In recent years, there has been increasing attention to the strain of the security leadership role. International studies regularly point to stress, burnout and high work pressure as conditions that come with responsibility for an organization's cybersecurity.
Part of that narrative has been based on a number for many years: that the average CISO only stays in the job for 18 months. The number comes from an analysis we conducted ourselves seven years ago – and it has been repeated so often that for most in the industry it appears as a fundamental truth about the role.
A truth we could not recognize ourselves from our observations in the market. To learn more about this, we have just conducted an updated analysis. We have registered the 382 most recent employment periods of security managers in Denmark, of which 225 are current, and the results paint a markedly different picture.
Durability has more than doubled
The average employment period is currently 41 months. If you adjust the figure for those positions where the person has not yet been in the role for a full year, but is still employed, it increases to almost 45 months – equivalent to just over three and a half years.
In comparison, the general employment period for knowledge workers is between 4 and 6 years. In other words, the safety manager role does not differ significantly from other knowledge-intensive positions when it comes to “durability”.
Looking more closely at the distribution among the 225 current CISOs, 63 percent have been in the role for more than two years – and 23 percent, corresponding to 52 people, have been there for over five years.
Why the 18 months still live on as a truth
Part of the explanation is probably that there are a small number of companies that have extremely high turnover in the CISO role and that they occupy a disproportionately large part of the overall storytelling about the role. Added to this is the general tendency for stories about what doesn't work to occupy more space than stories about what does.
The problematic thing about this story about the 18 months as the expected durability for a security manager in the role is when the expectation becomes a self-fulfilling prophecy. When the security manager, who experiences a challenging collaboration with management or the business, moves on based on the assumption that it is within the norm.
What explains the increased durability?
Firstly, the role itself has become more mature and well-defined. Whereas the security leadership role in many organizations was previously vaguely described and constantly changing, today there is more clarity about what the role entails and what mandate comes with it.
Second, those who hold the role today have a different background, experience and approach to the role. In 2019, when the original analysis was done, the CISO role was brand new, those who were given the role were in many cases the technical specialist in the organization with the greatest interest in security. Among the current security leaders, many come from a role as program or project managers, where they are already used to working closely with the business.
A further explanation is that significantly more resources are allocated to the security function today. Whereas the security manager in many Danish companies was previously a “one-man-army”, most now have a team or a real organization, which, all other things being equal, makes the task more sustainable over time.
A role that still lacks diversity
Not surprisingly, only 12 percent of current security leaders are women – a figure that is lower than the generally increasing proportion of women within cybersecurity, which now indicates a proportion of around 14 – 20 percent.
In relation to the estimated 20-30 percent more female leaders in the IT industry, we still have a challenge in making the security manager role attractive to female leaders. A trend we will likely see change as the role increasingly requires communication, stakeholder and general management skills rather than technical insight. We also see in the data that the existing female leaders are recruited from backgrounds other than the classic technical one.
A more nuanced conversation about the role
The updated figures do not change the fact that some safety leaders continue to leave the role early, or that collaboration with management and the organization remains challenging for some. But they do provide a more accurate starting point for the dialogue about the role.
Perhaps the most important conclusion is therefore not that the safety leadership role itself has become a more “sustainable” job, but that we as an industry need to regularly challenge the narratives we take for granted – because the stories we choose to tell about a role ultimately shape how those who occupy it understand their own situation.
The analysis was conducted by CPH Talent House and is based on 382 employment periods for security managers in Denmark, of which 225 are current. The results were first detailed in the first episode of season 3 of the podcast Onsdagstanker.