The CISO Job Market Has Fundamentally Changed

The CISO job market of 2026 is not the CISO job market of 2018. The skills, the compensation, the reporting structure, the board relationship, the budget authority, the legal exposure, all of these have shifted in ways that are reshaping…

Tech-noir editorial image: ciso market



The CISO job market of 2026 is not the CISO job market of 2018. The skills, the compensation, the reporting structure, the board relationship, the budget authority, the legal exposure, all of these have shifted in ways that are reshaping what boards are looking for and what the role actually is. The 2018 CISO was a technical leader. The 2026 CISO is a business operator with a technical background. The companies that still hire for the 2018 profile are getting the 2018 results. The companies that hire for the 2026 profile are getting the 2026 outcomes.

The shift has happened in 8 years. The shift is not subtle. The CISO compensation has roughly doubled at the top of the market. The CISO reporting line has moved up, from CIO or CFO to CEO or board. The CISO legal exposure has increased to the point where the role has become a high liability position. The CISO budget authority has increased, in real terms, faster than the security industry’s marketing spend. The CISO job description has changed more in the last 5 years than in the previous 20.

The 2018 CISO profile is still in most job descriptions. The 2026 CISO profile is in the work. The gap sits as the source of most of the bad CISO hires of the last few years.

The 2018 CISO profile

The 2018 CISO was, in most enterprises, a senior technical leader who had risen through the security engineering ranks. The CISO knew the tools. The CISO had run a SOC, or built one. The CISO had implemented an identity system, or run a vulnerability management program, or deployed an SIEM. The CISO reported to the CIO, sometimes to the CTO, rarely to the CEO. The CISO budget was part of the IT budget. The CISO had authority over the security tools and the security team, but not over the security of the business.

The 2018 CISO was, in most cases, a respected senior leader who could talk to the engineers but had limited influence with the board. The 2018 CISO was often excluded from the most important business decisions, including M&A, including product strategy, including vendor risk. The 2018 CISO was asked to secure what the business decided, not to inform what the business decided.

What changed: SEC rules, ransomware, AI, board exposure

An open worn manila folder on a dark steel desk, a few blank cream business cards spilled out onto the steel, a chrome pen resting on the open page, single cold side light, deep charcoal and steel grey palette, no people no text no logos
The 2018 CISO secured what the business decided. The 2026 CISO informs what the business decides.

Four things have changed since 2018. The SEC’s 2023 cybersecurity disclosure rules, which made the CISO personally accountable for the timing and quality of breach disclosures, and the board accountable for the cyber risk oversight described in the 10-K. The ransomware wave, which made the CISO the person who decides whether to pay, whether to restore from backup, whether to shut down operations. The AI deployment wave, which made the CISO responsible for the security of systems the CISO did not build and often does not fully understand. The board exposure, which made the CISO the person who has to explain to the board, in plain English, why a breach happened and what is being done.

Each of these, individually, would have shifted the role. Together, they have transformed it. The 2018 CISO could not have done the 2026 CISO job. The 2026 CISO could not have been hired for the 2018 CISO job description. The skills are different, the relationships are different, the legal exposure is different.

The 2026 CISO profile

The 2026 CISO is, in most enterprises, a business operator with a technical background. The CISO still knows the tools, because the CISO has to be able to challenge the engineers and be challenged by them. The CISO is not, however, the person who runs the tools day to day. The CISO has a team for that. The CISO’s job is to set the strategy, manage the relationships, own the risk, and be accountable for the outcomes.

The 2026 CISO reports to the CEO, the COO, or the board, in most cases. The CISO is at the same level as the CIO, the CFO, the General Counsel, the head of HR. The CISO is in the room when the most important business decisions are made, including M&A, including product strategy, including vendor risk. The CISO informs what the business decides, not just secures it.

The 2026 CISO is also legally exposed in a way the 2018 CISO was not. The CISO is named in SEC filings. The CISO signs off on the cyber risk oversight disclosure. The CISO is, in the event of a material breach, the person who decided materiality, the person who decided disclosure timing, the person who is on the hook with the regulator. The legal exposure has changed the risk profile of the role, and the change has shifted the compensation, the candidates, and the conversation.

The compensation shift

Top of market CISO compensation in 2026 is roughly twice what it was in 2018. Total comp for a Fortune 500 CISO, including base, bonus, and equity, is now in the $1.5 million to $4 million range. The very top, including the financial services and tech sectors, exceeds $5 million. The compensation has moved, in a few years, from the senior director level to the C suite level. The companies that have not moved their compensation are losing their CISOs to the companies that have.

The compensation shift reflects the legal exposure shift, the board visibility shift, and the demand shift. The demand for senior security leaders is high, the supply is constrained, and the price has moved. The companies that want to retain a senior CISO in 2026 are paying C suite rates. The companies that want to pay director rates are getting director candidates.

The reporting structure shift

The CISO reporting line has moved up. In 2018, the CISO reported to the CIO in roughly 60% of enterprises. In 2026, the CISO reports to the CEO in roughly 40%, the COO in 20%, the board or a board committee in 15%, the CIO in 20%, the CFO in 5%. The remaining 10% are hybrid reporting lines, often CIO for operations and board for risk. The shift reflects the realisation, in the wake of several high profile breaches, that security cannot be a sub function of IT. The security function is a peer function. The CISO is a peer to the CIO.

The shift has consequences. The CISO at peer level has budget authority. The CISO at peer level has access to the board. The CISO at peer level can say no to business decisions on security grounds, with the authority of a peer. The 2018 CISO, reporting to the CIO, had to escalate through the CIO, and the CIO was often the obstacle. The 2026 CISO stands as the obstacle, in a healthy sense.

The legal exposure shift

The SEC’s 2023 rules, two years into enforcement, have made the CISO personally exposed in a way the role was not exposed before. The CISO becomes the person who certifies the cyber risk oversight disclosure. The CISO serves as the person who decides, in the moment, whether an incident is material. The CISO stands as the person whose name is on the internal documentation that supports the disclosure decision.

The exposure is real. Several CISOs have been personally named in SEC enforcement actions. Several have been required to pay personal penalties, separate from the corporate penalties. Several have been required to claw back compensation under the same provisions that apply to CEOs and CFOs. The CISO role, in 2026, carries personal financial and reputational risk that is comparable to the CFO role. The candidates who are willing to take that risk are scarce. The candidates who can do the job under that risk are scarcer.

What boards are actually looking for

The boards that are hiring the 2026 CISO well are looking for four things. The first is a track record of managing a security function through a real incident. The candidate who has been the CISO during a major breach, who has navigated the disclosure, who has led the remediation, who has come out the other side with the function and the company intact, that candidate is in demand. The boards have learned, in the last 5 years, that the CISO job is a crisis job. The candidate who has not been through a crisis has not been tested.

The second stands as the ability to talk to the board. The CISO has to explain, in plain English, what the security function is doing, what the risks are, what the gaps are, what the plan is. The CISO who can talk to the board without slides, who can answer questions without jargon, who can admit when the function is not where it should be, that CISO is in demand. The boards have learned that the CISO who cannot talk to the board sits as the CISO who cannot do the job.

The third sits as the ability to work with the legal team. The CISO has to coordinate with the General Counsel on disclosure, on regulator engagement, on litigation. The CISO who treats the legal team as a partner, who documents decisions, who can be deposed, that CISO is in demand. The boards have learned that the CISO who cannot work with legal runs as the CISO who will be a liability in a breach.

The fourth stands as the willingness to be personally accountable. The CISO has to sign the documents. The CISO has to be the name on the disclosure. The CISO has to be willing to be fired if the function fails, and the CISO has to be willing to be the public face of the response. The candidate who is willing to take the personal risk, in 2026, sits as the candidate the boards want.

The 12 month reality check

The CISO who was hired in 2024 and is still in the role in 2026 has, in most cases, survived the legal exposure shift, the board visibility shift, and at least one close call with a material incident. The CISO who was hired in 2025 and is still in the role in 2026 has survived the early SEC enforcement actions and the AI deployment pressure. The CISO who is being hired now is being hired with a different profile than the 2024 hire. The profile is shifting. The candidates are shifting. The compensation is shifting.

The boards that are still hiring for the 2018 CISO profile, with a director level compensation, with a CIO reporting line, with a focus on technical tools, are getting the 2018 results. The 2018 results, in 2026, are not good enough. The 2018 results are the breaches the SEC is enforcing on, the AI deployments that are leaking data, the boards that are asking the CISO questions the CISO cannot answer.

The boards that are hiring for the 2026 CISO profile, with C suite compensation, with a CEO or board reporting line, with a focus on business outcomes, are getting the 2026 results. The 2026 results are the breaches the SEC is not enforcing on, the AI deployments that are secure, the boards that have a CISO who can answer the questions.

The bottom line

The CISO job has changed. The candidates have not all caught up. The boards have not all caught up. The companies that are still hiring the 2018 CISO at 2018 compensation are getting 2018 results, and 2018 results, in 2026, are breaches. The companies that are hiring the 2026 CISO at 2026 compensation are getting 2026 results, and 2026 results are the only results that satisfy the SEC, the board, and the regulator.

The work for the board is to know which profile you are hiring. The work for the CISO candidate is to know which profile you are. The work for the security industry is to stop pretending the 2018 profile is enough. It is not.


Sources & Further Reading

All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.

Spotted an error? Email the editor. Corrections are issued with a visible correction note.

Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.

Continue reading