Skip to main content

In the complex world of cybersecurity, we often encounter a perplexing paradox:

The traditional Chief Information Security Officer is becoming extinct, and few in our industry are talking about it. Despite an unprecedented focus on cybersecurity and mounting regulatory pressures, we’re witnessing a paradoxical trend: the dissolution of dedicated executive security leadership positions. After spending almost 20 years in security, with over half in security leadership / CISO positions leading, global and sizable organisations and now transitioning to fractional security leadership, I’ve observed this transformation firsthand.

The reality? Organisations are quietly restructuring their security leadership, often embedding it within technology functions or splitting it across multiple roles. This isn’t just evolution – it’s a fundamental reimagining of how enterprises approach security leadership. The traditional CISO role isn’t being enhanced; it’s being transformed, and survival requires adaptation.

The Market Reality

Let’s be brutally honest about what’s happening in the security leadership market. True executive security positions – those with real board influence and autonomous decision-making power – are shrinking. What’s replacing them? Roles with compressed salaries (often under £140k), reduced authority, and direct reporting lines into technology functions rather than the board or C-suite.

This shift isn’t just about cost-cutting. We’re seeing longer CISO tenures, not because of satisfaction, but due to reduced movement opportunities. My own experience of a 6.5-year tenure, while valuable, reflects this trend. The market for experienced, veteran security leaders has contracted, with organisations increasingly favouring interim or fractional leadership models.

The uncomfortable truth? Many organisations are concluding that they don’t need a full-time, highly compensated CISO. Instead, they’re opting for more flexible, cost-effective models that align security leadership with their perceived risk appetite rather than industry assumptions about what “good” looks like.

The Great Security Leadership Divide

The monolithic CISO role is splintering into specialised functions: Resilience (focusing on availability), Data (addressing integrity), and Privacy (managing confidentiality). This isn’t just organisational restructuring – it’s a fundamental shift in how businesses view security leadership.

Why is this happening when regulatory pressures around security and digital resilience are intensifying? The answer lies in how organisations are redefining technology leadership. Traditional technology leaders are increasingly absorbing security responsibilities, viewing them as integral to their broader digital transformation mandates rather than standalone functions.

This consolidation might seem counterintuitive given the growing complexity of security challenges, but it reflects a broader trend: organisations are prioritising integrated technology leadership over siloed security expertise. The irony? As security becomes more critical, dedicated security leadership becomes less common.

The New Security Leader

Tomorrow’s security leaders need a radically different skill set. Technical expertise, while still important, is no longer the primary currency. Instead, success depends on:

– Change management expertise that enables organisation-wide security transformation

– Deep understanding of the technology marketplace and its evolution

– Business acumen that translates security investments into business value

– GRC capabilities that balance compliance requirements with business objectives

The most crucial skill? Relevance. Security leaders must remain relevant to both their senior stakeholders and peers. This means speaking the language of business, understanding technology beyond security, and maintaining credibility across multiple domains.

Business literacy isn’t just about understanding P&Ls – it’s about comprehending how security decisions impact business operations, customer experience, and market competitiveness. The new security leader is a business enabler first, security expert second.

Survival and Adaptation

    1. Embrace Flexibility: Consider fractional or interim roles as legitimate career paths, not just temporary solutions
    2. Broaden Your Impact: Look for opportunities to influence beyond traditional security boundaries
    3. Build Business Credibility: Focus on business outcomes rather than security metrics
    4. Develop Commercial Acumen: Understand how security decisions impact business performanceFor current CISOs, adaptation isn’t optional – it’s essential for survival. Here’s how to navigate this transformation:

    My own transition to fractional security leadership wasn’t just a career choice – it was a response to market reality. It’s allowed me to maintain executive-level impact while adapting to organisations’ changing needs and risk appetites.

    The next 12-24 months will accelerate these changes. We’ll see the emergence of new security leadership archetypes: the Fractional Executive, the Business-Technology Integrator, and the Risk-Focused Advisor. Traditional CISO roles won’t disappear entirely, but they’ll become increasingly rare, reserved for specific industries or regulatory requirements.

    The future belongs to adaptable security leaders who can:

    – Navigate complex organisational dynamics

    – Deliver value through flexible engagement models

    – Balance technical expertise with business acumen

    – Embrace change rather than resist it

    The question isn’t whether to adapt – it’s how quickly you can evolve. The security leaders who thrive in 2025 won’t be those with the most technical expertise or the longest tenures. They’ll be the ones who recognised this transformation early and positioned themselves to lead it.

    The traditional CISO role may be dying, but security leadership isn’t – it’s transforming. Will you be part of that transformation, or will you be left behind defending a role that no longer exists?