A recent survey of 1,001 chief information security officers in the United States and United Kingdom found that half are thinking about leaving the profession after the arrival of Anthropic Mythos and similar cyber-capable artificial intelligence models and tools. Only a quarter disagreed with that statement, according to the survey. The findings highlight growing concerns among security leaders that rapidly advancing AI capabilities, combined with existing liability and authority challenges, are making their jobs increasingly difficult to sustain.
The data reveals additional pressure points for security executives. Sixty percent of CISOs reported that demands from boards and executive leadership to implement AI are moving faster than their organizations can safely govern and secure its adoption. Separately, a survey released earlier in the year showed 78% of CISOs are worried about personal liability for security incidents, up from 56% a year earlier. Eighty-nine percent of security chiefs say the rapid pace of technology advancement presents a challenge. Meanwhile, the average CISO tenure has dropped to 18 months, and experienced leaders are retiring, shifting to less stressful security positions, moving into consulting or sales support roles, or exiting the field entirely.
Christine Gadsby, chief security advisor at BlackBerry and former CISO until last September, described the current environment as "madness" and said she doesn't miss holding the top security role. "As an industry, we built the CISO role to take all of that liability and now we act surprised when people want out," she stated. One CISO at a large software company, who requested anonymity, said some days feel exhausting and overwhelming. Oliver Legg, co-founder and cybersecurity recruiter at Aspiron Search, noted a shift in candidate priorities: "Two years ago, we had CISO candidates ask about budget and headcount. Now, the first questions are about indemnification and D&O coverage."
Analysts and industry observers say the solution requires structural changes, including establishing minimum standards for responsible behavior that could shield CISOs from legal liability. IDC analyst Chris Kissel argued that governing bodies need to mandate baseline requirements that remove CISOs from legal jeopardy. On the AI front, Omar Khawaja, who teaches at Carnegie Mellon University's CISO and CAIO programs and serves as global field CISO at Databricks, said frontier models like Mythos don't fundamentally change what security teams need to accomplish, but rather alter "how well, and how fast, and how much of it we need to do." Security programs will need to become far more agentically driven with proper safeguards, he explained, and organizations should start with lower-risk AI use cases before scaling up. Mike Privette, former CISO and founder of Return on Security, countered that while frontier models are accelerating threat complexity, many security chiefs are more energized than ever, particularly when they have executive support, appropriate budgets, and room to experiment.
The path forward depends on whether companies and regulators can address liability concerns while giving security leaders the authority and resources to manage AI risks effectively. For now, the profession faces a compounding problem: veteran CISOs departing leave companies hiring less-experienced replacements who are even more susceptible to burnout, creating additional security vulnerabilities at a time when threats are evolving faster than ever. Organizations embracing the challenge will need to balance rapid AI adoption with the security guardrails and leadership support necessary to keep their top cyber defenders in the fight. The current landscape demands a fundamental rethinking of how accountability is distributed and how security leadership is empowered, rather than simply expecting individuals to absorb mounting personal and professional risk indefinitely.

