{"id":9358,"date":"2026-09-09T08:25:00","date_gmt":"2026-09-09T08:25:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9358"},"modified":"2026-09-09T08:25:00","modified_gmt":"2026-09-09T08:25:00","slug":"50-of-cisos-see-mythos-as-a-sign-to-exit-the-profession","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9358","title":{"rendered":"50% of CISOs see Mythos as a sign to exit the profession"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">CISOs already have it tough, but the straw that breaks the back of many IT security executives may be the rapidly advancing capabilities of frontier AI models, enterprise insistence on rapid and widespread AI experimentation, and the compounding risk responsibilities and personal liabilities surrounding all that.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThere are days where it feels exhausting,\u201d says one CISO at a large enterprise in the software industry, who did not want to be quoted by name. \u201cThere are days when it feels like this is a lot.\u201d<\/p>\n<p class=\"wp-block-paragraph\">This executive is not alone.<\/p>\n<p class=\"wp-block-paragraph\">In a <a href=\"https:\/\/www.absolute.com\/resources\/research-reports\/the-state-of-enterprise-cyber-resilience-research-series\">recent survey of 1,001 CISOs in the US and UK<\/a>, 50% agreed that the introduction of <a href=\"https:\/\/www.csoonline.com\/article\/4198019\/claude-mythos-faq-capabilities-access-competitors-implications.html\">Anthropic Mythos<\/a> and similar <a href=\"https:\/\/www.csoonline.com\/article\/4180920\/beware-the-son-of-mythos-security-experts-warn.html\">cyber-capable models<\/a> and tools has caused them to consider leaving the profession. Only 25% disagreed with that statement.<\/p>\n<p class=\"wp-block-paragraph\">And 60% said pressure from the board and executive leadership to adopt AI was outpacing their organization\u2019s ability to govern and secure its use.<\/p>\n<p class=\"wp-block-paragraph\">Christine Gadsby, chief security advisor at BlackBerry, who spent years in cyber leadership positions and was the company\u2019s CISO until switching to her new role last September, doesn\u2019t miss being the CISO.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIt\u2019s madness! Madness!\u201d she says. \u201cI wouldn\u2019t say that I would never do a CISO role again, but it\u2019s a tough time right now to be a CISO.\u201d<\/p>\n<p class=\"wp-block-paragraph\">CISOs have historically had shorter tenures than other executive positions, she notes. \u201cBefore, it was burnout. They had so much responsibility and so many things to do. And now, with AI, some of these challenges are just mindboggling,\u201d she says.<\/p>\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/www.csoonline.com\/article\/3631759\/personal-liability-sours-70-of-cisos-on-their-role.html\">personal responsibility aspect of the job<\/a> is also tough, she adds. \u201cOne thousand percent. As an industry, we built the CISO role to take all of that liability and now we act surprised when people want out.\u201d<\/p>\n<p class=\"wp-block-paragraph\">According to a survey released earlier this year, <a href=\"https:\/\/www.splunk.com\/en_us\/blog\/ciso-circle\/ciso-ai-strategy-digital-resilience.html\">78% of CISOs are concerned<\/a> about their own liability for security incidents \u2014 up from 56% a year ago. And 89% of CISOs say the breakneck pace of technology advancement is a challenge.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAs fast as AI evolves, the benefit is with the attacker right now,\u201d says Gadsby. \u201cAttackers are weaponizing vulnerabilities as fast as they can find them, sometimes even sooner than the fix is published.\u201d<\/p>\n<h2 class=\"wp-block-heading\">A compounding problem<\/h2>\n<p class=\"wp-block-paragraph\">As a result of these and other factors, experienced CISOs are retiring, moving to less stressful security-related positions, switching to consulting or sales support jobs, or <a href=\"https:\/\/www.csoonline.com\/article\/4127704\/69-of-cisos-open-to-career-move-including-leaving-role-entirely.html\">leaving the profession entirely<\/a>. That leaves companies having to hire less-experienced people, who are even more vulnerable to burnout.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIf you feel not ready for the role, or don\u2019t feel empowered \u2014 especially right now \u2014 that\u2019s when you\u2019re like, \u2018I\u2019m out. I\u2019m going to go do something else,\u2019\u201c Gadsby says.<\/p>\n<p class=\"wp-block-paragraph\">Plus, because every enterprise IT environment is different, it takes time for a new CISO to get up to speed, creating more security risks given today\u2019s pace of change and attack \u2014 and thus putting even more stress on the CISO.<\/p>\n<p class=\"wp-block-paragraph\">\u201cYou have to be a special person to want to do that job,\u201d Gadsby says, likening the role to being a firefighter.<\/p>\n<p class=\"wp-block-paragraph\">\u201cEvery once in a while, I\u2019ll read something in the news and think, \u2018Oh my gosh, all my friends are not sleeping tonight.\u2019 I\u2019m glad I\u2019m not up at 2 a.m. trying to solve this. But sometimes I do miss being helpful, being a firefighter,\u201d she says. \u201cThe heart of the role is wanting to protect people.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Addressing liability concerns<\/h2>\n<p class=\"wp-block-paragraph\">So is there a path forward for the profession?<\/p>\n<p class=\"wp-block-paragraph\">\u201cThere\u2019s not an easy way out for the CISO,\u201d says IDC analyst Chris Kissel. The average CISO tenure is now 18 months, he notes, and issues like personal liability for cybersecurity incidents and the new AI models aren\u2019t helping. \u201cThe new world for CISOs is very scary.\u201d<\/p>\n<p class=\"wp-block-paragraph\">It will take acts of leadership to improve the situation, he says, such as a governing body that mandates minimal requirements for responsible behavior.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAnd if you take these steps, that takes the CISO out of the legal indemnity,\u201d he says. \u201cThere has to be a way to put the CISO in the clear.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Oliver Legg, co-founder and cybersecurity recruiter at Aspiron Search, an executive search company focusing on cybersecurity, says he\u2019s seeing the liability concerns when talking to prospective CISOs.<\/p>\n<p class=\"wp-block-paragraph\">\u201cTwo years ago, we had CISO candidates ask about budget and headcount,\u201d he says. \u201cNow, the first questions are about indemnification and D&amp;O coverage.\u201d<\/p>\n<p class=\"wp-block-paragraph\">D&amp;O \u2014 or <a href=\"https:\/\/www.csoonline.com\/article\/2512968\/if-youre-a-ciso-without-do-insurance-you-may-need-to-fight-for-it.html\">directors and officers<\/a> \u2014 is liability insurance that protects business leaders from personal financial loss.<\/p>\n<h2 class=\"wp-block-heading\">Countering AI anxiety<\/h2>\n<p class=\"wp-block-paragraph\">And dealing with the growing AI threats?<\/p>\n<p class=\"wp-block-paragraph\">That can be managed as well. AI itself can be <a href=\"https:\/\/www.csoonline.com\/article\/4212560\/7-ways-ai-can-be-used-to-enhance-security-operations.html\">used to improve security operations<\/a>, as long as it\u2019s handled responsibly.<\/p>\n<p class=\"wp-block-paragraph\">\u201cMythos doesn\u2019t really change what we need to do,\u201d says Omar Khawaja, who teaches at Carnegie Mellon University\u2019s CISO and CAIO programs and serves as the global field CISO at Databricks. \u201cIt changes how well, and how fast, and how much of it we need to do. And we need to change the approach and frameworks that we use so we can achieve a scale that\u2019s 2X, 3X, 10X bigger than in the past.\u201d<\/p>\n<p class=\"wp-block-paragraph\">That means that security programs will have to become much more agentically driven, he says, with the proper precautions in place.<\/p>\n<p class=\"wp-block-paragraph\">And fears of a <a href=\"https:\/\/www.csoonline.com\/article\/4213883\/who-is-accountable-when-your-ai-agent-goes-rogue.html\">company\u2019s own AI going rogue<\/a> are a bit overblown, he adds.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAlmost every single one of those cases is where they\u2019ve been experimenting with models that have not been released and the companies say that they\u2019re not going to be released,\u201d he says. \u201cSo if you move to an agentic environment in production, don\u2019t use experimental AI. If you use one of the well-known AIs, it\u2019s very doable to manage those securely.\u201d<\/p>\n<p class=\"wp-block-paragraph\">And organizations that are new to AI and don\u2019t have all the experience and the guardrails yet should start with less risky use cases, learn to mitigate those risks, and then build from that.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIn the security space, I would use the AI for anomalies and to triage existing investigations,\u201d he says. \u201cI probably wouldn\u2019t start out with using AI to automate my response. But if I work my way up, I can get there.\u201d<\/p>\n<h2 class=\"wp-block-heading\">A new opportunity<\/h2>\n<p class=\"wp-block-paragraph\">The Mythos effect is overstated, confirms Mike Privette, former CISO and founder and cybersecurity economist at Return on Security. These frontier models have just turned a public spotlight on problems that were already there.<\/p>\n<p class=\"wp-block-paragraph\">\u201cOn the flip side, while frontier models are changing the speed and complexity of the threat landscape, many CISOs are more excited than ever to be in the seat,\u201d he says. \u201cFor many people, this is one of the most exciting times to be operating in the field.\u201d<\/p>\n<p class=\"wp-block-paragraph\">That\u2019s especially the case when the CISO is working at a company that\u2019s embracing AI, and where they\u2019re given executive support, the right budget, and the leeway to experiment, he says.<\/p>\n<p class=\"wp-block-paragraph\">\u201cI\u2019ve had the opportunity to be in other roles in the middle of my CISO tenure,\u201d says the executive at the large software company who did not want to be quoted by name. \u201cAnd those other roles are so much easier. You can be at 90% and still get a pat on the back. But when you\u2019re a CISO, and you\u2019re at 99%, and there\u2019s one server that allowed the bad guys to break in, nobody cares that you patched the other 99. Less than perfect is never good enough.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Still, there are days when it feels exhilarating, the executive adds. \u201cThough it\u2019s a very fine line between the two.\u201d<\/p>\n<p class=\"wp-block-paragraph\">And keeping a company and its customers secure is an awesome challenge.<\/p>\n<p class=\"wp-block-paragraph\">\u201cOur platform is used by thousands of enterprises,\u201d the executive says. \u201cI keep reminding myself and my team that that\u2019s the focus. We\u2019re not doing it just for us. The more I can think about what an awesome challenge this is, the more the mission and objective feel very awesome.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>CISOs already have it tough, but the straw that breaks the back of many IT security executives may be the rapidly advancing capabilities of frontier AI models, enterprise insistence on rapid and widespread AI experimentation, and the compounding risk responsibilities and personal liabilities surrounding all that. \u201cThere are days where it feels exhausting,\u201d says one [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9359,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9358","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9358"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9358"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9358\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9359"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9358"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9358"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9358"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}