
Follow the White Rabbit - IT Security Podcast - English Edition
#11: 63% of CISOs Have Experienced Burnout. Boards Still Call It a People Problem.
The average CISO tenure has dropped from 26 months to six to nine months. Not because the role attracts the wrong people, but because it is structurally designed to fail. In this episode of Follow the White Rabbit, Link11 ISO Kofi Osae-Attah talks to Jeroen Schipper, Chief Security Advisor at DEFION Security about the crisis hiding in plain sight inside security leadership. Jeroen was CISO of The Hague for seven years, a city that hosts the International Criminal Court, NATO, Europol, and the Dutch royal family. He could predict cyberattacks within 48 hours of any politically sensitive event at the ICC. He knows what sustained pressure feels like from the inside and the cost when organisations refuse to treat it as a structural problem. The conversation looks at a dynamic that most boards still misread. A CISO identifies the risk, writes the analysis, hands over the signed risk acceptance letter – and still takes the blame when something goes wrong. The question that follows an incident is never "why didn't the board act?" It's always "what did the CISO miss?" That gap between responsibility and authority isn't just unfair. It's a security vulnerability. A burned-out CISO experiences what research calls risk blindness – a desensitisation caused by chronic overload that affects exactly the kind of judgment the organisation is depending on. And unlike an ER doctor, there's rarely anyone who can step in and cover. The good people leave. The revolving door keeps spinning. And every few months, one of the most critical roles in the entire risk structure starts over from scratch. He organised "Hack The Hague", which involved inviting 120 ethical hackers to attack the city's live infrastructure in the middle of City Hall. This event helped to establish long-lasting board-level commitment to security. His advice for boards is simple: talk to your CISO. Ask what they need. Ask how you can help. If that conversation happened in every boardroom, it could create the shift the profession has been waiting for. Takeaways CISO burnout is a governance issue, not a personnel issue. 63% of CISOs worldwide have experienced burnout. The role is set up to fail structurally: you are responsible for outcomes you don't control, you report to boards that see security as a cost centre and you are blamed when the risks you have flagged are not addressed. The risk acceptance letter is not a shield. When a CISO documents a risk, escalates it and gets it signed off, only to take the blame when something goes wrong, accountability without authority becomes a trap. Too many CISOs fall into this trap unwittingly. Protect the CISO to protect the organisation. A burned-out CISO develops risk blindness. When someone in your most critical security role leaves after six months, all their knowledge of your environment leaves with them. The revolving door itself is a vulnerability. Hack The Hague worked because commitment came from the top. Inviting 120 hackers to attack live city infrastructure in the middle of City Hall sounds radical. It worked because the council approved it. Start smaller – with a bug bounty programme or a responsible disclosure policy, for example – but get the buy-in first. One conversation can shift the dynamic. Boards don't need a new framework. They need to ask their CISO what they need and how they can help. Making the board the entity that owns the risk, rather than just the CISO, changes everything downstream. Subscribe to Follow the Rabbit If this episode has made you think about the weight that is being carried by one person in your organisation that was never designed to be carried by one person, share it. Subscribe on your preferred platform, leave a review and share it with every board member, CEO and security leader who still believes that CISO burnout is an HR issue. Links Jeroen Schipper – Chief Security Advisor, DEFION Security | Former CISO of The Hague | First-ever CISO of the Year, Netherlands | Linkedin Hack The Hague – Bug Bounty & Ethical Hacking Programme ENISA: NIS2 Directive – Board Accountability for Cybersecurity DORA – Digital Operational Resilience Act ISC²: CISO Burnout & Workforce Research






