50% of CISOs see Mythos as a sign to exit the profession

Tags:

CISOs already have it tough, but the straw that breaks the back of many IT security executives may be the rapidly advancing capabilities of frontier AI models, enterprise insistence on rapid and widespread AI experimentation, and the compounding risk responsibilities and personal liabilities surrounding all that.

“There are days where it feels exhausting,” says one CISO at a large enterprise in the software industry, who did not want to be quoted by name. “There are days when it feels like this is a lot.”

This executive is not alone.

In a recent survey of 1,001 CISOs in the US and UK, 50% agreed that the introduction of Anthropic Mythos and similar cyber-capable models and tools has caused them to consider leaving the profession. Only 25% disagreed with that statement.

And 60% said pressure from the board and executive leadership to adopt AI was outpacing their organization’s ability to govern and secure its use.

Christine Gadsby, chief security advisor at BlackBerry, who spent years in cyber leadership positions and was the company’s CISO until switching to her new role last September, doesn’t miss being the CISO.

“It’s madness! Madness!” she says. “I wouldn’t say that I would never do a CISO role again, but it’s a tough time right now to be a CISO.”

CISOs have historically had shorter tenures than other executive positions, she notes. “Before, it was burnout. They had so much responsibility and so many things to do. And now, with AI, some of these challenges are just mindboggling,” she says.

The personal responsibility aspect of the job is also tough, she adds. “One thousand percent. As an industry, we built the CISO role to take all of that liability and now we act surprised when people want out.”

According to a survey released earlier this year, 78% of CISOs are concerned about their own liability for security incidents — up from 56% a year ago. And 89% of CISOs say the breakneck pace of technology advancement is a challenge.

“As fast as AI evolves, the benefit is with the attacker right now,” says Gadsby. “Attackers are weaponizing vulnerabilities as fast as they can find them, sometimes even sooner than the fix is published.”

A compounding problem

As a result of these and other factors, experienced CISOs are retiring, moving to less stressful security-related positions, switching to consulting or sales support jobs, or leaving the profession entirely. That leaves companies having to hire less-experienced people, who are even more vulnerable to burnout.

“If you feel not ready for the role, or don’t feel empowered — especially right now — that’s when you’re like, ‘I’m out. I’m going to go do something else,’“ Gadsby says.

Plus, because every enterprise IT environment is different, it takes time for a new CISO to get up to speed, creating more security risks given today’s pace of change and attack — and thus putting even more stress on the CISO.

“You have to be a special person to want to do that job,” Gadsby says, likening the role to being a firefighter.

“Every once in a while, I’ll read something in the news and think, ‘Oh my gosh, all my friends are not sleeping tonight.’ I’m glad I’m not up at 2 a.m. trying to solve this. But sometimes I do miss being helpful, being a firefighter,” she says. “The heart of the role is wanting to protect people.”

Addressing liability concerns

So is there a path forward for the profession?

“There’s not an easy way out for the CISO,” says IDC analyst Chris Kissel. The average CISO tenure is now 18 months, he notes, and issues like personal liability for cybersecurity incidents and the new AI models aren’t helping. “The new world for CISOs is very scary.”

It will take acts of leadership to improve the situation, he says, such as a governing body that mandates minimal requirements for responsible behavior.

“And if you take these steps, that takes the CISO out of the legal indemnity,” he says. “There has to be a way to put the CISO in the clear.”

Oliver Legg, co-founder and cybersecurity recruiter at Aspiron Search, an executive search company focusing on cybersecurity, says he’s seeing the liability concerns when talking to prospective CISOs.

“Two years ago, we had CISO candidates ask about budget and headcount,” he says. “Now, the first questions are about indemnification and D&O coverage.”

D&O — or directors and officers — is liability insurance that protects business leaders from personal financial loss.

Countering AI anxiety

And dealing with the growing AI threats?

That can be managed as well. AI itself can be used to improve security operations, as long as it’s handled responsibly.

“Mythos doesn’t really change what we need to do,” says Omar Khawaja, who teaches at Carnegie Mellon University’s CISO and CAIO programs and serves as the global field CISO at Databricks. “It changes how well, and how fast, and how much of it we need to do. And we need to change the approach and frameworks that we use so we can achieve a scale that’s 2X, 3X, 10X bigger than in the past.”

That means that security programs will have to become much more agentically driven, he says, with the proper precautions in place.

And fears of a company’s own AI going rogue are a bit overblown, he adds.

“Almost every single one of those cases is where they’ve been experimenting with models that have not been released and the companies say that they’re not going to be released,” he says. “So if you move to an agentic environment in production, don’t use experimental AI. If you use one of the well-known AIs, it’s very doable to manage those securely.”

And organizations that are new to AI and don’t have all the experience and the guardrails yet should start with less risky use cases, learn to mitigate those risks, and then build from that.

“In the security space, I would use the AI for anomalies and to triage existing investigations,” he says. “I probably wouldn’t start out with using AI to automate my response. But if I work my way up, I can get there.”

A new opportunity

The Mythos effect is overstated, confirms Mike Privette, former CISO and founder and cybersecurity economist at Return on Security. These frontier models have just turned a public spotlight on problems that were already there.

“On the flip side, while frontier models are changing the speed and complexity of the threat landscape, many CISOs are more excited than ever to be in the seat,” he says. “For many people, this is one of the most exciting times to be operating in the field.”

That’s especially the case when the CISO is working at a company that’s embracing AI, and where they’re given executive support, the right budget, and the leeway to experiment, he says.

“I’ve had the opportunity to be in other roles in the middle of my CISO tenure,” says the executive at the large software company who did not want to be quoted by name. “And those other roles are so much easier. You can be at 90% and still get a pat on the back. But when you’re a CISO, and you’re at 99%, and there’s one server that allowed the bad guys to break in, nobody cares that you patched the other 99. Less than perfect is never good enough.”

Still, there are days when it feels exhilarating, the executive adds. “Though it’s a very fine line between the two.”

And keeping a company and its customers secure is an awesome challenge.

“Our platform is used by thousands of enterprises,” the executive says. “I keep reminding myself and my team that that’s the focus. We’re not doing it just for us. The more I can think about what an awesome challenge this is, the more the mission and objective feel very awesome.”

Categories

No Responses

Leave a Reply

Your email address will not be published. Required fields are marked *