Half of CISOs say AI advances are pushing them toward the exit

A new survey finds one in two chief information security officers is weighing leaving the profession, as fast-moving AI tools and growing personal legal exposure make the job feel untenable.

ThreatVectr Newsdesk· 4 min read
Full-frame edge-to-edge photoreal news-editorial image of a modern laptop screen showing an abstract browser window with a glowing extension icon in the toolbar
Share

Key points

  • 50% of 1,001 CISOs surveyed in the US and UK said the rise of advanced AI models has made them consider leaving the profession.
  • 60% said board pressure to adopt AI is outpacing their organisation's ability to keep that AI safe.
  • 78% of CISOs are concerned about personal legal liability for security incidents, up from 56% a year ago.
  • The average CISO tenure now sits at 18 months, according to IDC analyst Chris Kissel.

Who are CISOs and why does their burnout matter?

A chief information security officer, or CISO, is the executive responsible for keeping a company's data and computer systems safe from attack. When they burn out and leave, companies scramble to replace them, often with less experienced people, and the security gap in between can be costly.

A survey of 1,001 CISOs in the United States and United Kingdom, reported by CSO Online, found that exactly half agreed that powerful new AI models, specifically Anthropic's Mythos and similar tools, had caused them to consider quitting the profession. Only a quarter disagreed.

The numbers behind that figure are striking. Six in ten CISOs said their boards were pushing them to roll out AI faster than the organisation could safely manage it. Meanwhile, personal liability concerns have spiked sharply: 78% of CISOs now worry about being held personally responsible if a breach happens on their watch, up from 56% just one year ago.

What is it about AI that's making things worse?

AI is giving criminals a speed advantage. Criminals are now finding and weaponising software flaws, weaknesses in programs that can be exploited to break in, sometimes before the company that makes the software has even published a fix.

"As fast as AI evolves, the benefit is with the attacker right now," said Christine Gadsby, chief security advisor at BlackBerry and the company's former CISO. "Attackers are weaponizing vulnerabilities as fast as they can find them, sometimes even sooner than the fix is published."

At the same time, boards want their companies experimenting with AI quickly. That pressure lands on the CISO, who is expected to secure tools their organisation is still learning to use.

Pressure point Share of CISOs affected
Considering leaving due to AI advances 50%
Board pressure outpacing AI governance 60%
Concerned about personal legal liability 78%
Challenged by pace of technology change 89%

What does this mean for ordinary people?

Experienced security leaders leaving means companies are hiring greener replacements, and the handover period is a vulnerable window. Every enterprise IT environment is different, so a new CISO needs months to understand the organisation before they can defend it well.

For customers, patients, or anyone whose data a company holds, a depleted security leadership bench raises the risk that a breach goes undetected longer or is handled less smoothly.

Oliver Legg, a cybersecurity recruiter at Aspiron Search, said candidate priorities have shifted sharply. Two years ago, prospective CISOs asked about budget. Now their first questions are about indemnification and directors and officers insurance, which is a policy that protects business leaders from personal financial losses if they face lawsuits over decisions made at work.

Is there a way through this?

Experts say yes, but it requires structural change. IDC analyst Chris Kissel argues that a governing body setting minimum standards for responsible security behaviour, and formally protecting CISOs who meet those standards from personal legal exposure, could ease the liability crisis.

Omar Khawaja, who teaches at Carnegie Mellon University and serves as global field CISO at Databricks, says AI itself can help CISOs do more with less, provided organisations start with lower-stakes uses. Using AI to spot unusual activity in systems or sort through existing security alerts is manageable. Automating the response to attacks from day one is not.

Mike Privette, founder of Return on Security and a former CISO, adds that many security leaders remain energised by the challenge. "For many people, this is one of the most exciting times to be operating in the field," he said. The key variable is whether the CISO has genuine executive support and budget to match the mission.

© 2026 Threat Vectr