The Weight on the CISO: Burnout, Board Pressure, and the Expectation to Be Right Every Time
UK CISOs are under unprecedented pressure, with over half reporting burnout and boardroom alignment falling sharply. This piece looks at what's driving the strain, why it's a business risk and not just a personal one, and what genuine support looks like for security leaders carrying the weight.

Sustained, high-stakes accountability takes a measurable toll over time. For a growing number of UK CISOs, that toll is now well documented: constant vigilance, personal accountability for incidents outside their direct control, and the knowledge that a single missed alert can have career-ending consequences.
The role has quietly expanded far beyond technical oversight. It now sits at the intersection of law, boardroom politics, regulatory compliance, and crisis communications, often without the resourcing or authority to match. This toll is being highlighted in the data.
Key takeaways
- According to Proofpoint's 2025 Voice of the CISO report, half of UK CISOs, approximately 58%, have experienced or witnessed burnout in the past year.
- Boardroom alignment with UK CISOs fell sharply between 2024 and 2025, leaving many security leaders carrying accountability without corresponding support.
- UK-based research found that around a third of CISOs believe the role is affecting their mental or physical health.
- Burnout is not just a personal cost. Estimates put the annual toll of lost productivity from cyber burnout at roughly £130 million for UK businesses alone.
- With the global cybersecurity workforce shortfall reaching 4.8 million people, there is little room left for CISOs to distribute the load. This pushes more pressure back onto the individual at the top.
- The Cyber Security Breaches Survey shows the threat landscape UK organisations face is only intensifying, adding to the pressure CISOs are expected to absorb.
A role that has outgrown its job description
Alongside technical strategy, CISOs are expected to translate risk into language a board will act on, hold the line during a breach while lawyers and communications teams look to them for answers, and stay personally accountable when something slips through, even when the resourcing to prevent it was never approved.
Proofpoint's research puts numbers on what many in the profession already feel. Boardroom alignment with UK CISOs dropped from 84% in 2024 to 57% in 2025, leaving security leaders exposed at the exact moment they need backing the most. The same report finds that 58% of UK CISOs have experienced or witnessed burnout within their peer group in the past year, and 63% expect a material cyberattack within the next 12 months. That is not a comfortable place to sit, professionally or personally.
Gartner's earlier forecast still holds weight here. It predicted that nearly half of cybersecurity leaders would change roles by 2025, with a quarter expected to leave the profession altogether because of the toll the work takes. When that many experienced leaders are considering leaving, it says less about individual resilience and more about how the role has been structured.
The human cost sits underneath the business cost
It is tempting to talk about burnout purely in terms of business risk: missed vulnerabilities, slower incident response, higher staff turnover. Those consequences are real, and they matter. But underneath the spreadsheets is a person carrying a weight that follows them home.
Nominet's research into the UK CISO community found that around 32% of CISOs believe their job is negatively affecting their mental or physical health, and that 17% have turned to alcohol or medication as a way of managing the pressure. That is not a statistic to skim past. It reflects people making difficult choices in the absence of better support, often while presenting a calm and composed front to their teams and boards.
This is where the wider talent shortage compounds the problem. With nearly 4.8 million unfilled cybersecurity roles globally, there are fewer hands available to share the workload and less opportunities for a CISO to step back without leaving a visible gap.
Why this matters for the whole organisation, not just the CISO
A CISO operating under chronic stress is not simply having a harder time at work. Their judgement is affected too. Fatigue narrows attention, slows decision making, and makes it easier for a genuine threat indicator to get lost among the noise. A burnt out leader is statistically more likely to miss the early signs of an incident than one who feels supported and able to think clearly.
There is also a retention cost that boards tend to underestimate. Losing a CISO mid-tenure means losing institutional knowledge of the organisation's risk landscape at precisely the moment continuity matters most. Rebuilding that knowledge under a new hire takes months, sometimes longer, and the estimated £130 million annual productivity loss tied to burnout in the UK gives some sense of the scale involved.
Layer regulatory complexity on top of this and the picture gets heavier still. UK organisations are already navigating an evolving compliance landscape, and upcoming legislation such as the Cyber Security and Resilience Bill will add further reporting obligations for many sectors. For a CISO already stretched thin, each new regulatory requirement is another item on a list that never seems to get shorter.
What actually helps
There is no single fix for a problem this structural, but a few shifts consistently make a difference:
- Clear boundaries set early. Waiting until the role feels unmanageable to raise concerns about scope or resourcing tends to be too late. The earlier expectations are negotiated, the more sustainable the role becomes.
- Genuine board engagement, not just reporting. A board that understands cyber risk as a shared responsibility, rather than something to delegate entirely downward, changes the dynamic considerably.
- Realistic resourcing conversations. Budget and headcount decisions made without input from the CISO tend to create the very gaps that later show up as incidents.
- External support that shares the load. A trusted intelligence partner who can absorb some of the monitoring, research, and analysis burden gives a CISO room to think strategically.
We understand the weight, because we sit alongside it
CYJAX works with security leaders who are carrying more than most people realise. We understand what it means to be the person who must be right every time, in a role that rarely gets the credit when things go well and takes the full weight when they do not.
That is why CYJAX exists as an extension of your team, not a vendor sitting outside it. We help absorb the monitoring, the research, and the early warning work that quietly consumes hours in a CISO's week, so there is more capacity left for the strategic decisions that need a human mind at its sharpest. We understand the pressure. We understand the burnout risk. And we understand that keeping the business safe should not come at the cost of the person responsible for it.
Get Started with CYJAX CTI
Empower Your Team. Strengthen Your Defences.CYJAX gives you the intelligence advantage: clear, validated insights that let your team act fast without being buried in noise.




