CISO Burnout: What UK CISOs Must Fix to Protect Resilience
UK CISOs must treat burnout as an operational resilience risk, not a wellbeing footnote: sustained overload is now measurably degrading the security function’s ability to defend the organisation.
Cambridge Judge Business School’s research on the CISO role concludes that its responsibilities have expanded so rapidly that the position risks becoming unsustainable, undermining exactly the resilience it exists to protect. This lands at the same moment the Cyber Security and Resilience (Network and Information Systems) Bill is progressing through Parliament, expanding regulatory expectations on critical infrastructure providers. A burned-out, understaffed security function is a poor foundation for meeting that bar.
How Widespread Is CISO Burnout?
According to Proofpoint’s Voice of the CISO report, 63% of CISOs experienced or witnessed burnout in the past year. Bitsight’s separate survey of over 1,000 risk and security professionals found 47% reporting some level of burnout, with more than one in ten describing their condition as acute — either very burned out or on the verge of leaving the profession altogether. These are not isolated findings: Gartner research puts the figure at 62% of cybersecurity leaders who have personally experienced burnout at least once, with 44% reporting multiple instances.
Executive Action:
- Run an anonymous burnout and workload survey across the security function this quarter, not annually.
- Benchmark security team headcount and on-call load against comparable organisations, not just budget history.
What Is Actually Driving the Burnout?
ISACA’s 2025 research found that too many responsibilities was cited by 65% of professionals as one of the biggest contributors to burnout, alongside a culture of working late nights and weekends, cited by 62%. The underlying issue is scope creep: CISOs are now expected to own technical security architecture, board reporting, regulatory liaison, third-party risk, and increasingly AI governance, often without a corresponding increase in team size or decision-making authority. Sixty-six percent of professionals say the role is more stressful than five years ago, and 47% cite high stress as the leading reason people leave the profession.
Executive Action:
- Map every responsibility currently sitting with the CISO and identify which can be delegated or shared with a named deputy.
- Separate the CISO’s technical security remit from board and regulatory reporting duties where the same person currently holds both.
- Use INFORMD’s project review checklist to identify which security initiatives can be paused or resourced differently.
Why Does This Threaten Operational Resilience Directly?
Regulators increasingly treat cybersecurity as a resilience obligation rather than a pure IT discipline, expecting organisations to demonstrate that controls work under pressure, not merely that they exist on paper. A burned-out security team is more likely to miss alerts, delay patching, and make poor incident-response decisions under stress — precisely the failure modes that operational resilience frameworks, including emerging expectations aligned with NIS-style regulation and ISO 27001 certification maintenance, are designed to prevent. Treating CISO wellbeing as separate from resilience planning misses where the actual risk sits.
Executive Action:
- Include security team capacity and wellbeing metrics in the operational resilience risk register, not just system uptime.
- Test incident response drills under realistic fatigue conditions, not only during business hours with a full team.
How Should CISOs Redesign Their Own Role to Sustain It?
CISOs cannot solve burnout alone by working harder or longer; the fix is structural. That means building a genuine deputy structure with real decision rights, formally declining new mandates that arrive without matching resource, and pushing board reporting toward a cadence that doesn’t require constant ad hoc preparation. NCSC guidance increasingly emphasises organisational resilience over individual heroics, and CISOs should use that framing to justify structural change rather than accepting an ever-expanding personal remit.
Executive Action:
- Appoint and empower a formal deputy CISO with genuine decision-making authority, not just an administrative backup.
- Set a fixed, predictable board reporting cadence rather than responding to ad hoc requests that disrupt operational work.
What Should the Board Do to Support the Security Function?
Supporting the CISO role sustainably is a genuine board-level responsibility: approving adequate security team resourcing, and requiring management to report on security team retention and burnout indicators alongside technical risk metrics. A board that only ever asks “are we secure” without asking “is the team sustaining this” is underwriting a resilience gap it cannot see until an incident exposes it.
Executive Action:
- Require the board risk committee to review security team retention and burnout indicators annually alongside technical risk reporting.
- Approve resourcing increases for the security function ahead of new regulatory obligations, not reactively after a near miss.
INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library or access our free assessment tools.
Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk.
According to Proofpoint’s Voice of the CISO report, 63% of CISOs experienced or witnessed burnout in the past year. Bitsight found 47% reporting some level of burnout, with over one in ten describing their condition as acute.
ISACA research found 65% of professionals cite having too many responsibilities as a leading contributor, alongside a culture of working late nights and weekends, cited by 62%. Role scope has expanded without matching resource or authority.
Burned-out security teams are more likely to miss alerts, delay patching, and make poor decisions under incident pressure, undermining the resilience regulators increasingly expect organisations to demonstrate under real conditions.
Boards should require regular reporting on security team retention and burnout indicators alongside technical risk metrics, and approve resourcing increases ahead of new regulatory obligations rather than reactively after an incident.
