The Honest State of the CISO Turnover in 2026

The CISO turnover number has been the metric the board has been reading about for five years, the metric that has finally crossed the threshold the recruiter said was unsustainable. The CISO who stayed two years, the CISO who left…

A worn brown leather office chair seen from behind, empty, in front of a dark steel desk, a single chrome pen left on the desk, a cold overhead spotlight, deep charcoal and steel grey palette, dramatic chiaroscuro, no people no text no logos

The CISO turnover number has been the metric the board has been reading about for five years, the metric that has finally crossed the threshold the recruiter said was unsustainable. The CISO who stayed two years, the CISO who left for the next role, the CISO who the enterprise has been hiring to replace the CISO who just left. The honest framing matters here, because the CISO turnover the recruiter has been warning about sits as the CISO turnover the postmortem will eventually describe, the postmortem that lands three months after the CISO who could have prevented the breach has already moved to the next role.

What follows runs as the working version of the field guide. The shorter version is what the board and the CISO both actually have time to read.

What the 2025-2026 numbers actually say

Three findings, in roughly that order of how much each one matters. The first runs as the average tenure dropped below three, where the average tenure the industry has been tracking, the average that used to sit around four years, the average that dropped below three in 2024, the average that dropped below two and a half in 2025, the average that the recruiter has been citing in the CISO salary negotiation. The second runs as the burnout cause share, where the burnout cause the departing CISO has been citing in the exit interview, the cause that runs in roughly that order of how often it shows up (the lack of board support, the lack of budget, the personal liability exposure, the breach that broke the CISO), the cause the next CISO hire will inherit unless the enterprise addresses the cause before the next CISO is hired. The third runs as the successor gap, where the successor the enterprise has been planning to promote from within, the successor that does not exist because the enterprise has been hiring CISOs from outside, the successor gap that will land as the CISO the enterprise cannot find when the next CISO quits.

Why the role has become unsustainable

Three things, in roughly that order of how much each one contributes. The first runs as the scope expansion, where the scope the CISO has been asked to cover, the scope that used to be the IT security, the scope that now covers the AI governance, the privacy, the product security, the third party risk, the OT security, the scope that no single CISO can cover at the depth the board expects. The second runs as the regulatory exposure, where the exposure the CISO carries personally under the SEC disclosure rule, the NIS2, the DORA, the state level privacy law, the exposure that the CISO has to factor into every decision the CISO makes, the exposure that the CISO cannot insure away. The third runs as the budget gap, where the gap between the security budget the CISO has been asking for and the budget the CFO has been approving, the gap that the CISO has been managing around, the gap that has been burning the CISO out faster than the breach cycle the CISO has been trying to prevent.

What an enterprise can do to keep the CISO

Three moves if you are the board or the executive team that wants the CISO to stay past the second year. Give the CISO the authority, where the authority the CISO has been asking for (the veto on the high risk project, the direct line to the CEO, the seat at the executive committee), the authority the enterprise can give before the next CISO quits, the authority that makes the job the CISO can actually do. Fund the security programme, where the funding the CISO has been asking for (the headcount, the tooling, the managed service the team needs), the funding the enterprise can approve in the next budget cycle, the funding that lets the CISO sleep at night and stays in the role past the second year. Recognise the cost, where the cost the CISO carries, the cost the board should acknowledge, the cost the board should compensate for in the salary, the bonus, the equity, the cost the next CISO will price in to the salary negotiation if the current CISO has to replace the CISO. The enterprise that gives the authority, funds the programme, and recognises the cost serves as the enterprise that has kept the CISO long enough for the CISO to actually do the work.

A worn employment agreement paper on a dark steel desk, a single torn signature line at the bottom, a cold steel fountain pen resting on the page, a faint coffee ring on the paper, single cold side light, deep charcoal and steel grey palette, dramatic chiaroscuro, 16:9 widescreen editorial photography, no people no text no logos
CISO turnover in 2026: 3 things the numbers actually say, 3 reasons the role has become unsustainable, 3 moves an enterprise can make to keep the CISO.

The bottom line

The CISO turnover in 2026 sits as the metric the board has been reading about and the metric the board has not yet acted on. The tenure drop, the burnout cause, the successor gap, those three are what the numbers say. The scope expansion, the regulatory exposure, the budget gap, those three are why the role has become unsustainable. The authority, the funding, the recognition, those three are how the enterprise keeps the CISO. The enterprise that does the three keeps the security programme. The enterprise that does not serves as the enterprise that hires the next CISO into the same trap.



Sources & Further Reading

All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.

Spotted an error? Email the editor. Corrections are issued with a visible correction note.

Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.

Continue reading