The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →A July 2024 survey found that 70% of 400 U.S. and U.K. IT-security decision-makers said stories about CISOs being held personally liable had negatively affected their opinion of the role. That is a measure of perception—not proof that 70% of CISOs are liable, plan to quit, or will be prosecuted. The concern is real, but legal exposure generally turns on a person’s conduct, duties, and decisions, not simply on whether their organization suffered a cyberattack.
What the 70% figure measures
BlackFog’s July 2024 survey covered 400 IT-security decision-makers at organizations with more than 500 employees: 200 respondents in the United States and 200 in the United Kingdom. The question asked whether stories of CISOs being held personally liable had negatively affected respondents’ opinion of the role. The survey was not limited to sitting CISOs.
The result does not measure how many CISOs have been sued, how many intend to leave, whether candidates have rejected jobs, or an individual’s odds of prosecution. It also does not represent smaller employers or security professionals outside those two countries. BlackFog’s survey summary and research report provide the finding and methodology.
Why personal exposure is getting more attention
The CISO’s job increasingly touches governance and public accountability as well as technical security. Public-company cybersecurity disclosure rules, regulatory scrutiny, investor attention, and enforcement actions have raised the stakes around what an organization says about its security risks and incidents. A CISO may help assess risk or brief executives, but may not control the final disclosure, remediation budget, business decision, or incident statement.
#1 Best Overall
Exposure depends on the executive’s actual responsibilities, reporting line, corporate role, jurisdiction, employment terms, and conduct. Being an operational security leader is not automatically the same as being a corporate officer with formal legal or fiduciary duties. Nor does an attack by itself establish negligence or personal liability.
What the Uber and SolarWinds cases do—and do not—show
Uber: a criminal case involving breach handling
In 2022, former Uber chief security officer Joe Sullivan was convicted of obstruction of justice and misprision of a felony in connection with the company’s handling of a 2016 breach. The case concerned alleged concealment and misrepresentation, not simply a failure to prevent attackers from accessing data. The U.S. Department of Justice’s announcement describes the conviction.
SolarWinds: civil securities-law claims, not a criminal prosecution
In October 2023, the SEC charged SolarWinds and its CISO with fraud and internal-control violations tied to cybersecurity disclosures and internal security practices. The action made individual executive exposure highly visible, but a charge is not a final finding of liability. In July 2024, a federal court dismissed most of the SEC’s claims while allowing some to proceed; that procedural ruling did not establish that the CISO was liable. The SEC’s announcement sets out its allegations, and Reuters’ report on the court ruling describes the later development.
The cases involve different legal theories: Uber was a criminal prosecution related to breach handling, while SolarWinds is a civil securities and regulatory matter. The common practical lesson is narrower than “a breach makes the CISO liable”: investigators may focus on what an executive knew, said, documented, concealed, certified, or escalated.
The accountability gap: responsibility without authority
A CISO may be expected to oversee controls, incident readiness, vulnerability management, risk reporting, regulatory coordination, and executive communication. Yet decisions that shape security outcomes may sit elsewhere: product deadlines, business-unit technology choices, staffing, budget, legacy-system replacement, risk acceptance, and public disclosure language.
This mismatch matters both for governance and for a prospective CISO’s personal risk. A role with broad accountability but no credible way to raise concerns, obtain resources, or record who accepted a risk leaves the executive poorly positioned to do the job. Before accepting or renewing a role, establish whether the CISO has:
Rank #3
- Direct access to the board or audit committee, with a defined escalation route when executive concerns remain unresolved.
- Clear authority over security decisions—or a formal process to record who can override recommendations and accept the resulting risk.
- A defined part in incident and disclosure workflows, including who drafts, reviews, approves, and communicates statements.
- Budget, staffing, and remediation expectations that match the organization’s risk profile and stated security commitments.
- A process for preserving recommendations, risk decisions, remediation deadlines, and executive overrides in appropriate records.
Documentation can help establish what was raised and decided, but it has trade-offs: maintaining it takes time, and records may be discoverable. Direct board access can improve escalation while creating friction with executives. The goal is not paperwork for its own sake; it is a workable governance process that connects responsibility to authority and recorded decisions.
What other surveys say about concern and insurance
BlackFog’s findings show mixed views rather than uniform opposition to accountability. In the same survey, 34% viewed prosecution of individuals after a cyberattack as a “no-win” situation, while 49% believed possible prosecution could improve accountability and transparency. Forty-four percent said their organization had introduced processes to reduce cybersecurity exposure as scrutiny increased; 41% said boards were taking cybersecurity more seriously, but only 10% reported additional cybersecurity spending. Fifteen percent believed the trend would deter future IT professionals from becoming CISOs. These are respondents’ reported views and experiences, not measured changes in hiring or spending across the market. BlackFog provides the survey figures.
A separate 2024 Voice of the CISO report found that 66% of surveyed CISOs worldwide were concerned about personal, financial, and legal liability; 72% said they would not join an organization without D&O insurance or equivalent protection against financial liability following a successful cyberattack. Heidrick & Struggles’ 2024 global CISO survey found that more than half of respondents agreed or strongly agreed that D&O insurance would not protect them from personal liability in a breach. In its U.S. results, 65% reported D&O coverage, while 29% did not know whether they were covered. These surveys use different populations and questions and should not be combined as if they measured the same thing. Read the Voice of the CISO report and Heidrick’s survey.
The data does not establish a mass CISO exodus. It does point to plausible pressures: candidates may prefer advisory or vendor roles, avoid public-company positions with weak governance, or refuse roles without adequate protection. Those are possible labor-market effects, not a demonstrated departure rate.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What protections a CISO should examine
Insurance and contract language can reduce some financial risk, but neither creates authority or excuses inaccurate statements or intentional misconduct. A CISO should have counsel and an insurance broker review the actual agreements and policy wording, rather than rely on verbal assurances.
Indemnification and legal-cost advancement
Ask whether the company will indemnify the CISO for covered actions within the scope of employment and advance reasonable defense costs while a matter is pending, rather than reimburse expenses only after it ends. Clarify treatment of civil and regulatory investigations, subpoenas, interviews, and testimony, as well as whether protection continues after termination. Indemnification is subject to applicable law and agreement terms; it may not protect intentional misconduct, fraud, or criminal conduct.
Recommended Free Tools
Independent counsel and changes to the role
Determine when the CISO can consult independent counsel and who pays if the executive’s interests conflict with the company’s. Consider severance protections if a material reporting-line change or removal of authority leaves the CISO accountable for duties they can no longer perform. Written access to relevant records after departure may also matter, subject to company policy and law.
Know what each insurance policy does
- D&O insurance may cover certain claims arising from management decisions, but a CISO’s insured status, covered investigations, defense-cost treatment, limits, retentions, and exclusions depend on the policy.
- Cyber insurance primarily protects the organization against specified incident costs and liabilities; it is not automatically personal coverage for a CISO.
- Professional-liability or errors-and-omissions coverage may address claims tied to professional services, but an employed CISO must verify that the policy covers their role and circumstances.
- Employment-practices liability insurance generally addresses employment-related claims, not core cybersecurity liability.
- Dedicated CISO professional-liability coverage is an emerging product category. Crum & Forster announced a CISO-specific product in November 2024; availability, eligibility, jurisdiction, exclusions, and terms need to be confirmed with the insurer or broker. See the announcement.
No policy should be assumed to cover fraud, intentional concealment, criminal fines, punitive damages, or conduct excluded by law or the contract. A corporate policy may also change or lapse, and the executive may not know whether they are an insured person.
A checklist for evaluating a CISO job
- Map the reporting line. Ask who the CISO reports to, whether board or audit-committee access is direct, and whether a reporting change triggers contractual protection.
- Identify decision rights. Ask who can stop unsafe deployments, approve exceptions, accept residual risk, and override security recommendations—and how those decisions are recorded.
- Clarify disclosure duties. Determine whether the CISO drafts, reviews, certifies, approves, or only advises on incident and public disclosures, and who makes the final decision.
- Review the contract with counsel. Examine indemnification, advancement of fees, independent counsel, survival after termination, severance triggers, and access to relevant records.
- Verify insurance directly. Confirm insured status and ask about regulatory investigations, defense-cost advancement, exclusions, limits, deductibles or retentions, cancellation or reduction, and post-employment coverage.
- Test the resourcing assumptions. Review security staffing and budget, vulnerability backlogs, third-party exposure, legacy systems, and incident-response readiness against the duties the role is expected to meet.
For boards and CEOs, the corresponding governance test is whether the organization has a clear security-risk owner, an escalation route, resources aligned to risk, a defined disclosure workflow, and a documented method for accepting risk. A CISO cannot substitute for those organizational decisions.
Does the headline mean CISOs should avoid the role?
No. It means candidates and employers should treat authority, governance, contracts, and insurance as part of the job—not as details to sort out after a crisis. Personal exposure is not automatic after a breach, and the cited cases do not support treating every security failure as individual wrongdoing. The sharper question is whether a CISO can demonstrate the authority, resources, escalation path, documentation, and legal protection needed to perform the duties for which they may later be held accountable.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




