DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Was 2024 a Dire Year for CISOs? The Expanding Risks Behind the Role

CISOs faced heavier cyber, regulatory, and business pressures in 2024. Learn what the SEC disclosure rule requires, why personal liability is contested, and how boards can support resilience.
From TheFinanceBase Team5 min to read

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes—2024 put chief information security officers under pressure from rising cyber threats, tighter disclosure expectations, and greater legal and business accountability. The CISO’s job was no longer just to defend systems: it increasingly involved business continuity, privacy, compliance, AI oversight, and explaining risk to the board. That made the year difficult, but it did not mean every CISO was automatically personally liable for a breach.

Why 2024 was difficult for CISOs

The strain came from several pressures landing at once. Security leaders had to prepare for attacks while helping organizations deploy cloud services and AI, manage compliance and privacy concerns, and keep operations running if defenses failed. They also had to make the case for resources to business leaders who ultimately decide how much risk to accept.

The threat outlook included cybercrime-as-a-service, AI-assisted attacks, geopolitical advanced persistent threats, ransomware and wipers, and “harvest now, decrypt later” activity: attackers collecting encrypted data in anticipation of future quantum decryption capabilities. These are distinct risks, but they share a practical consequence for security teams: a defense plan must account for disruption and recovery, not just prevention.

How the CISO role is changing

A CISO increasingly has to translate technical exposure into business consequences: which services could stop, what data or operations are at risk, and what investment would reduce that exposure. The role also touches privacy, compliance, AI oversight, and crisis communication. Security expertise remains central, but it is not enough without access to decision-makers and a clear understanding of the organization’s priorities.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How responsibilities are arranged depends on the organization. Smaller organizations may combine CISO, CIO, or CTO responsibilities; larger organizations generally need separate leaders. Combining roles can make sense where staffing is limited, but it can also leave security competing with technology delivery for the same leader’s attention. Separate leadership is useful only if the CISO still has board access and influence over budgets, staffing, and risk decisions.

What the SEC’s four-business-day cyber rule means

For public companies subject to the SEC rule, a material cybersecurity incident generally must be disclosed on Form 8-K Item 1.05 within four business days after the company determines that the incident is material. The clock is triggered by that materiality determination—not simply by discovering an incident. The SEC’s July 26, 2023 release describes a narrow mechanism for delaying disclosure when the U.S. Attorney General determines that disclosure poses a substantial risk to national security or public safety.

The rule also adds annual Form 10-K disclosures about the company’s processes for assessing and managing cybersecurity risk, material effects of risks, board oversight, and management’s role and expertise. SEC Chair Gary Gensler summarized the investor focus this way: “Whether a company loses a factory in a fire — or millions of files in a cybersecurity incident — it may be material to investors.”

For a CISO, the operational implication is that incident response and disclosure readiness need to work together. Security teams need a reliable way to surface facts and changing impacts to the people responsible for determining materiality; the company, not the CISO acting alone, makes that determination. A practiced escalation and decision process can help leadership assess an incident promptly without treating discovery itself as the filing trigger.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can a CISO be held personally liable for a breach?

Personal liability is a contested concern, not an automatic consequence of a breach. Charles Blauner, CISO in Residence at Team8 and former CISO at Citi, described the change in perceived exposure: “Over the last year or so, what had been a difficult job and an under-appreciated job, has now become a job that also potentially puts you at personal criminal or civil liability.” That statement reflects concern about possible exposure; it does not establish that a CISO is personally liable whenever an organization suffers an incident.

One argument against placing responsibility on a single security executive is that boards and other executives control funding, business priorities, and acceptance of residual risk. A CISO may identify a weakness but lack authority to fund or implement a fix. Other practitioners argue that stronger accountability could improve management support and disclosure discipline. The practical distinction is between responsibility to advise and escalate, and authority to decide what the organization will fund or accept.

For that reason, organizations should make risk decisions explicit: identify the risk, the options presented, who had decision authority, and what residual risk was accepted. Legal exposure depends on circumstances, and this overview cannot determine liability in a particular case; organizations and individuals facing a specific matter need qualified legal advice.

Why burnout is a structural problem

CISO burnout is not simply an individual time-management issue. Constant firefighting, expanding attack surfaces, legal and disclosure pressure, inadequate staffing or budgets, and limited business support can combine to make the workload unsustainable. Emily Heath called CISO burnout “a huge problem.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Chartered Institute of Information Security’s 2022/23 report records that 22% of professionals worked more than 48 hours per week and 8% worked more than 55 hours per week. The figures describe security professionals in that report, not every CISO or every organization, but they illustrate the long-hours burden facing the field.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What boards should do to support the CISO

Cyber resilience means being able to absorb an inevitable incident without significant operational or material loss. Andrew Bayers, director of threat intelligence at Resilience, described it as “being able to withstand the impact of an inevitable cyber incident without significant operational or material loss.” The definition shifts the board’s question from whether an incident can be prevented to whether the organization can withstand and recover from one.

  • Set risk appetite. Decide which risks the organization is prepared to accept and which require action, rather than leaving the CISO to infer business priorities.
  • Match expectations with resources. Fund the staffing and controls needed to meet the security outcomes leadership expects. Andrew Shikiar, executive director at FIDO, said, “CISOs are too often overlooked or low on resources, funding and/or business support to properly implement change.”
  • Give security a route to decisions. Ensure the CISO can brief the board or an appropriate board committee, and can raise material concerns before a crisis.
  • Agree incident and disclosure responsibilities in advance. Establish who gathers facts, who assesses materiality, who makes disclosure decisions, and how those decisions are escalated and recorded.
  • Record accepted residual risk. When leadership chooses not to mitigate a known risk, document the decision, its rationale, and the authority accepting it.
  • Plan for continuity and recovery. Evaluate whether the organization can maintain or restore important operations after an incident, not only whether it has preventive controls.

A CISO can advise, coordinate, and challenge, but resilience is an enterprise responsibility. Boards and executives need to own the trade-offs among security, cost, and business operations.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.