← All posts

Your CISO Is Thinking About Quitting. Here's Why That's a Board-Level Problem.

One in four CISOs considered walking away from the job in the past year. Not because they lost interest in the mission, but because the mission now includes personal legal exposure that didn't exist three years ago.

That statistic comes from the 2026 Splunk/Oxford Economics CISO Report, which surveyed 650 security chiefs across nine countries. The headline number: 78% of CISOs now worry about personal liability for security incidents on their watch, up from 56% the year before. That's not a trend line. That's a fire alarm.

If you sit on a board or run a company, this should concern you — not because your CISO's feelings matter more than anyone else's, but because a CISO who is managing personal legal risk instead of enterprise security risk is a CISO who is not protecting your organization.

The Liability Rules Have Changed

The regulatory machinery driving this anxiety is real and expanding on multiple fronts.

In the United States, the SEC's 2023 charges against SolarWinds and its CISO Timothy Brown — alleging fraud for overstating cybersecurity practices — sent a shockwave through the profession. The charges were ultimately dismissed in late 2025, but the message landed: individual security leaders can be personally named in enforcement actions when disclosures don't match reality.

Under CMMC 2.0, a senior executive called the "Affirming Official" must personally certify that their organization meets all 110 NIST SP 800-171 security controls. False Claims Act exposure attaches to that signature. Even though the Department of Defense paused mandatory third-party certification in July 2026, the self-assessment requirement — and the personal attestation that accompanies it — remains fully enforceable.

In Europe, the NIS2 Directive enables authorities to hold management bodies personally liable when gross negligence contributes to a cyber incident. Sanctions can include temporary bans from holding management positions. As of early 2026, 22 of 27 EU member states have completed transposition, and enforcement has begun in Germany, the Netherlands, and France.

The EU's Digital Operational Resilience Act (DORA) adds another layer for financial entities, requiring documented board accountability for ICT risk management, third-party oversight, and recovery planning.

AI Governance Made It Worse

The Splunk report reveals a compounding factor that boards need to understand: 96% of CISOs now own AI governance and risk management across their enterprises. Two years ago, that responsibility belonged to almost nobody in the security function.

This mandate landed without a corresponding increase in budget or headcount at most organizations. CISOs are now personally accountable for how AI tools access sensitive data, how model outputs are reviewed before production use, and how unsanctioned AI experimentation is governed — on top of every responsibility they already carried.

Forty percent of CISOs report already using generative AI within their security operations. The rest are governing its use across the enterprise while simultaneously defending against AI-enabled threats. The scope of what can go wrong — and what a CISO can be held personally responsible for — has expanded dramatically.

What This Means for Your Board

In Cyber Risk Is Business Risk, I outline the Three Questions framework that every board should be able to answer: What are our most critical assets? What are we doing to protect them? How do we know it's working?

The CISO personal liability crisis adds a fourth question boards need to ask themselves: Are we setting our CISO up for success, or for a lawsuit?

Here's how to tell the difference:

Budget alignment. If your CISO's responsibilities have expanded to include AI governance, supply chain attestation, and cross-border regulatory compliance, but the security budget hasn't moved, you have a gap between accountability and authority. That gap is where liability lives.

Board reporting structure. CISOs who report through the CIO or CFO often lack the organizational independence to deliver bad news without career consequences. The Splunk report found that 85% of CISOs cite "low cybersecurity fluency among non-technical executives" as an obstacle to collaboration. If your CISO can't get a meeting with the board, the board can't claim it was exercising oversight.

Documentation discipline. Personal liability attaches to what leaders knew and when they knew it. Organizations that treat security briefings as informal check-ins rather than documented governance activities are creating exposure — for the CISO and for the directors who should have been paying attention.

What to Ask Your CISO This Week

If you're a CEO or board member reading this, here are three conversations worth having before your next committee meeting:

  1. "Has your scope of personal liability changed in the past twelve months?" Most CISOs will tell you it has. The follow-up is whether your organization's D&O insurance, indemnification provisions, and employment agreements reflect that reality.
  2. "What would you need to feel confident signing a personal attestation of our security posture?" If your CISO hesitates, that hesitation is information. It tells you there are gaps between what you're certifying and what you're actually doing.
  3. "Are we budgeting for the CISO role as it exists today, or as it existed three years ago?" The Splunk data shows 45% of CISOs report moderate burnout among their teams. Underfunded security functions don't just increase breach risk — they increase the personal legal exposure of the person you're asking to sign their name to your compliance posture.

The Bottom Line

The CISO retention crisis isn't about compensation or title inflation. It's about a fundamental mismatch between the personal risk these leaders carry and the organizational support they receive.

When a quarter of your security leadership talent pool is eyeing the exits, that's not an HR problem. It's a governance failure — and boards that don't address it are creating exactly the kind of oversight gap that regulators are now empowered to punish.

Cyber risk is business risk. And right now, for 78% of CISOs, it's personal risk too.