By Sean Cleary, Partner and Cybersecurity Practice Lead
3 Takeaways
1. Most CISO mis-hires start with the role design. The problem surfaces around month 18, and it usually traces to decisions the company made before anyone was hired.
2. Five things decide whether the hire holds: the mandate, the reporting line, the bench, the compensation, and personal liability protection. Get them right before you go to market.
3. Liability protection is now a recruiting lever. A majority of security leaders won’t take a role without D&O coverage. Offering it up front widens your candidate pool and signals how seriously you take the seat.
I’ve written before about what a CISO should evaluate before accepting a role. This is the other side of that conversation, written for the CEOs, CHROs, and boards who own the hire. The pattern I see most often is a search that looks successful at the offer stage and unravels around month 18, and the cause is almost always a role that was designed loosely before the first candidate walked in. The good news for the hiring side: every one of these failures is preventable, and the fixes cost far less than a failed search.
Define the Mandate Before You Go to Market
The most important decision in a CISO search happens before it starts. What does this role actually own in its first year, given your stage and your risk? IPO readiness, regulated-market expansion, a product-security build, AI risk, or a governance rebuild after an incident are different mandates that call for different people.
The classic mistake is importing a mandate from a different kind of company. A leader who built security from scratch at a Series C startup is a different hire from one who walks into a PE-backed portfolio company to formalize third-party risk, even when the resumes look alike. Treat them as interchangeable and you get the mis-hire both sides feel by month nine and no one names until month 18. Write the mandate down, in the specific decisions the role will own, and align the CEO, CHRO, and board on it before you approve the search.
Set the Reporting Line for Real Access
Top candidates screen for the reporting line before they engage, and boards that need meaningful oversight require it structurally. A CISO buried several layers under IT inherits accountability without the access to act on it. That structure repels the strongest candidates and weakens the oversight the board is on the hook for.
Give the role a reporting line with genuine proximity to the CEO and regular contact with the board. Monthly time with the executive team and quarterly board engagement is the pattern that works. This is also a recruiting advantage: the scope and access you design into the role is often what wins a candidate who’s choosing among offers.
Fund the Bench, Not Just the Seat
The most common way a well-hired CISO fails is structural. When there’s no qualified leader beneath them to own security engineering or GRC day-to-day, the CISO ends up running incident response by hand and loses the room at the board level. The bench is the rate limiter on the whole function once a company is past Series C.
Budget the VP layer as part of the hire rather than a later phase. The two roles that matter most at growth and scale are the head of security engineering, who provides the technical execution capacity that frees the CISO to operate at the executive level, and the GRC lead, who manages the compliance surface that can otherwise consume the CISO’s calendar entirely. Committing to that layer during the search, with headcount and timing, is often what convinces a strong candidate the role is real.
Benchmark the Compensation to Today’s Market
If your internal reference point for what a CISO costs is more than 18 months old, you’re underpricing the role, and you’ll learn it when a finalist goes quiet between rounds. Demand has run at multi-year highs, several categories of company that delayed the hire are all bidding at once, and compensation has moved with the volume.
Two things to get right. Benchmark against current, company-type-specific data rather than a stale internal figure. And design the equity deliberately, since late-stage private companies now use RSU structures that pay like a public company without the liquidity, and finalists compare your offer against packages you may not know you’re competing with. The structure carries a signal on its own: a thoughtful, well-built offer tells a candidate security is a priority, and a below-market one tells them it’s a cost center regardless of the job description.
Offer Liability Protection Before You’re Asked
Personal liability moved from theoretical to real when the SEC charged the SolarWinds CISO individually in 2023. A court dismissed that case in 2025, and the concern it raised has not gone away. In one industry survey, two-thirds of security chiefs said they would not take a role without directors-and-officers (D&O) protection for the position.
Companies that wait to be asked look reactive. Companies that put it on the table early stand out. Name the CISO on the D&O policy, offer a written indemnification agreement, and settle who signs security disclosures and control attestations before the offer goes out. This is now part of a competitive package, and getting it right widens the pool of leaders who will take your call.
Do You Actually Need a Full-Time CISO Yet?
One more question worth asking honestly before any search: is a full-time CISO the right answer right now? Forcing the hire before the organization can support it is its own failure mode. In the right circumstances, a fractional CISO, a virtual CISO engagement, or a strong VP of Engineering with security ownership can credibly cover the function for another 12 to 18 months. The wrong answer here costs real money; a failed executive search burns close to nine months of mandate drift before anyone calls it.
How to Know the Design Is Working
Track the hire the way you’d track any other executive bet: time-to-fill against plan, offer-accept rate, and retention at the 18-month mark, which is the point where a mis-designed role shows its cracks. Watch for mandate drift, where the role quietly becomes something other than what you hired for, because that’s the early signal that the design and the reality have come apart. Roles that hold at 18 months almost always trace back to a mandate that was clear before the search began.
Frequently Asked Questions
Why do CISO hires fail around the 18-month mark?
The failure usually traces to role design set before the hire. A vague or imported mandate, a reporting line without real access, and no funded bench beneath the CISO all surface at around month 18, when the gap between the role as designed and the role as needed becomes clear. Defining the mandate precisely before going to market is the single highest-leverage fix.
What should a company get right before hiring a CISO?
Five things: a specific year-one mandate matched to the company’s stage and risk, a reporting line with genuine access to the CEO and board, a funded VP-level bench (security engineering and GRC), compensation benchmarked to current market data, and personal liability protection such as D&O coverage and indemnification. Aligning the CEO, CHRO, and board on the mandate before the search is where it starts.
Does offering D&O protection help attract a CISO?
Yes. A majority of security leaders now say they won’t take a role without D&O protection for the position, so offering it early widens your candidate pool and signals that the company takes the role seriously. Name the CISO on the policy, provide written indemnification, and clarify who signs security disclosures before the offer goes out.
Related: How to Hire a CISO in 2026: What’s Changed in the Mandate, the Comp, and the Reporting Line
Related: How to Structure a Security Organization by Stage, Risk Profile, and the Bench Beneath the CISO
Related: Cyber Risk Is Enterprise Risk: What That Means for Board Oversight in 2026
Sean Cleary leads the cybersecurity executive search practice at Riviera Partners. Connect on LinkedIn.
About Riviera Partners
Riviera Partners is a global executive search firm focused exclusively on technical leadership, including product, engineering, IT, AI/ML/Data, and cybersecurity.