Skip To Content
Cyber-Security Has a Scapegoat Problem

Cyber-Security Has a Scapegoat Problem

CISOs are taking the blame for security failures they were never empowered to prevent – and it’s making everyone less safe

Illumio is a Business Reporter client.

Every CISO job description carries an unwritten clause: you will answer for decisions you were never allowed to make. The budget the CFO rejected; the control the business unit waived; the warning the board waved off – when those choices produce a breach, the buck stops at the security chief’s desk.

That reflex is what passes for accountability at most enterprises. But it isn’t accountability. It’s scapegoating dressed up as governance. And it’s putting organizations at risk.

The gap between the title and the power

Every board says cyber-security is a top priority. The budgets and reporting lines tell a different story.

A global survey of security chiefs by a leading executive search firm found that only 5 per cent of CISOs report directly to the CEO. Two-thirds sit two levels down, often under the CIO, negotiating for airtime at board meetings. A separate global survey of more than 4,000 business and technology executives found that fewer than half involve their CISO in strategic planning, board reporting, or technology deployments.

That means the person accountable for cyber-risk often isn’t even in the room when that risk is created.

The pressure runs the other way too. A 2024 global survey of 2,600 security leaders found that 79 per cent felt boardroom pressure to downplay cyber-risks. A third had their warnings dismissed out of hand. And 80 per cent believed their board would only act decisively after a breach. We may as well tell CISOs that the surest way to fund a security program is to fail at it. 

When it goes wrong, the CISO pays

The consequences are predictable and well documented. A 2025 ransomware study found that 25 per cent of organizations replaced or removed their security leader after a major incident, regardless of fault. In another survey of 200 enterprise CISOs, 77 per cent said they were very or extremely worried about losing their job after the next big breach. As one industry expert put it, firing the security officer after a breach is like blaming the fire chief because a homeowner disabled the smoke detectors.

The bill comes due in talent

Regulators have raised the stakes further. The SEC has charged a sitting CISO over a landmark supply chain breach. And one former security chief at a major tech company was criminally convicted for concealing an incident. New disclosure rules sharpen the exposure: the security chief signs the attestations, but the decisions behind them get made elsewhere. When the two diverge, guess who’s on the hook.

The security community has noticed. In one survey of security decision-makers, 70 per cent said high-profile liability cases soured their view of the CISO role. A separate 2025 pressure study found 87 per cent of security chiefs reported rising stress over the past year, with 44 per cent citing board and executive demands as their greatest stressor – ahead of the threats themselves. Not surprisingly, two-thirds report weekly or daily burnout. Some keep logs of every overruled recommendation, insurance for the day the inevitable breach arrives.

One CISO-turned-analyst called the arrangement “taxation with limited representation”. CISOs answer for security while committees make all the decisions. Small wonder seasoned leaders are heading for the exits. And when they go, they take years of institutional knowledge with them, leaving programs adrift for the months it takes to fill the seat.

What real authority looks like

The fix starts with boards matching rhetoric with structure.

Give the CISO a direct line to the CEO and a standing seat in board risk discussions. Put security in the room while decisions get made. Tie executive incentives across the C-suite to security outcomes, so accountability is shared rather than concentrated in one office. One influential analyst forecast predicted that by this year, half of C-level executives would have risk-related performance goals in their employment contracts.

And fund the mandate. Fund it fully. Fund it now. A widely cited annual breach-cost study found only 49 per cent of breached organizations planned to increase security spending post-breach – down from 63 per cent the year before.

The underfunding shows up exactly where you’d expect: in what teams can’t see. Ransomware research found that in 40 per cent of attacks, threat actors exploited a security gap the victim didn’t know it had. Visibility takes staff, tools and time – the line items trimmed first. Every unfunded project and unfilled vacancy is another crack in the resilience the CISO is still expected to maintain. When the breach becomes a disaster, the leaders who denied the budget will ask why the CISO failed to contain it.

Is the tide finally turning?

Regulation is pushing in the right direction. New US disclosure rules require public companies to report material incidents within days and explain how the board oversees cyber-risk. European directives impose duties, and potential personal liability, on boards and senior management. Directors can no longer claim ignorance after the fact.

And some companies are already rethinking their approach. After facing one of the biggest data theft incidents of the past decade, one credit-reporting giant rebuilt its security program with the CISO reporting directly to the CEO and the board. The incoming security chief called the change essential to the turnaround. In some cases, accountability has reached the top: the CEOs of a major US retailer and that same credit bureau both departed in the wake of major security failures.

That’s the right direction. If cyber-risk is business risk, then the leader who owns it needs the same standing as the leaders who own financial or operational risk. Anything less amounts to a succession plan for the next scapegoat.

A mandate to act starts with the ability to act: see how Illumio gives security leaders control over how far an attack can spread.

This article originally appeared in Business Reporter.

Image credit: Illumio