CISOs are burning out because operational load is unbounded while resources are flat, not because pay is low. Four verified drivers: security budgets grew just 4% in 2025, the slowest in five years, with only 11% of CISOs describing their teams as adequately staffed; 46% of security leaders spend more time maintaining tools than defending the organization; 52% of CISOs say their scope is no longer fully manageable; and burnout runs 63% in organizations without full visibility capability versus 44% in those with it. Compensation is a floor condition. Operational discipline is the differentiator.

That last pair of numbers is the whole argument. Two organizations, same threat landscape, same salary bands, 19 points apart on burnout based on whether the work is visible. You cannot pay your way across that gap. You can instrument your way across it.

## The retention numbers don't match the pay numbers

Security compensation is good and getting better, and people are leaving anyway. That contradiction is the starting point for anything useful about retention.

IANS Research and Artico Search surveyed more than 500 security professionals for their [2026 Cybersecurity Talent Report](https://www.iansresearch.com/resources/press-releases/detail/new-ians-and-artico-search-report-finds-only-34--of-cybersecurity-professionals-plan-to-stay-in-their-current-roles), published in April 2026. Headline finding: **only 34% plan to stay with their current employer.**

The same research puts median pay for a security analyst at $113,000, a security architect at roughly $188,000, and a functional security leader at $256,000, with large enterprises paying 18% to 20% above average (IANS/Artico data as reported by Security Boulevard, since the underlying report is paywalled). Two thirds of a well-paid profession are eyeing the door.

When high pay and low retention coexist in the same population, you are not looking at a compensation problem.

## What the burnout surveys actually measured

Burnout figures here get quoted as a single range. They should not be. Four 2025 to 2026 instruments surveyed four different populations with four different question wordings, and mashing them into "63% to 76% of CISOs are burned out" is the fastest way to get a retention memo fact-checked into the bin.

| Source | Who was asked | Sample | Figure |
|---|---|---|---|
| Proofpoint, *2025 Voice of the CISO* | CISOs at orgs with 1,000+ employees, 16 countries | 1,600 | **63%** experienced *or witnessed* burnout in the past year |
| Splunk, *CISO Report 2026* | CISOs reporting on **their teams** | 650 | **Nearly two-thirds** of security teams at moderate to significant burnout |
| Sophos, *The Human Cost of Vigilance* | **IT and** cybersecurity professionals, 17 countries | 5,000 | **76%** burned out "constantly, frequently, or occasionally" |
| Bitsight, *State of Cyber Risk and Exposure 2025* | Cyber risk and security leaders, orgs 500+ | 1,000 | **47%** reporting exhaustion |

Read the qualifiers. Proofpoint's 63% includes people who *witnessed* burnout in others. Sophos surveyed a broader IT population and counted "occasionally." Splunk's figure is about teams, reported secondhand by their bosses. Bitsight asked the same seniority tier as Proofpoint and got 47%.

The honest summary: burnout among security leaders sits somewhere between "half" and "most," and the exact number depends entirely on who you count. That is enough to act on. It is not enough to build a slide that says 76%.

## The compensation lever is real, and it's small

Raises work. They just do not work the way most retention plans assume, and the strongest evidence comes from the compensation researchers themselves. IANS and Artico state it plainly in their own report: "Compensation remains important, but it is not the primary driver of retention." Two findings explain why.

**Wage growth beats wage level.** Employees receiving even modest pay increases report significantly higher satisfaction and are more likely to stay than those with flat compensation. A raise functions as a *signal* that someone noticed. The absolute number matters less than the fact of movement.

**Perceived organizational backing swamps everything else.** Among security staff who see security as a core organizational priority, **73% report being satisfied with their careers. Among those perceiving little or no organizational backing, 19% do.** That is a 54-point satisfaction gap on a variable with a budget line of zero dollars.

So no, do not stop giving raises. Underpaying is a fast way to lose people for a reason you fully control. But understand the ceiling: a raise converts a resentful engineer into a slightly better-paid resentful engineer if the queue is still bottomless. What separates the 73% from the 19% is whether the organization visibly runs security like it matters, and "visibly" is a systems property, not a sentiment.

## Where the hours actually go

The load is rising while the resource base contracts. Both halves are measured.

**The resource base is shrinking in real terms.** IANS and Artico's [Security Budget Benchmark](https://www.iansresearch.com/resources/press-releases/detail/ians-research-and-artico-search-release-security-budget-benchmark-report), fielded from April 2025 across 587 CISOs, found security budget growth slowed to **4% year over year, the lowest in five years**, down from 8% in 2024. Security as a share of IT spend fell from 11.9% to 10.9%, breaking a five-year upward trend. Staffing growth hit a four-year low of 7%, and **only 11% of CISOs describe their teams as adequately staffed.**

**The scope keeps growing.** IANS and Artico's 2026 State of the CISO Benchmark (662 CISOs, fielded April to November 2025) found **52% say their scope is no longer fully manageable**, and nearly seven in ten are open to a career move within the next year. Splunk's CISO Report 2026 shows the mechanism: nearly all CISOs now own AI governance and risk, four in five oversee DevSecOps, and nearly three in four say the role has become significantly more complex.

**The gap gets filled with toil, not defense.** Splunk's State of Security 2025 surveyed 2,058 security leaders across nine countries with Oxford Economics. The results are a portrait of a profession doing maintenance work:

- **46%** spend more time maintaining tools than defending the organization
- **59%** name tool maintenance as their main source of inefficiency
- **57%** lose investigation time to data management gaps
- **59%** face too many alerts, **55%** too many false positives
- **52%** say their team is overworked
- **52%** say job stress has prompted them to consider leaving cybersecurity entirely

A Sapio Research survey of 300 security and IT leaders, reported by Help Net Security in March 2026, adds the hours: an average of **10.8 extra hours per week** beyond contracted schedules, with nearly half logging 11 or more. Nearly half say the job feels emotionally exhausting more often than it feels rewarding, most acutely at C-level. And yet 94% would choose cybersecurity again.

Hold those two facts together, because they are the diagnosis. **They love the work. They hate the operating conditions.** Nobody quits a job they would choose again over the salary.

## The clearest case study is a seven-person team and a bug bounty inbox

Surveys tell you how people feel. For how the load actually accumulates, the best available data is first-party and public: Daniel Stenberg's July 2025 post ["Death by a thousand slops"](https://daniel.haxx.se/blog/2025/07/14/death-by-a-thousand-slops/) documents curl's security intake in operational detail. The 2025 numbers:

- roughly **two security submissions per week**
- only about **5% turned out to be genuine vulnerabilities**, down from a historical rate north of 15%
- roughly **20% of all submissions were AI-generated**
- **three to four people engage per report**
- each report costs **"30 minutes, sometimes up to an hour or three. Each."**
- the security team is **seven people**, several of whom have only **three hours per week** for curl

Do the arithmetic on the page, because nobody in this conversation ever does. Two reports a week, times about 3.5 people engaging, times roughly 1.5 hours each, is on the order of **10 person-hours per week** consumed by intake. The team members budget three hours each. The yield is roughly **one real vulnerability every ten weeks.**

That is not a staffing shortfall. Ten more engineers would produce the same ratio at higher cost. It is an intake process with no valve: no bound on volume, no clock on any individual item, no mechanism that converts "we are drowning" into a number anyone can act on. We covered the volume side of this in [AI slop is flooding bug bounty triage](/blog/ai-slop-flooding-bug-bounty-triage) and the economics in [A $25 bug worth $500,000](/blog/ai-cheap-vulnerability-research-vdp-triage-economics). This is the labor side of the same shift.

If you run a security function at a 200-person company, you have this exact structure. You just do not have Stenberg's willingness to publish the numbers.

## When load has no valve, the intake becomes the valve

Here is what happens when unbounded load meets fixed capacity for long enough. In six months, three of the most competent security operations in open source reached the same conclusion independently.

**January 2026:** curl ended its bug bounty program, accepting HackerOne submissions through January 31 and moving to direct GitHub reporting from February 1. Stenberg's reasoning, per [The Register](https://www.theregister.com/2026/01/21/curl_ends_bug_bounty/), was explicitly about load: "The current torrent of submissions put a high load on the curl security team and this is an attempt to reduce the noise."

**March 2026:** the Internet Bug Bounty paused new submissions, effective March 27, having paid out more than $1.5 million since 2012. HackerOne's explanation is the most consequential sentence in this story: "AI-assisted research is expanding vulnerability discovery across the ecosystem, increasing both coverage and speed. The balance between findings and remediation capacity in open source has substantively shifted." In the same window, Node.js moved to accepting reports without paying bounties and Google's OSS VRP halted AI-generated submissions.

**July 2026:** curl declared a ["summer of bliss."](https://daniel.haxx.se/blog/2026/06/15/curl-summer-of-bliss/) HackerOne submissions and the security email went dark from July 1 until August 3. The project had been "under a huge pressure for the last four months or so. Now we need some rest," Stenberg wrote, adding pointedly: "We do not expect this deluge to be over."

The reflexive answer here is "just outsource triage." But the largest triage platform in the world has now conceded that discovery has outrun remediation capacity. Outsourcing moves the black box rather than removing it, and the vendor is telling you the box is full.

Note what none of these three did. Nobody hired their way out. Nobody found a better tool. **The only control any of them could reach was the intake itself.** That is what an operating model with no valve looks like at the limit: the last lever available is the off switch, and pulling it is worse for everyone, researchers included.

## Why "just turn it off" stops being an option on September 11

Commercial security teams do not get curl's option, and the deadline is now measured in weeks.

From **September 11, 2026**, the EU Cyber Resilience Act requires manufacturers placing products on the EU market to file an **early warning to ENISA within 24 hours** of becoming aware of an actively exploited vulnerability, a **full notification within 72 hours**, and a **final report within 14 days**. It applies regardless of where the company is headquartered. Penalties reach €15 million or a revenue-linked alternative. We walked through the full obligation set in [what the EU Cyber Resilience Act means for vulnerability disclosure](/blog/eu-cyber-resilience-act-mandatory-vulnerability-disclosure).

Put the trajectory in one line. Intake volume rising. Valid-report rate falling. Budget growth at a five-year low. Headcount flat. And a statutory 24-hour clock arriving in six weeks.

You cannot answer a 24-hour regulatory clock with an inbox and good intentions. "Becoming aware" is a timestamp, and a regulator will ask you to produce it. That requires an acknowledgment SLA that runs automatically, an escalation path that pages a named human, and a defensible record of when you knew what. Teams that already have those will experience September 11 as a config change. Teams that do not will experience it as the thing that finally breaks the person holding the inbox, a failure mode we have already documented in [what happens when the disclosure clock is ignored](/blog/when-researchers-go-public-botched-disclosure).

## Are CISOs really quitting every 18 months?

Probably not. This is the piece of the narrative most likely to be wrong, and it gets repeated uncritically in almost every article on the subject.

The alarmist figure comes from Cybersecurity Ventures' 2026 CISO Report, produced with Sophos, which puts large-enterprise CISO tenure at **18 to 26 months** against nearly five years for other C-suite roles. Two other datasets disagree. IANS and Artico's 2026 State of the CISO Benchmark, surveying 662 CISOs, reports an **average tenure of nine years** in the role. Ross Haleliuk's *Venture in Security* analysis of **526 Fortune 500 companies** found CISOs averaging **4.5 years in role with a 3.6-year median**, at or above CMO (3.5) and CHRO (3.7). Of 36 departing Fortune 500 CISOs he tracked, 18 took another security leadership role elsewhere and only 2 became consultants. Gartner's much-quoted February 2023 forecast that half of cybersecurity leaders would change jobs by 2025 is a prediction about a year that has now passed, with no published validation.

The honest synthesis is more useful than either extreme. **CISOs are not fleeing the profession. They are churning between employers.** That is exactly what "nearly seven in ten open to a move within the next year" and "only 34% plan to stay" describe, and it matches the 94% who would choose cybersecurity again.

Churn, not exodus. And churn is *worse* news for you specifically, because the people leaving are not rejecting the work. They are rejecting how the work is run where they are, and taking the same job at a company that runs it better. Do not expect the market to bail you out either: Cybersecurity Ventures estimates 35,000 CISOs employed globally in 2026, up from 32,000 in 2023, against roughly 359 million businesses worldwide. That estimate is vendor-partnered with no disclosed methodology, so treat it as directional. Directionally it is decisive. **3,000 net new leaders in three years will not rescue anyone.** The only variable moving at the speed of the problem is how much load each existing leader absorbs.

## What to instrument instead of what to pay

The prescription follows from the two measured gradients: Bitsight's 19-point burnout spread on visibility, and IANS' 54-point satisfaction spread on perceived organizational backing. Both are properties of systems, not salaries. Five moves, in order of relief bought per hour invested:

1. **Publish an acknowledgment SLA and put a clock on it.** One number, public, enforced automatically. The value is not the promise to researchers. It is that "did anyone respond to that?" stops being a question your security lead answers from memory at 11pm.
2. **Define per-severity resolution targets and render them publicly.** A critical finding and an informational one should not share a deadline. Publishing the matrix converts an unbounded obligation into a bounded, defensible commitment, which is also what an EU regulator will ask to see.
3. **Escalate on a schedule to a named on-call human, with cooldowns.** Escalation without a rotation just pages the same exhausted person. Escalation without cooldowns produces the alert fatigue 98% of Splunk's CISOs already cite. Both halves are required.
4. **Ledger every bounty decision and disbursement.** Payout state should be a query, not a recollection. "Did we ever actually pay that researcher" is a recurring source of both leader anxiety and researcher fury, and we unpacked the fairness dimension in [bug bounty payout disputes](/blog/bug-bounty-payout-disputes-resolution-sla-fairness).
5. **Report MTTA, MTTR, and SLA compliance to the board monthly.** This is the direct lever on the 73%-versus-19% split. A team whose leader can *show* the function running to a standard is a team that perceives organizational backing, without a dollar of new budget.

None of that requires a specific vendor. All of it requires that the operating model live somewhere other than one person's head. Starting from zero, [how to set up a vulnerability disclosure program](/blog/how-to-set-up-vulnerability-disclosure-program) covers the ground floor.

<div class="blog-inline-cta">
  <p><strong>Running disclosure out of a shared inbox?</strong> Kit's CSIRT module ships acknowledgment and per-severity resolution SLAs, on-call rotation, an append-only payout ledger, and board-ready MTTA/MTTR metrics, self-hosted alongside your hiring pipeline.</p>
  <p><a href="/users/sign_up">Start your free trial</a></p>
</div>

## How Kit's CSIRT module implements this

Kit is not a burnout product. It is a disclosure-operations product, and the retention effect is second order: it makes load bounded, timed, and visible, the three properties separating a 44% burnout organization from a 63% one.

**SLAs that run on a clock, not a memory.** You set one acknowledgment window for the whole program, 72 hours by default, plus a resolution target per severity: super critical 24h, critical 72h, high 7 days, medium 14 days, low and informational 30 days. Every report then carries its own live status, on track, at risk, or breached, and flips to *at risk* once three quarters of its window is gone. The queue sorts by whatever is closest to the edge. Nobody has to be the clock.

**Escalation that pages a named human, designed against alert fatigue.** When a report runs out of window, Kit pages the person on call, posts a breach card to Slack, and opens a PagerDuty incident. A six-hour cooldown per report stops one stuck case from re-paging all evening, and findings your team has already judged informational are still tracked as breaches without waking anyone.

**On-call rotation so "who owns the inbox tonight" is never open.** Assign manually, run an automatic daily or weekly rotation with the handoff day and hour you choose, or sync against the PagerDuty schedule you already keep. New reports land on whoever is on shift, and handoffs and shift changes get announced. When a slot ends up with nobody in it, Kit says so, instead of you discovering it from an angry post.

**A payout ledger instead of a spreadsheet.** Every bounty decision and every payment is written to an append-only ledger: approvals, adjustments, disbursements initiated, completed and failed, tax documents submitted, verified and rejected, and revocations. Entries cannot be edited after the fact, sensitive details are encrypted, and Kit re-checks the books against themselves on a schedule. "Did we ever actually pay this researcher" becomes a lookup.

**Metrics that answer the board question without a data pull.** MTTA, MTTR, SLA compliance percentage, total bounty paid, reports over time, and reports by severity, with each viewer seeing only the reports their permissions cover. And because resolution targets are configured once and published worst-severity-first on your public policy page, the promise a researcher reads is the same commitment the escalation runs on.

**The honest limits.** Kit does not reduce how many reports arrive, eliminate triage judgment, or turn a two-person team into a five-person one. It converts unbounded, invisible, memory-held work into bounded, timed, delegated, reportable work. Per Bitsight, that difference is worth 19 points of burnout. Per IANS, the perception of a well-backed security function is worth 54 points of career satisfaction.

## The bottom line for a retention plan written this quarter

Pay the market rate, and give the modest raise: underpaying loses people for a reason you fully control, and movement works as a signal that someone is paying attention.

Then stop. The next dollar does not belong in a counteroffer. It belongs in making the queue visible.

The people leaving are not rejecting the work. Ninety-four percent of them would choose this profession again. They are rejecting a job where the queue has no bottom, nothing has a visible clock, and there is no way to show anyone that the work is bounded. That is fixable, and unlike a salary band, it is fixable this quarter. If you are also rebuilding the team, [what CTF performance actually tells you about security engineers](/blog/hiring-security-engineers-ctf-performance-signal) covers the hiring side of the same problem.