The Other Side of the Security Desk
For years, the Chief Information Security Officer has been one of the most visible roles in enterprise technology — and one of the least understood. A new docuseries called "Declassified" aims to change that, giving sitting and former CISOs an unfiltered platform to speak candidly about what the job is actually like.
The series, covered by Dark Reading, features stories that range from harrowing to deeply personal: million-dollar data heists, the psychological toll of leading incident response under public scrutiny, career-ending burnout, and in at least one case, a divorce tied directly to the relentless pressure of the role.
What CISOs Are Actually Saying
Historically, CISOs have been reluctant to speak publicly about their worst experiences. The reasons are well-documented — NDAs, liability concerns, reputational risk, and the fear of being seen as the person who "failed" when a breach occurred. "Declassified" creates a structure where these conversations can happen, even if some details remain anonymized.
The recurring themes are striking:
- The isolation of the role — CISOs frequently describe feeling caught between the board (demanding certainty they can't provide) and technical teams (demanding resources that never fully materialize)
- Impossible accountability — being held responsible for outcomes shaped by decisions made well above their pay grade
- The breach aftermath — several participants describe the period following a major incident as more damaging to their mental health than the incident itself
- The decision to leave — multiple CISOs in the series describe choosing to exit corporate security leadership after their first major breach, not because they were pushed out, but because they simply couldn't envision repeating it
The Burnout Crisis is Real
The cybersecurity industry has published enough surveys on CISO burnout to fill a filing cabinet. What "Declassified" does differently is put faces and stories to the statistics. The average CISO tenure in large enterprises sits around 18-26 months — and the series suggests this isn't primarily about compensation or career advancement. It's about sustainability.
The factors are compounding: 24/7 on-call expectations, the speed of the threat landscape, board relationships that frequently lack technical fluency, and an industry culture that still quietly blames the security leader when a breach occurs — regardless of context or resources.
One CISO in the series describes receiving a call from their spouse at 2 AM during an active ransomware response, not to check in, but to say they'd reached a breaking point. The incident itself was eventually contained. The marriage wasn't.
Why This Matters for the Industry
The CISO pipeline is not infinite. The combination of high demand, high accountability, limited authority, and chronic stress has created a retention problem that most organizations have only partially acknowledged. "Declassified" is a cultural artifact, but it may also serve a practical function: making it easier for aspiring security leaders to walk into the role with realistic expectations, and for current CISOs to recognize that their struggles are systemic, not personal failures.
There's also a governance angle. Boards that watch this series may walk away with a more nuanced picture of what their CISO is actually managing — which, in the best case, translates into better resource allocation, clearer authority, and more sustainable working conditions.
Key Takeaways
- CISOs face structural isolation that is poorly understood by the boards they report to
- Burnout and career exits are systemic, not individual failures
- The breach aftermath is often more damaging to CISO wellbeing than the breach itself
- Realistic expectations — both from CISOs and their organizations — could meaningfully improve retention
- Human stories may accomplish what industry surveys have not: shifting how organizations think about the CISO role
Further Reading
- CISO burnout and tenure data — Gartner, 2025
- Dark Reading — CISOs Break Their Silence in 'Declassified' Docuseries