While the major causes of CISO burnout get a fair amount of coverage at conferences and in the media—issues like the latest cybersecurity threats, budget cuts, or growing pressure from the board to keep your organization safe—one longstanding and growing stressor remains under the radar: losing a good part of your staff to attrition.
Replacing the talent can be challenging enough for those chief information security officers, especially given the worsening shortage in this high-stress industry. But staff turnover can present other maybe-less-obvious problems for security chiefs, enterprise leaders, board members and all others responsible for overseeing cybersecurity.
“It’s not just about replacing an employee—it’s about rebuilding the trust, expertise, and situational awareness that walk out the door with them,” says Pablo Riboldi, CISO at BairesDev, a nearshore software development company.
“As the threat landscape evolves quickly, losing skilled employees can undermine a company’s security stability and growth posture,” he says. “In some cases, turnover can even heighten the risk of misconfigured systems, overlooked vulnerabilities, or delayed detection of threats.”
And it’s not just the loss of front-line workers, like those on your threat intelligence squad, that threaten cybersecurity. Instability also comes from turnover among the higher-ups—senior executives such as the chief financial officer, chief information officer, chief technology officer, or even business-line leaders who might play key roles in keeping organizations safe.
CISOs might be limited in what they can do to keep other C-suiters on board, but they can take initiatives to prepare for the eventual turnover of their security teams. And as industry statistics indicate, turnover rates aren’t likely to improve anytime soon.
Why it’s time to pay attention to security team turnover
The staffing stats are daunting: About 60% of more than 500 cybersecurity professionals in the U.S. and Canada surveyed said they were considering a job change, according to the 2025 Cybersecurity Staff Compensation Benchmark Report, released in February by research firm IANS Research and executive search firm Artico.
“It’s not just about replacing an employee—it’s about rebuilding the trust, expertise, and situational awareness that walk out the door with them.”Pablo Riboldi, CISO, BairesDev
Only one-third of the respondents said they would recommend their employer, and fewer than 40% were satisfied with their advancement opportunities. While compensation remains a factor in whether to stay with a current job, the ability to develop new skills and advance within the organization has a greater impact on retention, the report notes.
And CISOs can hardly afford to lose any of the talent they have. In its 2024 Cybersecurity Workforce Study, cybersecurity professional association ISC2 found that the size of the active global workforce had grown by only 0.1% from the previous year. The size of the workforce gap was 4.8 million worldwide, up 19% from the year earlier. And the total workforce needed to satisfy demand was 10.2 million, up 8.1%.
“Frequent changes in key personnel can leave gaps in institutional knowledge, slow down incident-response times, and delay the implementation of strategic initiatives,” says Riboldi.
[Read also: And what happens when the CISO leaves? These 5 succession plans will keep orgs safer]
Here at Focal Point, we’ve been exploring the various ways to keep security departments running smoothly, from how to handle CISO turnover to specific strategies utilized by security chiefs profiled in our “CISO Success Story” series. We surveyed CISOs and other experts for tips on how to tackle the increasing strain of security team turnover. Here are six best practices to consider.
1. Build a structured knowledge management process
Sometimes the bigger problem is not so much the people leaving the company but the knowledge that goes with them.
“CISOs should proactively map critical security functions… and ensure coverage through internal cross-training or ready-to-go external talent pipelines.”Casey Marquette, CEO, Covenant Technologies
Documenting security procedures, system configurations, and incident response playbooks ensures that critical knowledge doesn’t leave with the departing individual, Riboldi says.
“A centralized, regularly updated knowledge base enables smooth transitions and empowers remaining team members to step in confidently when needed,” he says. “It’s important to document everything; if something has happened once, it could very well happen again.”
[Read also: How a Barclays CISO manages the regulators]
Creating a skills map can help companies deal with staff turnover, advises Casey Marquette, CEO at Covenant Technologies, a provider of IT and cybersecurity staffing and recruiting services. “CISOs should proactively map critical security functions—[for example] incident response, identity management, and cloud security—and ensure coverage through internal cross-training or ready-to-go external talent pipelines.” Organizations with no plan in place lose precious time—“and often, visibility,” he says—when key players exit unexpectedly.
2. Invest in cross-training and role redundancy
Riboldi agrees organizations need to ensure that security team members are cross-trained to cover one another's responsibilities. “This not only increases team flexibility but also reduces operational disruption when someone leaves,” he says.
“Encouraging team members to understand multiple roles within the security function ensures operational continuity.”Anthony Nyberg, director of the Center for Executive Succession at the University of South Carolina’s Darla Moore School of Business
Role redundancy also helps in retaining key capabilities, even during sudden transitions.
“Encouraging team members to understand multiple roles within the security function ensures operational continuity,” says Anthony Nyberg, director of the Center for Executive Succession at the Darla Moore School of Business at the University of South Carolina.
3. Establish clear communication channels
Transparent communication builds trust and facilitates smoother transitions, Nyberg adds.
“If there is a continuous assessment and adaptation of security plans, that is understood by multiple roles both at the C-suite level and within the CISO’s function, then the organization overall can be better prepared for evolving threats and personnel shifts.”
Just as CISOs need to clearly communicate their needs to CEOs and the board, they also must convey to their staff why they are being asked to do something and the hoped-for outcomes. Staffers need to feel like they’re doing something meaningful to help bolster security at their organizations, and that they are part of a team. Staffers who are covering for each other are ultimately learning new skill sets that can benefit them in terms of linear and nonlinear advancement.
Communication also means listening. CISOs need to check in with staffers to get feedback on how workflow is going and how procedures can be improved.
4. Implement strong offboarding protocols
Organizations need to establish comprehensive offboarding checklists that include recovering corporate information and procedures, revoking access credentials, auditing privileged accounts, and reviewing access logs, Riboldi says. “This is crucial to prevent data leakage or unauthorized access after a departure.”
Security staff often have elevated access, Marquette says. “Offboarding must include revoking credentials across all systems.”
5. Leverage outside partnerships
Companies can consider outsourcing to supplement their higher-skilled functions while shifting commodity work to an organization that excels at that type of work, says Doug Saylors, cybersecurity practice lead at global technology research and advisory firm ISG.
“Service providers are good at rotating talent and provide… a large pool of resources—and ideas—when needed.”Doug Saylors, cybersecurity practice lead, ISG
“Service providers are good at rotating talent and provide [a] contractual mechanism for service quality,” Saylors says. “This allows your internal team to focus on the higher-valued work and get access to a large pool of resources—and ideas—when needed.
[Read also: Hiring remote IT workers? Beware the deepfake frauds]
6. Assess C-suite access to sensitive data
What if the CEO leaves, or the CFO, CIO, CMO, CHRO, or some other C-suite member? These are the people who oftentimes have elevated access to the most sensitive data in the company, including cybersecurity data.
CISOs need to make sure none of that data is walking out the door with these executives when they leave the company. This is a key part of identity access management (IAM), and making sure CISOs know which executives have what levels of access and what projects they were working on. Acquiring that knowledge while the exec is employed means security leaders are not playing catch-up later when that person leaves.
This puts an additional burden squarely on a CISO’s shoulders: They must communicate to the CEO or the board the need for security chiefs to be informed of impending executive changes, so they can be better prepared when the exit happens and take proper measures such as robust offboarding protocols.
