ao link
Menu
Business Reporter
Business Reporter

CISOs are being judged on the contract they didn’t agree to

Raghu Nandakumara at Illumio argues that boards often blame the wrong problem when a breach happens

Linked InXFacebook

Whenever an organisation suffers a data breach, two investigations usually follow. The first examines how the attacker got in, which is both necessary and sensible. So far so good.

 

The second is more problematic. Rather than focusing on technical lessons, attention often turns to finding someone to blame. More often than not, that culprit is the CISO. It means that a carefully managed cyber-security strategy that took months or even years to build is reduced by the board to a simple question of “why wasn’t this prevented?”

 

Now, I completely understand that reaction because breaches are hugely consequential and boards have the right to demand answers. However, judging security purely on whether a breach occurred creates the wrong incentives for the people responsible for protecting the organisation.

 

Changing the agreed contract post-breach

CISOs are rarely hired to eliminate cyber-risk because that is impossible. Just as police officers cannot prevent every crime, security leaders cannot stop every cyber-attack.

 

Instead, they’re tasked with managing cyber-risk to an agreed level, within a finite budget, alongside competing business priorities. Like every executive, they operate within the organisation’s agreed risk appetite.

 

However, once a breach occurs, those earlier agreements often disappear. The focus often narrows to the single control that failed or wasn’t in place, and the question changes from "was risk managed appropriately?" to "why wasn’t this fixed?" These are fundamentally different questions.

 

Decisions that were entirely rational when made are suddenly judged with the benefit of hindsight. Essentially, months of balanced decision-making are eclipsed by one successful attack.

 

A standard applied to no one else

The changing parameters are unique to CISOs. Elsewhere in the business, leaders are judged on the quality of their decisions within the constraints they were given, not on whether risk ever materialised.

 

A CFO isn’t considered ineffective simply because market conditions deteriorate. A COO isn’t deemed to have failed because a supplier experiences disruption.

 

Many argue CISOs have accountability without authority. Whilst I think this is true in certain circumstances, it’s a diagnosis that misunderstands how most security leaders actually operate.

 

Most security leaders have significant authority over how security budgets are allocated, which initiatives take priority, and which risks require immediate attention. They don’t control the size of the investment itself or the organisation’s appetite for risk.

 

Every investment means another project waits. Security leaders make these trade-offs every day, guided by the organisation’s priorities and the level of risk the board has agreed to accept.

 

The dangerous cycle created when the rules change

When CISOs fear being held personally accountable for a data breach, their approach to managing cyber-risk completely changes.

 

For instance, 77% of CISOs worry a data breach could cost them their job. Faced with that pressure, many are incentivised to prioritise the highly visible, short-term security measures that demonstrate action and reduce personal risk. CISOs react to the latest breach or technology trend instead of addressing the foundational weaknesses that make organisations vulnerable in the first place.

 

When careers are defined by the one incident, investing in less visible, long-term improvements becomes difficult to justify. The result is a reactive security programme that accumulates temporary fixes, compensating controls and point solutions without addressing the underlying causes of vulnerability.

 

Research from Barracuda highlights the consequences of this approach. It found that a lack of integration between security tools weakens organisations’ defences, with 77% saying it hinders threat detection and 78% citing challenges in threat mitigation.

 

Better questions lead to better security

Breaking this cycle requires a change in boardroom thinking. Rather than asking only what failed, boards should ask whether cyber-risk was being managed to the level that had been agreed.

 

For example, were the right risks prioritised? Were investment decisions aligned with business objectives?

 

Those are better questions that recognise cyber-security is a programme of hundreds of interconnected decisions, not a single security control. Breaches become viewed as an opportunity to reassess assumptions, priorities and risk tolerance.

 

The conversation should also extend beyond prevention to include containment. The difference between a managed cyber-incident and a damaging data breach is determined by how quickly compromised systems can be isolated and lateral movement contained before business operations are affected.

 

This shift is becoming even more important in the era of frontier AI, where attackers are increasingly using AI to operate with greater speed and scale. This means organisations have less time to detect and stop attacks before they spread. Boards therefore need confidence not only that they are investing in prevention, but that they have the resilience to contain threats quickly and limit business impact when prevention inevitably fails.

 

Building long-term resilience instead of short-term wins

Even mature organisations with well-funded security teams experience successful attacks. What distinguishes resilient organisations is the quality of the decisions that shape their security posture before those incidents occur.

 

Boards decide how much cyber-risk an organisation is prepared to accept. CISOs decide how best to manage it. Confusing those responsibilities after a breach helps nobody.

 

If organisations continue to judge cyber-security solely by whether a breach occurred, they’ll continue to misunderstand what good security leadership looks like. If they begin measuring the quality of risk management and the ability to contain breaches, they’ll make better investment decisions and create the conditions for CISOs to deliver long-term resilience.

 


 

Raghu Nandakumara is VP of Industry Strategy at Illumio

 

Main image courtesy of iStockPhoto.com and ismagilov

Linked InXFacebook
Business Reporter

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Business Reporter

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@business-reporter.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543