The US CISO in 2026: Smaller Budgets, Bigger Threats, a Board That Has Stopped Paying Attention and a Burnout Rate of 66 Percent

The most revealing data point in the IANS 2025/2026 Security Budget Benchmark is not any single number. It is the perception gap between CISOs and their boards. Twenty-nine percent of CISOs say their budget is adequate. Forty-one percent of board members think the budget is adequate. Both figures are low. But the 12-point gap between them represents something more serious than a disagreement about numbers. It represents a fundamental misalignment about the nature and severity of the risk that the organisation faces.

This misalignment is occurring at the worst possible moment. The Cyberbase 2026 analysis of the top CISO challenges identifies ten converging pressures: governing AI and shadow AI deployments, managing SOC operational strain from alert overload, addressing third-party cyber risk that has doubled year over year, closing a 4.7 million person cybersecurity talent gap, consolidating fragmented security tooling, navigating overlapping global regulations with personal liability exposure, building genuine cyber resilience, preparing for post-quantum cryptographic migration, sustaining the expanding CISO role without burnout and making the case for security budgets that are growing at their slowest pace in five years. Any one of these would constitute a significant challenge. All ten are arriving simultaneously.

Gartner’s forecast, now confirmed by actual attrition data, was that nearly half of cybersecurity leaders would change jobs by 2025 and that 25 percent would move into entirely different roles due to work-related stress. Proofpoint’s Voice of the CISO report, based on surveys of 1,600 global CISOs across 16 countries, found that 66 percent feel at risk of burnout and more than half report losing sleep due to cyber threats and the pressure of accountability. ISC2’s Cybersecurity Workforce Study shows the global cybersecurity workforce gap has grown to 4.8 million unfilled positions, the largest ever recorded. The people leaving the CISO role are not being replaced at the rate they are departing.

The Budget and Wellbeing Numbers

The charts below present two views of the US CISO’s situation in 2026. The left chart shows key budget and resource metrics compared to the prior year, illustrating the compression across every dimension from budget growth to headcount addition. The right panel presents the wellbeing indicators that explain why experienced security leaders are leaving senior roles at an unprecedented rate.

Chart 1: CISO budget and resource metrics 2025/26 vs prior year (left) and CISO wellbeing indicators 2026 (right). Sources: IANS; Proofpoint Voice of CISO; Gartner; Cyberbase

The Board Alignment Problem

The boardroom alignment problem that Proofpoint identified in its 2025 CISO survey is more structurally damaging than the budget figures alone suggest. When a CISO presents a risk that the board does not adequately understand or value, the consequence is not just underfunding. It is a systematic bias toward under-investing in controls that address the most serious threats while over-investing in visible but lower-priority activities that are easier to explain and quantify.

The Wiz 2026 CISO Budget Benchmark Report, based on insights from more than 300 security leaders, describes CISOs redefining ROI as security yield: how much risk reduction is achieved per incremental dollar. This shift moves budget discussions from activity to impact. It is exactly the right framing for a board conversation about security investment. The problem is that most boards are not equipped to evaluate security yield without help, and the CISO who is best positioned to provide that help is often the one under the most pressure and with the least time to prepare a genuinely persuasive board narrative.

The industries where CISOs are most likely to report flat or reduced budgets according to IANS research are healthcare, professional and business services and retail and hospitality. These are sectors under financial pressure from global economic uncertainty, inflation and sector-specific instability. Financial services, insurance and technology fared better with growth rates above 5 percent. But even in these better-positioned sectors, the resource allocation challenges are present. The difference is degree rather than kind.

What the Most Effective US CISOs Are Doing Differently

ChallengeWhat Most CISOs DoWhat the Most Effective CISOs Do
Board budget conversationsPresent activity metrics: tools deployed, incidents handled, training completionsPresent risk delta metrics: quantified reduction in breach probability and expected loss per dollar invested
AI governanceBlanket restriction on generative AI tool use by employeesRisk-tiered governance framework distinguishing acceptable and unacceptable use with monitoring for violations
Talent shortageCompete on salary for scarce certified professionalsBuild internal talent pipelines; use AI-assisted tools to extend capacity of existing team; retain through culture and scope
Third-party riskAnnual vendor security questionnairesContinuous third-party access monitoring with real-time visibility into which vendors have active access to which systems
Burnout and attritionIndividual resilience advice; wellness programmesStructural changes: deputy CISO roles, defined on-call rotations, direct board access, shared ownership of security outcomes
SOC alert overloadMore analysts; longer review queuesAI-assisted triage and automated response for defined alert categories; analysts focus on alerts AI cannot resolve

Table 1: Key CISO challenges with typical versus most effective response approaches, US market 2026 (Sources: IANS; Wiz; Cyberbase; Proofpoint)

The Structural Fix That Budget Cannot Buy

The most important change the US security industry needs to make in 2026 is not a budget increase, though budgets need to grow. It is a structural redesign of the CISO role itself. The current model asks one person to be the organisation’s chief security strategist, its primary regulator-facing executive, its board communicator on technical risk, its operational security leader, its talent manager, its vendor relationship owner and its crisis manager during incidents. No single person can perform all of these functions effectively at the same time, particularly when budgets are constrained and the threat environment is accelerating.

The organisations that are building sustainable security leadership capacity are distributing these responsibilities across a team: a Deputy CISO who owns day-to-day operations, a dedicated board reporting function that translates technical risk into business language, a vendor risk management team with continuous monitoring capability and a talent development programme that builds senior security professionals internally rather than bidding for them in a constrained external market.

The 66 percent burnout rate is not an individual failing. It is a systemic signal that the structure of the CISO role as currently designed is not compatible with the demands being placed on it. Addressing that structural problem is not a wellness initiative. It is a security strategy decision. A burned-out CISO makes slower decisions, misses signals and eventually leaves. The organisation that replaced them with someone equally capable of handling the full current scope of the role, at the current market salary, in the current talent environment, will discover that the search takes longer and costs more than the structural redesign would have.

Leave a Reply

Your email address will not be published.