Desk live·
ForensicPost
Breaches/Workforce/File 25-0428

Organisations Report Difficulty Filling CISO Roles and No Successors in Place

Reporting on 2025 describes difficulty getting people to accept or remain in CISO roles, and organisations that have stopped developing successors.

Constructed geometry · not a chart of case data
TargetSecurity leadership
ActorUnattributed
S. Rosler11 min readConfidence: low1 source reviewed

Commentary through 2025 describes persistent difficulty in getting people to accept or stay in chief information security officer roles, and observes that organisations are largely not developing people into them.

The Role Carries Personal Exposure The Salary Does Not Price

A CISO is accountable for outcomes largely determined by decisions made elsewhere: budget set by a finance function, architecture inherited over decades, suppliers selected by procurement, and a workforce that will click things.

The disclosure files at 26-0403 and 26-0415 record what follows an incident — regulatory attention, litigation, and in some jurisdictions personal consequences. Responsibility without proportionate authority is a recognisable and unattractive position.

Succession Is Not Being Built Because The Role Is Not A Step

Most executive functions have a pipeline: deputies who do part of the job and eventually do all of it. Security leadership frequently does not, because the layer below is technical specialists whose work does not resemble the CISO’s, which is largely persuasion, budgeting and board communication.

So organisations hire externally, which transfers a person and destroys the institutional knowledge that 25-0219 identifies as the thing that actually makes a team effective.

Graded Low, And Why It Is Filed Anyway

This rests on commentary rather than measurement. This desk has no tenure data, no vacancy duration, no comparison against other executive roles.

It is recorded because it is the leadership counterpart to the staffing files, and because the absence of measurement is itself the finding: the discipline that keeps demanding organisations quantify their risk does not measure the stability of the function that owns it.

How we reported this

Compiled from published commentary, listed below. No tenure or turnover data was available in the material we reviewed and none is asserted. Corrections: corrections@forensicpost.com.

Sources
  1. Cyber staffing shortages remain CISOs’ biggest challenge in 2025Fortray
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary