Commentary through 2025 describes persistent difficulty in getting people to accept or stay in chief information security officer roles, and observes that organisations are largely not developing people into them.
The Role Carries Personal Exposure The Salary Does Not Price
A CISO is accountable for outcomes largely determined by decisions made elsewhere: budget set by a finance function, architecture inherited over decades, suppliers selected by procurement, and a workforce that will click things.
The disclosure files at 26-0403 and 26-0415 record what follows an incident — regulatory attention, litigation, and in some jurisdictions personal consequences. Responsibility without proportionate authority is a recognisable and unattractive position.
Succession Is Not Being Built Because The Role Is Not A Step
Most executive functions have a pipeline: deputies who do part of the job and eventually do all of it. Security leadership frequently does not, because the layer below is technical specialists whose work does not resemble the CISO’s, which is largely persuasion, budgeting and board communication.
So organisations hire externally, which transfers a person and destroys the institutional knowledge that 25-0219 identifies as the thing that actually makes a team effective.
Graded Low, And Why It Is Filed Anyway
This rests on commentary rather than measurement. This desk has no tenure data, no vacancy duration, no comparison against other executive roles.
It is recorded because it is the leadership counterpart to the staffing files, and because the absence of measurement is itself the finding: the discipline that keeps demanding organisations quantify their risk does not measure the stability of the function that owns it.
Compiled from published commentary, listed below. No tenure or turnover data was available in the material we reviewed and none is asserted. Corrections: corrections@forensicpost.com.