The CISO Resignation Letter

The CISO resignation letter has become a genre. The reasons are depressingly consistent: not enough authority, not enough budget, not enough board attention, then a breach, then a quiet exit. The pattern repeats because the role has not been fixed.…

A single fountain pen on a dark wood surface next to a folded piece of paper, dim warm amber side light, deep navy shadows, no people visible.

The CISO resignation letter has become a genre. The reasons are depressingly consistent: not enough authority, not enough budget, not enough board attention, then a breach, then a quiet exit. The pattern repeats because the role has not been fixed, and the resignation serves as the symptom, not the cause. The enterprise that treats the resignation as the HR problem will hire the next CISO into the same trap. The enterprise that treats the resignation as the organisational problem has a chance of keeping the next CISO.

The honest framing matters here, because the CISO who is set up to fail will fail, and the failure will land on the CISO, and the next CISO will get the same setup. The cycle ends when someone at the executive level decides it should end.

What the letters actually say

Three things, in roughly that order of how often each one shows up. The first runs as the personal reasons, with the letter citing the family, the health, the opportunity, the personal framing that lets the CISO leave without burning the bridge, the language that protects the relationship with the executive team. The personal reasons are real. They are also the safe version of the truth. The second runs as the strategic misalignment, with the letter citing the gap between the security vision and the executive appetite, the language about needing a different kind of organisation, the framing that says the CISO is too ambitious for the company without saying the company is not serious about security. The third runs as the breach exhaustion, with the letter citing the weight of the last incident, the postmortem cycle, the regulatory follow up, the insurance claim, the burnout that comes from running the marathon on no sleep.

What the letters do not say

Three things, in roughly that order of how much each one matters for the next hire. The first runs as the budget refusal, where the letter does not say that the board approved the security budget that was a third of the peer benchmark, the letter does not name the specific initiative that the CFO blocked, the letter does not list the headcount that the HR denied. The next hire walks into the same budget, the same block, the same denial. The second runs as the peer pressure, where the letter does not say that the CEO compared the security spend to the marketing spend at every quarterly review, the letter does not name the board member who asked why the security team was bigger than the sales team, the letter does not describe the conversation where the CISO was told to “just say no to the auditors.” The third runs as the breach blame, where the letter does not say that the CISO was the one who signed off on the configuration that the breach exploited, the letter does not say that the executive team had rejected the fix the CISO had proposed eighteen months before the breach, the letter does not say that the CISO was asked to take the fall for the executive decision. The next hire walks into the same breach risk, the same executive decision, the same fall waiting to happen.

How to stay

Three moves if you are the CISO who wants to keep the job past the second year and is honest about the cost. Negotiate the authority before the signature, because the CISO who takes the job without the direct line to the CEO, the veto on the security budget, the authority to hire the team, is taking the job that has already failed. The negotiation that happens at the offer sits as the negotiation that has the most use, the negotiation that happens after the breach sits as the negotiation that is too late. Build the executive sponsorship that does not depend on you, because the CISO who counts as the only person in the building who cares about security will burn out in eighteen months, the CISO who has the CEO, the CFO, the general counsel as the active allies will survive the next breach. Document the refused risk, because the CISO who proposed the fix and was told no has the documentation that protects them when the fix becomes the breach, the documentation that lives in the email archive, the board deck, the audit log, the CISO who has the documentation has the career after the breach. The CISO who negotiates, builds the sponsorship, and documents the refused risk serves as the CISO who holds the job long enough to matter.

Abstract resignation as glowing cyan fading signature on a dark navy surface, dramatic chiaroscuro lighting from above.
The CISO resignation letter in 2026: 3 things the letters say, 3 things the letters do not say, 3 moves to stay.

The bottom line

The CISO resignation letter in 2026 serves as the symptom of the organisational problem, not the cause. The next hire walks into the same trap unless the executive team decides to fix the role, not the resume. The CISO who wants to stay negotiates the authority, builds the sponsorship, documents the refused risk. The one who skips the three moves writes the next letter.

Sources & Further Reading

All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.

Spotted an error? Email the editor. Corrections are issued with a visible correction note.

Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.

Continue reading