GCS Talent Briefing
Careers & Hiring

The Board Sets the Notice Period

G
Jonathan Garzon
Founder & CEO, Garzon Cyber Solutions
22 September 2026 · 7 min read
GCS Talent Briefing cover: The Board Sets the Notice Period. Dark brand panel with the headline in white and red and a standfirst explaining that only 34% of security professionals plan to stay with their employer, and that the sharpest divide in how they feel about the job is whether they believe the organisation treats security as a priority.

Most retention conversations about security teams start in the wrong room. They begin with HR, move to a salary benchmark, and end with a counter-offer made after the resignation letter has arrived. By then the decision has usually been made, and it was shaped by signals the board sent without realising it was sending them.

The evidence published this year points somewhere less comfortable. Few factors separate satisfied security staff from dissatisfied ones as sharply as their perception of how seriously the organisation takes security. That perception is built from a small number of observable behaviours: who the security leader gets to speak to, whether resources follow the risks the board has agreed, whether there is anywhere to progress, and whether anyone above the security function owns the outcome. Each of those behaviours sits with the board.

What the data says

The IANS and Artico Search 2026 Cybersecurity Talent Report, published on 14 April 2026 and based on a survey of more than 500 security professionals, found that only 34% intend to stay with their current employer.

The more useful finding sits underneath. Among security staff who see security as a core organisational priority, 73% report career satisfaction. Among those who perceive little or no organisational backing for security, the figure is 19%. The report also found that wage growth plays a bigger role in retention than absolute pay levels: modest, regular increases did more than a high starting number left to stand still.

Set that against what UK organisations report about themselves. The Cyber Security Breaches Survey 2025/2026, published by the Department for Science, Innovation and Technology on 30 April 2026 from a sample of 2,112 businesses, found that 72% of businesses say cyber security is a high priority for their senior management. Some 31% have board members taking explicit responsibility for it. Large businesses largely keep a regular rhythm: 81% say senior management receives a cyber update at least quarterly. Medium businesses are moving the other way. The share whose senior management is updated even once a year fell from 78% to 70% in a single year. Of businesses and charities combined, 16% had heard of the government's Cyber Governance Code of Practice, launched in April 2025.

Read together, the numbers describe a gap. Almost three quarters of businesses say security is a priority for their senior management. Fewer than a third have a board member who owns it. The Code asks boards to require formal reporting at least quarterly; among medium businesses, three in ten now do not report to senior management even once a year.

Infographic titled Priority is measured from below. The first panel shows career satisfaction among security staff: 73% of those who see security as a core organisational priority are satisfied, against 19% of those who see little or no backing (IANS and Artico Search, April 2026, satisfaction rather than intention to stay). The second panel shows what UK businesses report: 72% call cyber a high priority for senior management, 31% have a board member with explicit cyber responsibility, and 16% of businesses and charities are aware of the Cyber Governance Code of Practice (DSIT Cyber Security Breaches Survey 2025/2026).
Security teams judge priority by behaviour. Almost three quarters of UK businesses call cyber a high priority; fewer than a third have a named board owner. Sources: IANS and Artico Search, April 2026; DSIT Cyber Security Breaches Survey 2025/2026.

Why this belongs on the board agenda

A security professional does not experience "priority" as a sentence in the annual report. They experience it as a calendar. Did the CISO present to the board this quarter, or did a slide appear in someone else's pack? When the risk register grew, did the budget move with it? When a project was cut, was it the security one?

The team reads those signals continuously, and it reads them more accurately than most boards assume, because security staff are trained to look for the gap between a stated control and an operating one. A board that says security is a priority but hears from its security leader once a year has published a policy that its own people can see is not operating.

This is also why a counter-offer is a weak instrument. Salary answers a question the leaver may not have been asking. The IANS finding on wage growth points the same way: what retains people is evidence of movement, in pay and in standing, rather than a single number offered at the door.

There is a second, less obvious consequence. The people most sensitive to these signals are the ones with the most options. A strong senior engineer who concludes the organisation will not back security does not wait to be proved right. The people who stay are, disproportionately, those with fewer alternatives. Over two or three cycles, a board that under-signals priority does not merely lose headcount. It selects for a weaker team while believing its establishment is unchanged.

The commercial exposure of a departure

A security resignation is usually booked as a recruitment cost. The larger costs sit elsewhere.

Regulatory. Under DORA, Article 5(2) places ultimate responsibility for ICT risk on the management body and requires it to allocate and periodically review the budget for resilience needs, explicitly including ICT skills for all staff. NIS2 Article 20 requires management bodies to approve and oversee cyber risk-management measures and provides that they can be held liable for infringements. Both apply to UK firms only where they operate in, or supply into, the EU. At home, the Cyber Security and Resilience Bill remains at report stage in the House of Lords and has not yet received Royal Assent, but it moves in the same direction. Under each regime, the capability that walks out of the door is capability the management body remains answerable for.

Contractual. Enterprise customers ask, in security questionnaires and audits, who operates the controls they rely on. ISO/IEC 27001 requires roles and responsibilities to be assigned (clause 5.3) and competence to be determined and evidenced (clause 7.2). When the person behind an answer leaves, the answer does not update itself. The organisation is carrying a representation that has quietly stopped being true.

Transactional. In due diligence, security capability concentrated in a small team with weak retention reads as key-person risk. Buyers and investors price that risk, through valuation, retention packages or conditions on completion. A board that cannot show why its security people stay is inviting someone else to discount the answer.

Insurance. Underwriters price the controls they are told exist. A control whose operator has left, and whose replacement has not yet started, is a gap between the proposal form and reality. We assess that as an exposure most organisations have not tested, rather than one insurers have yet made explicit.

The Priority Test

We use a simple framework to make the signal visible. It asks four questions a security team is already answering for itself. The board should answer them first.

1. Access. How often does the security leader speak directly to the board, and in which direction does the conversation run? The Code asks for regular two-way dialogue with the CISO or equivalent. A slide presented by someone else is not access.

2. Allocation. When the agreed risk changed in the last twelve months, did resources move with it? The Code asks boards to gain assurance that resources are allocated effectively against agreed risks. A team that watches risk grow while budget stays flat draws its own conclusion.

3. Advancement. Is there a visible route for a strong security professional to grow here, in scope, standing and pay? The IANS data suggests steady movement matters more than a high entry salary. If the only way up is out, people will take it.

4. Attribution. Does a named person above the security function own the outcome? Only 31% of UK businesses have a board member with explicit cyber responsibility. Where no one owns it, the security leader carries accountability without authority, and that is a role strong people rarely stay in for long.

Score each honestly. Where the answer is weak, the retention problem is already in train, whatever the latest engagement survey says.

Infographic titled The Priority Test: four questions your security team is already answering about you, which the board should answer first. Access: does the security leader speak to the board directly, and does the conversation run both ways? Allocation: when the agreed risk changed this year, did resources move with it? Advancement: is there a visible route to grow in scope, standing and pay, or is the only way up the way out? Attribution: is a named person above the security function accountable for the outcome? A weak answer to any one means the retention problem has already started.
The Priority Test from Garzon Cyber Solutions: Access, Allocation, Advancement and Attribution. Four signals that shape whether a security team stays.

What this means when you hire

The Priority Test does not stop at retention. In our view, experienced security candidates run the same test at interview. They ask who the security leader reports to, when that person last spoke to the board, what happened to the budget after the last audit, and who owns the risk. A process that cannot answer those questions plainly tends to lose the candidates it most wants, often at offer stage, and to keep the ones who did not think to ask.

That changes how a security role should be briefed. Before it goes to market, the hiring manager should be able to answer the four questions in writing, because the strongest candidates will test every answer. Where the honest answer is weak, it is better to say so and set out what is changing than to let a new hire discover it in their first quarter. A replacement hired without fixing the signal that caused the departure is likely to follow the same path out.

This is how we run a search. We ask the four questions before we accept a brief, we put the answers in front of candidates at the first conversation, and where an answer is likely to cost the hiring company its preferred candidates, we say so before the search starts rather than after it stalls.

Three questions for the board

  1. When did our security leader last present to this board in person, and what did we decide as a result?
  2. If our two most capable security people resigned this quarter, which customer commitments, regulatory attestations or audit findings would become untrue before we replaced them?
  3. Which board member is named as accountable for cyber risk, and would our security team give the same answer?

The strategic takeaway

Retention in security is usually treated as a people problem to be solved with money. The evidence suggests it is a governance problem that shows up as a people problem. The board that fixes access, allocation, advancement and attribution will spend less on replacements, carry fewer untrue representations and present a stronger capability in every contract, audit and transaction that tests it. That is a commercial advantage, and it costs less than replacing the people who leave.

Confidence note

Confirmed. The 34% intention to stay, the 73% and 19% satisfaction figures, the sample of more than 500 and the finding on wage growth are as reported by IANS and Artico Search on 14 April 2026. The 72%, 31%, 81%, 78% to 70% and 16% figures are as published in the Cyber Security Breaches Survey 2025/2026 on 30 April 2026; the update-frequency figures refer to senior management rather than the board specifically, and the 16% covers businesses and charities combined. The DORA, NIS2 and Code of Practice wording is quoted from the published texts. The Bill's status reflects the UK Parliament record as updated on 16 September 2026.

Assessed. The 73% and 19% figures measure career satisfaction, not intention to stay; some secondary coverage has reported them as retention rates, which they are not. The link between satisfaction and staying is our reading, supported by the report's own emphasis, rather than a figure it publishes. The IANS report does not disclose respondent geography in its public materials and reports compensation in US dollars, so we treat it as weighted towards North America. The selection effect, the behaviour of candidates at interview and the insurance exposure are our assessments.

Not known. The public IANS materials do not give a survey period or full methodology. There is no UK-specific equivalent of the intention-to-stay figure of comparable recency.

What this is not

We do not run engagement surveys, HR retention programmes or compensation consulting, and we would not claim to. Our ground is the security capability itself: who owns it, how deep it runs, how it maps to the compliance obligations it has to prove, and who you hire when someone leaves.

Working with Garzon Cyber Solutions

Garzon Cyber Solutions is a young firm. We built it around a single view: technology capability, the compliance that proves it and the people who run it fail when they are bought from suppliers who never speak to each other. We put all three under one accountable owner.

Our recruitment practice covers cybersecurity, IT and AI security, DevOps and engineering roles across the UK, EU and Americas, together with the commercial roles technology companies build around them. It runs on contingency. Nothing is payable until a candidate accepts and starts. Our founder, Jonathan Garzon, runs every search personally, and no CV reaches a hiring company without the candidate's explicit permission for that specific role.

If the Priority Test surfaced a gap you would rather close before it becomes a resignation, or you are hiring into a security team and want a brief that survives the candidate's questions, start with a conversation. Terms of business are available the same day.

Could your board answer the Priority Test today?

Garzon Cyber Solutions is built to put questions like this on the risk register with an owner, map the controls to what regulators, customers and insurers actually ask for, and place the people who keep the answer current. Cybersecurity, compliance and talent, delivered in that order, as one capability.

Start the Conversation →
Subscribe to GCS Insights

Sources: IANS and Artico Search, 2026 Cybersecurity Talent Report, press release 14 April 2026. Department for Science, Innovation and Technology, Cyber Security Breaches Survey 2025/2026, 30 April 2026. Department for Science, Innovation and Technology and NCSC, Cyber Governance Code of Practice, April 2025. Regulation (EU) 2022/2554 (DORA), Article 5. Directive (EU) 2022/2555 (NIS2), Article 20. UK Parliament, Cyber Security and Resilience (Network and Information Systems) Bill, bill record updated 16 September 2026.

Sources
Department for Science, Innovation and Technology, Cyber security skills in the UK labour market 2025, published 19 September 2025. ISC2, 2025 Cybersecurity Hiring Trends, 929 hiring managers across six countries, published June 2025. Barclay Simpson, 2026 Salary Survey and Recruitment Trends Guide: Cyber Security. Department for Science, Innovation and Technology, Cyber security sectoral analysis 2026, published 12 May 2026.
Talent Cyber Careers Hiring GRC Skills