The CISO’s Dilemma: Accountability Without Authority, Regulation Without Capacity

In Part 1 of this series, we examined why the boardroom, not the security operations centre, is where most organisations’ cyber resilience breaks down. Board ownership of cyber risk is declining. Budgets are tightening. And the person expected to absorb all of it is the CISO.
This instalment looks at the reality from the CISO’s side of the table. Two pressures, in particular, are reshaping the role faster than most organisations have acknowledged.
The first: "I am accountable for risk I do not fully control."
The second: "Regulation is increasing faster than we can operationalise it."
Both are structural. Neither can be solved by hiring one more person or buying one more tool.
The Accountability Trap
I speak to CISOs regularly who describe the same dynamic. They own the security risk register. They present to the board. They sign off on incident response. But they do not control the infrastructure, the procurement decisions, the cloud migration roadmap, or the headcount allocation that determines whether any of their plans are executable.
The infrastructure sits under IT. The cloud strategy was driven by the CTO. The workforce training budget was decided by HR. The third party vendor was onboarded by procurement without a security review. And when something goes wrong, the first name on the incident report is the CISO’s.
IANS Research captured this gap in their 2025 State of the CISO report. Only 11% of CISOs report being sufficiently staffed. 89% describe themselves as stretched thin or operating below minimum viable capacity. Just 47% received a budget increase this year, down from 62% in 2024 and 78% in 2022. Average security budget growth has dropped to 4%, a five year low. Security’s share of IT spend fell from 11.9% to 10.9%.
The expectation on the CISO is growing. The resources are moving in the opposite direction. And the person in the middle absorbs the difference.
When It Goes Wrong, the CISO Pays Personally
The legal precedents of the past three years have made this imbalance significantly more dangerous.
In 2022, Uber’s former Chief Security Officer, Joe Sullivan, was convicted of obstruction of justice and failure to report a crime after concealing a 2016 breach that exposed data from over 50 million riders and 600,000 drivers. He did not cause the breach. He managed it the way the company’s leadership expected him to. He was the one who faced criminal charges.
Then SolarWinds. The SEC pursued its CISO, Timothy Brown, for securities fraud related to how the company described its security posture to investors. While the court dismissed most of the claims in July 2024, the signal to the market was unmistakable: the CISO is now personally on the hook for how risk is communicated externally, not just how it is managed internally.
The Berkeley Technology Law Journal published a piece earlier this year titled "The Security Scapegoat." The framing captures what many CISOs already feel. Liability is increasing. Authority is not keeping pace. And 93% of organisations have already begun changing their internal liability policies in response.
Proofpoint’s 2025 Voice of the CISO report found that 63% of cybersecurity leaders have experienced or witnessed burnout among their peers in the past year. Sophos put the figure at 76%. Just 34% of cybersecurity professionals plan to stay in their current role.
This is not a wellbeing issue. It is an enterprise risk. When a CISO leaves, the organisation loses six to nine months of continuity. IBM’s 2025 data shows that organisations with high security staffing shortages face average breach costs of $5.74M, versus $3.98M for those without. The $1.76M gap is the price of not addressing the structural pressures driving people out of the role.
The Regulatory Collision
The second pressure reshaping the CISO’s world is the sheer volume and velocity of regulation arriving simultaneously.
Consider what has landed in the past 18 months alone.
NIS2 came into force across the European Union in October 2024. It embeds personal liability for management body members, requires incident notification within 24 hours, and expands the scope of regulated entities to include supply chain providers, managed services, and digital infrastructure operators. First administrative penalties were issued in Q1 2026. Most member states are still finalising transposition, meaning CISOs are trying to comply with a framework whose national interpretation is not yet settled.
DORA took full effect in January 2025 across twenty categories of EU financial entity. It requires boards to approve ICT risk management frameworks, mandates regular threat led penetration testing, and imposes direct oversight on critical third party technology providers. For financial services CISOs, this arrived on top of everything else, not instead of it.
The EU AI Act enters its main application phase in August 2026. Any organisation deploying high risk AI systems must demonstrate governance, risk assessment, and ongoing monitoring that, in many cases, falls squarely on the CISO’s desk.
In the United Kingdom, the Cyber Security and Resilience Bill is expected to receive Royal Assent in late 2026. It brings approximately 2,500 managed service providers, data centres, and SOCs into regulatory scope. It places the NCSC’s Cyber Assessment Framework on a statutory footing and tightens incident reporting to 24 hours for initial notification and 72 hours for a full report.
The UK Cyber Governance Code of Practice, published by DSIT in April 2025, adds five governance pillars that boards are expected to implement. Voluntary for now. But DSIT has been explicit: mandatory enforcement will follow if uptake is insufficient.
And the SEC’s four day material incident disclosure rule, effective since December 2023, means CISOs in US listed organisations are simultaneously managing European and American disclosure obligations that operate on different timelines and different definitions of materiality.
The issue is not that CISOs are unaware of these requirements. They are deeply aware. The issue is capacity. ENISA’s 2025 analysis concluded that NIS2 compliance is structurally impossible to achieve through human capital alone. The European Union faces a deficit of 299,000 skilled cybersecurity professionals. The UK has the widest workforce gap in Western Europe, with demand growing 27.1% while the workforce contracted 4.9%.
CISOs are being asked to operationalise four or five major regulatory frameworks simultaneously, with teams that were already too small before any of them arrived.

The Structural Mismatch
These two pressures compound each other.
The CISO who is accountable for risk without controlling the systems, the budgets, or the people is the same person being asked to stand up compliance programmes across NIS2, DORA, the AI Act, and the UK Cyber Governance Code. They are doing this with flat or shrinking resources, in an environment where personal liability for failure is now embedded in law, and where the average tenure in the role is 39 months.
Gartner’s research shows that 88% of boards now recognise cybersecurity as a business risk. That is progress. But recognition without investment is performative. The same boards acknowledging cyber as a strategic risk are approving budgets that make it harder to manage.
Heidrick and Struggles’ 2025 data shows that 42% of CISOs now report directly to the CEO, up from roughly 14% the year before. Three in five present to the full board. Reporting lines are improving. Compensation is increasing, with average total packages reaching $700,000 at large enterprises and $1.1M at organisations above $20B in revenue.
But neither a better reporting line nor a higher salary resolves the fundamental problem. The role has expanded beyond what one person, or even one internal team, can sustainably deliver.
What This Means for the Board
The CISO’s dilemma is not the CISO’s problem alone. It is the board’s problem.
If the person accountable for your security posture, your regulatory compliance, and your incident response does not have the authority, the budget, or the team to deliver on those responsibilities, the board has not delegated risk. It has concentrated risk in a single point of failure.
In Part 3, we will examine the third pressure facing today’s CISOs, the tension between business speed and security friction, and lay out what organisations can do to resolve all three.
At Garzon Cyber Solutions, we work with boards and CISOs to close the gap between accountability and authority. From CISO advisory and board level risk translation to compliance readiness across NIS2, DORA, the EU AI Act, and the UK Cyber Governance Code, we provide the strategic intelligence that turns cybersecurity leadership from an operational burden into a strategic advantage.
The CISO cannot carry this alone. The board has to meet them halfway.
Sources: IANS Research and Artico Search, State of the CISO 2025 · Hitch Partners, 2025 CISO Security Leadership Survey · Heidrick and Struggles, 2025 Global CISO Compensation Survey · Proofpoint, 2025 Voice of the CISO Report · Sophos, The Human Cost of Vigilance 2025 · IBM, Cost of a Data Breach Report 2025 · Gartner, Board of Directors Survey on Cybersecurity 2025 · ENISA, 2025 NIS Investments Report · DSIT, Cyber Security Skills in the UK Labour Market 2025 · DSIT and NCSC, Cyber Governance Code of Practice, April 2025 · UK Parliament, Cyber Security and Resilience Bill 2024/26 · European Commission, NIS2 Directive (EU 2022/2555) · European Commission, Digital Operational Resilience Act (EU 2022/2554) · European Commission, EU AI Act (EU 2024/1689) · SEC, Final Rule on Cybersecurity Incident Disclosure, December 2023 · SEC v. SolarWinds Corp. and Timothy Brown, Case Ruling July 2024 · United States v. Joseph Sullivan, Uber CISO Conviction 2022 · Berkeley Technology Law Journal, The Security Scapegoat 2025 · Garzon Cyber Solutions, CISO Advisory Intelligence, 2026
Where does this sit on your own risk register?
A short, practical conversation about where the exposure actually is, and what a proportionate response looks like. No obligation and no product pitch.
Start the Conversation →