope, affected services and plausible impact. The company makes the disclosure decision through its governance process.

The board needs to make sure this process exists before an incident, while there is still time to test it.

Now add frontier AI and open-weight models

AI adds another source of pressure. Understanding it starts with what the evidence says.

The UK National Cyber Security Centre assessed in May 2025 that AI would almost certainly make elements of intrusion operations more effective and efficient, increasing the frequency and intensity of cyber threats. It also expected a digital divide between organizations able to keep pace with AI-enabled threats and those that could not. The report highlighted AI-assisted vulnerability research and exploit development, faster exploitation of known vulnerabilities and a larger attack surface as AI systems spread.

The International AI Safety Report 2026 describes a dual-use reality. General-purpose AI can assist defenders and attackers. Open-weight models provide valuable access for research, private deployment and innovation. They also allow models to be copied, modified and run outside a provider’s monitoring. Once weights are widely released, access cannot be fully rolled back. The report notes that open-weight models have narrowed the capability gap with leading closed models.

These findings point to changes in the cost and pace of familiar attack and defence activities. They do not mean autonomous AI agents are breaking into every enterprise today. The changes include:

  • reconnaissance can become cheaper and more parallel;
  • phishing and social engineering can become more tailored;
  • vulnerability research can accelerate;
  • attackers can analyze stolen data faster;
  • defenders can automate triage, correlation, validation and response.

“Machine versus machine” captures some of this shift, but it leaves out the organizational work. Defenders need to turn good data into timely action, with governance in place. Attackers need one workable path; defenders have to protect a changing estate while preserving evidence, limiting business disruption and staying within law and policy.

The budget problem sharpens the divide. The same WEF survey found 67% of focus-group participants saw a shortfall in investment in AI skills. If a CISO receives money for an AI pilot but not for asset inventory, identity hygiene, telemetry, incident exercises or remediation capacity, the organization has funded a demonstration rather than defence.

AI can reduce analyst toil, but the organization still has to make decisions and complete the work. Someone must own the asset, accept the risk or carry out the fix. Otherwise, faster findings simply add pressure to an unresolved queue.

What CISOs need from their organizations

After a 70-hour incident week, a wellness webinar is unlikely to address the source of the pressure. Personal support matters. So do changes to how the role is set up, funded and supported.

1. A written mandate with real decision rights

Define what the CISO owns, what business and technology leaders own, and how unresolved disagreements escalate. Include authority for emergency containment, risk-exception requirements and direct access to the board or relevant committee.

2. Shared executive accountability

Cyber risk should appear in enterprise risk governance with named business owners. A CISO can recommend that a critical service be redesigned; the executive who chooses cost, timing and customer impact should own the decision with them.

3. A budget tied to risk reduction

Move beyond “security spend as a percentage of IT.” Fund the scenarios that could cause material harm and measure whether investment reduces their likelihood or impact. Show leadership the residual risk that remains when an initiative is deferred.

4. A protected incident decision process

Create a standing incident group with security, legal, privacy, finance, communications, operations and executive leadership. Define thresholds, evidence standards, regulators, customer obligations and decision logs. Exercise difficult situations: incomplete facts, a supplier breach, a ransomware demand, conflicting legal duties and a leak to the media.

5. Continuous visibility across the ecosystem

An annual questionnaire cannot describe a vendor’s current exposure or every indirect dependency. The program needs continuously refreshed signals, a current inventory, evidence for attribution and a way to connect an external event to the business relationship it may affect.

6. Prioritization that engineers can act on

Security teams do not need a larger queue. They need to know which exposures are reachable, exploited, connected to critical assets, insufficiently controlled and material to the business. Remediation work should have an owner, due date, evidence and exception path.

7. Human operating limits

No executive should be the only route for every security decision. Build deputies, on-call rotations and succession. After a severe incident, provide recovery time and confidential support. A rested leader makes better decisions; this is operational resilience, not a perk.

A practical compact between the CISO, CEO and board

Before the next incident, agree to the following:

The CISO commits to The CEO and board commit to
Present risk in business terms, with uncertainty made explicit Treat cyber risk as enterprise risk and make trade-offs at the right level
Escalate material concerns early Protect escalation from retaliation and avoid punishing bad news
Maintain evidence for major assertions and decisions Fund the information, people and controls required to produce that evidence
Build a capable leadership bench and tested response process Avoid dependence on one heroic individual
Measure risk reduction and disclose limits Accept, transfer, avoid or fund residual risk through named decisions

These commitments give the CISO and the organization a fairer, more effective way to work together, even when the decisions remain difficult.

My message to CISOs

If you are a CISO reading this after midnight, another reminder to “be resilient” probably offers little help. You may already be carrying more than the role should require.

My advice is to insist on precision. Document what you know, what you do not know, who decided and when the decision must be revisited. Build direct relationships with legal, finance, communications and operations before the crisis. Teach the board to discuss scenarios and choices, not a fictional state called “secure.” Develop deputies who can challenge you and carry the phone.

You should also challenge the expectation that a strong leader prevents every breach. Good security leadership builds a system that reduces credible risk, detects failure early, contains impact, learns honestly and helps the organization recover.

The job may still be thankless on some days. It should never be powerless, isolated or designed around permanent personal sacrifice.

When the 2:13 a.m. call comes, the CISO needs an organization ready to respond alongside them. Evidence should be accessible, decisions should have owners, and suppliers and exposures should already be mapped. The incident team should know its role. The board should recognize the incident as an enterprise risk, with responsibilities across the business.

Protecting the organization also means supporting the people trusted to protect it.

Frequently asked questions

Why is the CISO role so stressful?

The role combines continuous operational responsibility, incomplete information, regulatory deadlines, board expectations, public scrutiny and dependence on teams the CISO may not control. Prevention is hard to see, while failure becomes highly visible.

Is a CISO personally liable when a company is breached?

Not automatically. Liability depends on jurisdiction and conduct. The Uber CSO case involved a criminal conviction related to concealment and obstruction. The SEC’s civil case against SolarWinds and its CISO was dismissed with prejudice in November 2025. Organizations should obtain jurisdiction-specific legal advice and create clear disclosure governance.

Can a CISO guarantee that a breach will never happen?

No. A CISO can reduce likelihood and impact, improve detection and response, and provide evidence for risk decisions. No responsible security leader can promise zero incidents across a changing organization and supply chain.

What should a board ask a CISO?

Ask which business services and loss scenarios carry the greatest risk, what changed, which actions reduced risk, what remains above appetite, which decisions are unfunded, and how third- and fourth-party dependencies could amplify impact.

How should CISOs prepare for AI-enabled cyberattacks?

Start with strong asset, identity, vulnerability, supplier and incident-response foundations. Add AI where it improves triage, correlation, validation and response. Test model and automation risks, keep humans accountable for high-impact actions and invest in team skills.

Why do open-weight AI models matter to cyber defence?

Open-weight models can support private deployment, research and defensive innovation. They can also be copied, modified and run beyond provider monitoring, making misuse harder to prevent and access difficult to reverse after release. The result is a faster capability cycle for both attackers and defenders.