A CISO fighting a live incident cannot also be the person running an eighteen-month scenario plan for how a new AI regulation will reshape the vendor contract portfolio. Those are not the same job wearing two hats. They are two different time horizons competing for the same calendar, and in almost every company, the fire wins.
This article is grounded in current advisory work, not retrospective analysis. Mark Lynd is a 5x CEO/CIO/CISO with Thinkers360 Top 10 global rankings across Cybersecurity and Artificial Intelligence and was ranked #1 globally in Cybersecurity in 2023. He is currently Head of Executive Advisory and Strategy at Netsync, advising enterprise C-Suites and boards on the AI and cybersecurity questions moving fastest in 2026. The frameworks and patterns referenced here are from active engagements this quarter.
What the CISO Is Actually Paid to Do
The CISO job, as most companies have built it, is an operational role wearing a strategic title. Research from Deloitte's Cyber Risk Services CISO Transition Lab, one of the more thorough studies of how CISOs actually spend their time, found CISOs reported spending 77 percent of their time on technical and tactical duties, while they said they would prefer to spend only 35 percent there. Cynet's 2023 CISO Stress Survey found much the same thing from a different angle. Ninety-three percent of the CISOs surveyed believed they spend too much time on tactical work instead of strategic work, and more than a quarter said their entire workday is consumed by tactical and operational tasks almost exclusively.
This is not a complaint about workload for its own sake. It is a structural mismatch. Boards hire a CISO expecting a strategic partner who can speak to enterprise risk, AI governance, and long-range investment decisions. What they actually get, most of the time, is the person who has to be reachable at 2am when a ransomware alert fires, who owns the vendor risk questionnaire backlog, and who is accountable for the next audit finding. Both jobs are real and both matter. They just do not fit inside one person's week, and the data on CISO turnover shows what happens when companies pretend otherwise. Cybersecurity Ventures has reported that estimates of average CISO tenure in a single role range from roughly 18 to 26 months across multiple industry sources, a churn rate that outpaces most other C-suite functions and is consistent with a role that burns people out faster than it develops them into long-horizon strategic thinkers.
There is a countervailing data point worth naming honestly. IANS Research and Artico Search's 2026 State of the CISO report found CISOs report an average of nine years total experience in the CISO title, though most have held that title at more than one company. Read alongside the shorter single-company tenure figures, the picture is a workforce of experienced operators who move employers frequently rather than staying anywhere long enough to build the kind of institutional, multi-year strategic view a company needs for AI governance planning. Experience is accumulating across the industry. It is not accumulating inside any one company long enough to compound into strategy.
None of this means the CISO role is poorly designed by accident. It grew this way because the threats it was built to answer, network intrusions, ransomware, phishing, kept escalating in frequency and severity, and every escalation pulled more of the CISO's calendar into response mode. Adding AI governance, model risk, and third-party AI vendor oversight on top of an already saturated operational role does not create room for strategic thinking. It just adds another category of urgent work competing with the others for the same finite hours, which is exactly why so many companies report AI governance as a stated priority and an unstaffed one at the same time.
Picture a mid-size insurer preparing for a new state AI liability disclosure requirement that takes effect in fourteen months. The CISO understands the requirement in outline, but between an active phishing campaign targeting the claims team, a pending SOC 2 renewal, and a backlog of vendor security reviews from the company's AI vendor sprawl, nobody has blocked out the two weeks of focused work needed to map every AI system against the new disclosure standard, price the compliance gap, and bring the board a real recommendation instead of a status update. The requirement does not go away because the CISO is busy. It just gets addressed six weeks before the deadline instead of six months before it, at a much higher cost and with far less negotiating room on vendor contracts that should have been renegotiated earlier.
The Case Against a Second Executive
The strongest objection to adding a cybersecurity strategist role is cost and turf. Most companies, especially outside the largest enterprises, cannot easily justify two senior security executives, and a second title invites exactly the kind of authority confusion this piece warns about elsewhere in the AI governance conversation. Who does the board actually listen to when the CISO and the strategist disagree. Who signs off on the budget. A cleaner, cheaper fix, the argument goes, is to hire a strong deputy CISO or security operations lead who absorbs the tactical load, freeing the existing CISO to do the strategic work they were always supposed to do. No new C-suite seat, no new political fight, and the person doing the strategic thinking already has the institutional credibility and the security depth to be taken seriously.
That argument is right about the risk and wrong about the fix. A deputy who absorbs tactical work is still, by definition, operating inside the operational tempo of the security function, managing tickets, coverage, and incident response even if one layer removed from the CISO's direct queue. The skill that makes someone excellent at running a security operations center under pressure is not the same skill that makes someone good at long-horizon scenario planning, regulatory forecasting, or advising the board on where AI investment should or should not go over the next three years. Those are different cognitive modes, developed through different career paths, and a deputy promoted from operations usually inherits the operational instincts along with the operational relief. The strategist role does not have to be a full-time C-suite hire to solve this. It can be a fractional advisory function, reporting alongside the CISO rather than above them, with an explicit charter that keeps it out of incident response and vendor questionnaires entirely. The point is not adding a rival executive. It is protecting one function's time horizon from being eaten by the other's urgency, in whatever staffing shape a given company can afford.
The turf concern is real but manageable with a clear charter. The strategist should never be the person a business unit calls when they want to route around a CISO's operational decision, and the CISO should never be asked to defend a strategic recommendation they had no time to develop. Draw that line in the charter document on day one, in writing, and most of the authority confusion the critics worry about never materializes, because everyone in the room knows which questions go to which person before a disagreement ever gets a chance to happen.
What Leadership and the Board Should Ask This Week
Leadership and the board should start by asking the CISO directly what percentage of last month's calendar went to incident response, audit support, and vendor reviews versus scenario planning, board briefings, and long-range roadmap work. Most CISOs can answer this quickly because they feel the imbalance daily. They should ask who in the organization is currently responsible for tracking upcoming AI regulation that will affect the security program, and whether that person has had protected time to work on it in the last thirty days. They should ask whether the company has ever brought in outside strategic advisory capacity specifically to give the CISO breathing room on a major initiative, rather than adding to their existing load. And they should ask, plainly, whether the CISO would describe their own role as mostly strategic or mostly operational, because the honest answer usually settles the question of whether a second, protected strategic function is overdue.
The CISO title was built for a threat model that mostly stayed still long enough for one person to manage both the fire and the forecast. That is no longer true, and companies that keep asking one person to do both jobs will keep losing that person to burnout, and losing the strategic work to whatever crisis happened to be loudest that quarter.