The Resignation That Didn’t Surprise Anyone Who Knew Her
She had been CISO for three years and four months.
In that time, she had built a security program from a spreadsheet and two junior analysts into a 22-person team with a $9.4 million annual budget. She had navigated two major compliance audits, one near-miss ransomware incident, three rounds of board presentations, and the ongoing, never-finished project of integrating the security stack from an acquisition that closed before she started.
She had also managed 58 vendor relationships, sat in 47 renewal conversations in the last 12 months, attended 3 security conferences where she was sold to by everyone she met, reviewed 340 open vulnerabilities across 11 different scanning platforms that didn’t talk to each other, and received 7 executive briefings about new threat categories that required “immediate attention.”
On a Thursday afternoon in February, she submitted a resignation letter that was four sentences long. No drama. No grievances. Just four sentences and a two-week notice.
Her deputy found her in the parking garage an hour later. He asked the question everyone asks when someone like her leaves: “Why? Things were going so well.”
She thought about it for a moment.
“I spent more time managing the tools than managing the risks,” she said. “I couldn’t tell you, with confidence, whether we were more secure than we were eighteen months ago. I just know we were busier. And I couldn’t do it anymore.”
She wasn’t burned out from too much security. She was burned out from too much noise disguised as security.
That’s a distinction the industry consistently fails to make — and it’s costing organizations some of their best security leaders at exactly the moment they can least afford to lose them.
The Numbers Behind the Crisis
CISO tenure has been declining for years. The average CISO now stays in role for 24 to 36 months — down from 4 to 5 years a decade ago — Heidrick & Struggles 2024. In high-pressure industries like financial services and healthcare, median tenure is even shorter.
The burnout data is starker:
- 65% of CISOs report experiencing significant burnout in 2025 — ISACA State of Cybersecurity 2025
- 42% of CISOs say they are likely to leave their current role within the next 12 months — Nominet Cybersecurity 2025
- 38% of CISOs report that managing the complexity of their security technology stack is a primary driver of their stress — ESG Research 2025
- The global cybersecurity workforce gap stands at 3.5 million unfilled positions — ISC2 2026 — meaning that every CISO who burns out and exits takes institutional knowledge that takes months to replace, in a market with no bench depth
These numbers are not a talent pipeline problem that can be solved by training more security professionals. They are a structural problem — a mismatch between what the CISO role has become and what any individual human being can sustainably execute.
And tool sprawl is at the center of it.
What the Modern CISO Role Actually Requires
The CISO role has expanded faster than any other C-suite position in the last decade. What was once primarily a technical leadership function has become simultaneously:
A technical leadership role — responsible for the architecture, operation, and effectiveness of a security program spanning endpoint, identity, cloud, network, application, and data domains, each with its own tooling, its own vendor relationships, and its own operational cadre.
A business leadership role — responsible for translating security risk into financial terms, building the board-level security narrative, navigating cyber insurance requirements, managing regulatory relationships across multiple jurisdictions, and making the case for security investment in language that non-technical executives can evaluate.
A compliance leadership role — responsible for maintaining compliance across an expanding set of frameworks — SOC 2, ISO 27001, PCI DSS v4.0, GDPR, CCPA, DORA, SEC disclosure rules — each with distinct requirements, distinct evidence collection processes, and distinct audit timelines.
A vendor management role — responsible for managing relationships with 45 to 70 security vendors simultaneously, each with their own renewal cycles, their own escalation paths, their own account team contacts, and their own competing claims on the security team’s attention.
A crisis management role — responsible for being available to respond to incidents at any hour, manage the organizational response under pressure, make regulatory notification decisions in real time, and communicate with executives and boards during the moments when the organization’s stress level is highest.
A people leadership role — responsible for recruiting in a market with 3.5 million unfilled positions, retaining analysts whose skills are in constant demand, managing burnout in a team that is itself under pressure, and building the culture that makes security a shared organizational capability rather than an isolated function.
No other C-suite role carries this breadth. The CFO doesn’t simultaneously manage technical infrastructure, vendor relationships at this scale, regulatory compliance across multiple jurisdictions, and crisis response. The CTO doesn’t carry the personal liability exposure that modern CISO roles carry — in the post-SEC disclosure rule environment, CISOs face personal accountability for decisions made under incomplete information in real-time crisis scenarios.
The CISO role has been expanded by accretion — each new responsibility added as the threat landscape evolved, as regulations multiplied, as tool counts grew — without a corresponding reduction in scope elsewhere.
The result is a role that is structurally unsustainable at the pace modern organizations expect it to run.
How Tool Sprawl Specifically Drives Burnout
Tool sprawl’s contribution to CISO burnout is not simply “more tools equals more work.” The mechanism is more specific — and more damaging — than that.
It Creates Irresolvable Accountability Without Control
A CISO is accountable for the security outcomes of every tool in the stack. When a breach occurs, the question “why didn’t your tools catch this?” lands on the CISO — regardless of whether the tool that missed was well-configured, whether it had a named owner who actively managed it, or whether it was one of the zombie tools that nobody had opened in eight months.
The accountability is absolute. The control is not.
A CISO managing 58 vendor relationships cannot meaningfully verify that every tool is configured correctly, operating effectively, and covering the coverage it was purchased to provide. The math doesn’t allow it. But the accountability structure doesn’t acknowledge the math.
The CISO is responsible for the outcome of everything in the stack — including the tools nobody is actually managing — and has no realistic mechanism to verify the operational state of all of them simultaneously. That gap between accountability and control is a specific, sustained source of executive stress that has no resolution as long as the stack remains at its current scale.
It Makes Progress Unmeasurable
One of the most consistent findings in CISO burnout research is the role of meaninglessness — the sense that the work being done doesn’t produce visible, measurable progress toward a defined objective.
Tool sprawl is a primary driver of this experience. When the security program has 58 tools, each generating its own alerts, its own findings, its own metrics, and its own vendor narratives about the threats it’s addressing — synthesizing all of that into a coherent, honest answer to “are we more secure than we were a year ago?” is genuinely difficult.
The CISO who cannot answer that question confidently — not because the program isn’t working, but because the measurement infrastructure across 58 tools doesn’t produce a coherent picture — is in the position of working extremely hard at something they cannot demonstrate is producing results.
That experience — high effort, invisible progress — is the psychological profile of burnout. It’s not the intensity of the work that burns people out. It’s the combination of intensity and meaninglessness. Tool sprawl produces both.
It Generates Constant Context-Switching at the Highest Stakes Level
Executive-level attention is finite. A CISO managing 58 vendor relationships is distributing their finite attention across 58 renewal cycles, 58 account team relationships, 58 sets of product roadmap conversations, and 58 separate escalation paths when something goes wrong.
This context-switching doesn’t happen at low stakes. Every vendor conversation carries some implication for the security program. Every renewal decision carries some career risk. Every incident that implicates a specific tool triggers a response that requires the CISO to simultaneously manage the technical response, the executive communication, and the vendor relationship all at once.
Constant context-switching at high stakes is cognitively exhausting in a way that sustained focused work is not. The CISO who could work effectively on a complex, deep security problem for eight hours finds the same eight hours fragmented across fourteen vendor calls, twenty-three Slack escalations, and three board updates unsustainable — because the cognitive load of context-switching vastly exceeds the cognitive load of equivalent time spent on focused work.
It Creates Inescapable Personal Liability With No Clear Resolution Path
The post-SolarWinds, post-Uber CISO conviction, post-SEC disclosure era has fundamentally changed the personal liability profile of the CISO role. CISOs are now personally accountable — in ways that can include individual SEC enforcement action — for the accuracy of their organizations’ public statements about security posture and for the timeliness of their incident disclosures.
This accountability lands on the individual even when the failures that triggered it were organizational — a missed tool configuration, an incomplete asset inventory, a contractor account outside the primary identity system’s scope. The CISO didn’t fail. The program’s complexity made the failure invisible until the breach revealed it.
The CISO who is personally liable for the failure modes of a 58-tool stack they cannot fully verify is carrying personal risk that cannot be resolved through effort alone — because the stack’s complexity inherently exceeds any individual’s ability to verify every component at the resolution required to be confident that no component is creating undisclosed liability.
This irresolvable personal risk is a specific and severe driver of executive attrition. It’s not that CISOs are unwilling to accept accountability. It’s that they’re accepting accountability for outcomes they cannot control — in a market where the personal consequences of that gap are increasingly real.
The Organizations That Are Retaining Their CISOs
The organizations that retain CISOs for four or more years — well above the current median — share characteristics that have less to do with compensation and more to do with how the role is structured and supported.
They Have Rationalized the Stack to a Manageable Scale
CISOs who can tell you, with confidence, what every tool in their stack does, who owns it, and what evidence exists of its effectiveness are CISOs who have the control that the accountability requires. That confidence comes from a stack that is small enough to be genuinely managed — not one that has accumulated to the point where full visibility is structurally impossible.
Organizations that have conducted rigorous tool rationalization exercises — reducing from 60+ tools to 25–35 well-integrated, fully utilized tools — report meaningfully improved CISO satisfaction alongside the better security outcomes. The connection is direct: a manageable stack allows the CISO to exercise genuine oversight rather than nominal accountability.
They Have Built the Measurement Infrastructure That Makes Progress Visible
The CISO who can show the board — with evidence — that MTTD has decreased from 60 days to 12 days over the last 18 months, that ATT&CK detection coverage has expanded from 41% to 73% of relevant techniques, and that the remediation backlog on critical findings has been cut from an average age of 94 days to 11 days, is a CISO who can see and demonstrate meaningful progress.
That visibility is not just a board communication tool. It’s a psychological anchor — the evidence that the work is producing outcomes, that the program is moving in the right direction, that the effort is connected to a result.
Organizations that have built outcome measurement infrastructure retain CISOs longer because they’ve given their CISOs the ability to know they’re winning — not just working.
They Have Distributed Security Accountability Across the Organization
The CISO who is the sole accountability point for security across the entire organization carries a structural burden that no one person can manage sustainably. Organizations that distribute security accountability — through DevSecOps cultures, through security champion programs, through shared security OKRs across dev, ops, and security — give their CISOs a team that is collectively accountable for outcomes rather than a single executive absorbing all accountability alone.
This is not accountability dilution. It’s accountability architecture. The CISO is still responsible for the security program’s strategy and effectiveness. They are no longer personally responsible for every security-relevant decision made by every developer, operations engineer, and procurement manager in the organization — because those decisions are made with security context embedded in the process, not added afterward as CISO review gates.
They Have Drawn a Clear Line on Personal Liability
Organizations serious about retaining CISOs in the post-SEC disclosure era have become explicit about where personal liability begins and ends — through documented authority structures, through D&O insurance that specifically covers security leadership decisions, through legal counsel involvement in major security decisions, and through board-level governance that makes the CISO’s authority and accountability commensurate.
CISOs who know exactly what decisions they own, what authority they have to make those decisions, and what organizational protections exist for good-faith decisions made under uncertainty are in a fundamentally more sustainable position than CISOs who carry unlimited liability with ambiguous authority.
What the Departure Costs
Organizations that lose experienced CISOs to burnout typically underestimate the true cost of the departure — because many of the costs are invisible until they materialize.
Direct replacement costs: Executive search fees for CISO-level roles typically run $80,000–$150,000. The search process takes 4–8 months for a qualified candidate — and in a market with 3.5 million unfilled positions, “qualified” is doing significant work.
Institutional knowledge loss: The departing CISO carries years of context about why specific tools were purchased, why specific architectural decisions were made, what the failure modes of the current stack are, and what the organization’s most important unaddressed risks are. That knowledge is not in any document. It leaves with the person.
Program momentum loss: Security programs require sustained, consistent leadership to maintain their development trajectory. A 4–8 month CISO search, followed by a 3–6 month onboarding period before the new CISO has enough context to make major decisions, represents 7–14 months of reduced security program development velocity — at a time when the threat landscape is not slowing down.
Vendor relationship disruption: 45–70 vendor relationships, each with their own account team contacts and their own expectations of the CISO relationship, need to be re-established with the new hire. Some vendors use the transition period to renegotiate contracts, reposition products, or introduce new requirements. The transition creates a window of reduced organizational leverage in every vendor negotiation.
Team stability impact: The departure of a respected CISO is frequently a signal to the security team that something about the organization isn’t working. Key team members who were retained because of their loyalty to the departing leader begin evaluating their own options. CISO departures have a documented correlation with elevated team attrition in the 6–12 months that follow.
Total cost of a CISO departure: Conservatively, $500,000–$1.5 million in direct and indirect costs when the full impact is accounted for. For organizations in the middle of major security programs, regulatory engagement, or incident response, the cost can be substantially higher.
The Conversation That Needs to Happen Before the Resignation Letter
Most CISO burnout is visible — to the CISO, to their team, and to anyone paying attention — months before the resignation letter. The signals are consistent: the CISO who stops advocating for program improvements because they’ve stopped believing the advocacy will produce change. The CISO who begins delegating increasingly important decisions to avoid the personal liability exposure of making them. The CISO who stops developing professionally because they don’t have the cognitive bandwidth for learning on top of the current operational load.
These signals invite a specific conversation — one that most boards and CEOs don’t know to have until it’s too late.
The conversation is not “how do we keep you from quitting?” It’s “what would make this role sustainable for you and for the organization?” The answers consistently cluster around the same themes: clearer authority boundaries, reduced tool management overhead, measurement infrastructure that makes progress visible, distributed security accountability, and personal liability protections that are commensurate with the accountability the role carries.
None of these require replacing the CISO. They require redesigning the role around what it actually takes to be effective in it — rather than assuming that the right person, under enough pressure, can make the current design work indefinitely.
The Bottom Line
CISOs are not quitting because cybersecurity is too hard. They are quitting because the role has been allowed to become structurally unsustainable — bloated with vendor relationships, unmeasurable in its outcomes, exposed to irresolvable personal liability, and accountable for the operational state of tool stacks that no individual can realistically verify.
The burnout crisis is not a people problem. It’s a program design problem. And it manifests most visibly in the CISO — the person at the intersection of every structural failure the program contains — before it manifests anywhere else.
Fixing it requires the same discipline that fixes every other security program failure in this series: honest measurement of what the current design actually produces, honest acknowledgment of what it costs in human terms, and the organizational will to make the structural changes that convert an unsustainable role into one that excellent people will stay in for the four or more years it takes to build security programs that actually work.
The resignation letter is not the problem. It’s the symptom.
The problem started long before Thursday afternoon in February — the moment the 58th tool was added to a stack that was already too large to manage, and nobody decided that something had to go.
Your Next Move
CISO burnout and tool sprawl are two symptoms of the same structural problem — a security program that has grown by accumulation rather than by design.
→ Read next: The Security Vendor Extortion Wheel: Why You’re Paying 10 Dashboards to Do the Same Job — the market dynamics that produce the tool sprawl that’s driving the burnout, and the procurement discipline that breaks the cycle.
→ Is your security program’s structure sustainable for the people running it? A security program design assessment evaluates not just your tools and controls but the organizational architecture that determines whether your security leadership can do their job effectively — and stay long enough to make it matter. Let’s talk.
