Industry surveys have long put CISO tenure below that of other C-suite roles, and part of the reason is a double standard. During recruitment, the focus is technical depth, security experience, and leadership. But when budget season arrives and the board weighs a leader’s performance, the lens is cost, growth, customer trust, and brand protection.
Many CISOs feel this acutely. They came up through security, or through risk and compliance, and that is where they are fluent. Their board is not. It wakes up thinking about cost, growth, and customer commitments, and a security leader who cannot connect their work to that language will be seen as important, but rarely as strategic.
Some of this comes down to how the job has been defined. For a long time, a CISO’s success has been measured by proving a negative, by showing that nothing went wrong. That is an impossible assignment, and it frames the entire function as insurance rather than a business driver.
The business is not wrong to expect this
Security plays a significant role in buying decisions. In McKinsey’s early-2026 survey of more than 3,000 enterprise technology buyers, data privacy and compliance ranked as the single most important customer concern, named by over half of respondents, and providers that fall short on security and compliance were increasingly excluded from consideration regardless of price or features. The same survey found that among buyers who switched providers in the past year, cybersecurity was the number one reason they left, ahead of price, coverage, and reliability. Trust makes or breaks the deal. And yet at most companies security is still treated as the team that slows things down, buried in a review that starts only after everyone else has agreed to move forward.
I see the same thing from the CEO seat, as a buyer and as a boss. When I talk with my own CISO, I do not ask how many alerts his team closed. I ask three things. How are you making us stronger? How are you helping us grow? And how will we recover if something goes wrong? Every CISO I know can talk about strength and recovery. Far fewer can concretely show how they enable business growth by proving trust to close deals.
Why the gap is so hard to close