A "golden parachute" clause allows outgoing executives to land softly. WeWork's former CEO Adam Neumann used one to walk away with $1.7 billion in stock, cash, and credit. But that was Neumann's choice; security executives may not be so lucky.

Golden parachutes provide financial protection when executives leave. Facing the ongoing threat of data breaches, CISOs can secure financial protection after an incident through a "golden bullet" clause, Stuart Mitchell, head of information and cyber security recruitment at Stott and May, told CIO Dive.

A golden bullet doesn't fully shield executives from public scrutiny, but it can ease the burden of being blamed. If termination due to a breach becomes a reality, the golden bullet clause pays out as a bonus to the departing CISO.

"Every time there's a high-profile breach, companies need a scapegoat," Mitchell said. If it's a well-known company, "you're publicly fired and dragged through the mud."

A golden bullet can cushion that drag. Mitchell noted that Neumann's reputation may have suffered, but the golden parachute gave him a financial "soft landing," a luxury CISOs don't always have.

According to a Nominet survey of over 400 CISOs, nearly a third believe they would lose their job or receive a "formal warning" due to a data breach.

Samantha Schwartz/CIO Dive, data from Nominet, 2019

If CISOs had ample budgets and fully staffed security teams, they would have all the resources needed for reliable protection. In that case, blaming the CISO would be reasonable. However, these conditions are almost never a reality.

According to Nominet data, only 60% of CISOs believe their CEO or president agrees that a breach is inevitable. Non-IT leadership may fall into defensive blame rather than pursuing security best practices or investments, putting more pressure on CISOs to deliver results with minimal resources.

Paying the price

After a breach, it's easy for companies to make the CISO the scapegoat. These executives are responsible for maintaining cybersecurity, but everyone in security knows that cyber incidents are a matter of "when," not "if."

In the third quarter of 2019 alone, over 5,100 breaches were reported, exposing 7.9 billion records, according to research by Risk Based Security. In comparison, just over 1,300 breaches were reported for all of 2011, affecting a total of about 420 million records.

Capital One's breach was reported in July, making it one of six breaches involving over 100 million records between July 1 and September 30.

Even though breaches are inevitable, professionals still enter this "thankless job," Mitchell said. Unlike other C-suite members, such as a CTO who becomes a "hero" when launching a new product line, a CISO "is never really the hero, but people know when you mess up."

"You can definitely be the villain," Mitchell said.

According to Risk Based Security, top leadership worries most about the impact of a breach on the company's reputation.

Mitchell said that during and after a breach, the PR playbook is to single out a scapegoat—usually the CISO—even though that may not reflect reality. There are aspects of the security program that the CISO cannot directly oversee, yet they still bear the blame.

"That's why if you can't stand the heat, get out of the kitchen," Andy Kim, CISO of Allstate's e-commerce division, told CIO Dive.

Even with a tough exterior, there's a significant mental health component to the CISO role, Mitchell said.

According to Nominet, 91% of CISOs say they experience moderate or high stress. About 17% of CISOs rely on medication or alcohol to relieve stress.

Samantha Schwartz/CIO Dive, data from Nominet, 2019

"I know a lot of people who like being the number two, like deputy CISO or VP, because sometimes it's more fun to be the prince than the king," Mitchell said. "You can turn off your phone."

Anatomy of a golden bullet

A golden bullet clause allows CISOs to consider their own future and what is in the best interest of the company.

Golden parachutes are often used to attract executives, although critics warn they provide moral incentives executives shouldn't need; organizations should act in the company's best interest without additional compensation.

The clause also helps protect the CISO's career.

"Ultimately you have to suck it up and keep your head down," Mitchell said. "You always carry that skeleton in the closet; you can't hide that information," especially in front of Fortune 500 companies.

If a CISO leaves, they may have to reinvent themselves, hiring a personal brand manager to help. They could choose to leave with a substantial payout to support themselves while being "dragged through the mud" until the next public breach occurs and people forget, Mitchell said.

Companies also benefit from the contractual clause. If a CISO's contract includes a golden bullet clause, it more or less guarantees the CISO focuses on post-breach recovery rather than job hunting, Mitchell said. "It also gives the company an agreement that allows them to make the CISO the scapegoat."

This add-on helps mitigate criticism and concerns from investors and customers.

Today, golden bullet-style clauses typically "appear in nominal CISO appointments," Kim said. Some boards don't know what qualities make an effective CISO and appoint someone familiar to them rather than a security veteran.

"Many uninformed board members don't know how to choose an effective CISO," Kim said. Fortune 100 companies often have boards that hire "their friends or politically connected appointees."

But "a lot of responsibility lies in hiring and firing, and whether you trust the right or wrong people," Mitchell said. Trust either exists between executive leadership and their CISO, or between the CISO and the rest of their security team.

The cybersecurity industry relies on a workforce with diverse and non-traditional backgrounds. According to (ISC)² research, about 70% of qualified applicants hold titles not necessarily related to security.

"A CISO who knows what they're doing yearns for the moment when a breach happens," Kim said. "A marginal CISO will just resign."

Falling on their sword

Success in cybersecurity can only be measured by silence—no breaches, no cyberattacks, no headlines.

A CISO's performance should not be quantified by a single event, Greg van der Gaast, head of information security at the University of Salford, said in a LinkedIn post.

"I think CISOs should be measured on the improvements they bring, not a point in time. Even if you're moving in the right direction, bad things can happen," van der Gaast said.

Retaining a publicly tainted executive is a potential PR risk. Firing the CISO is, to some extent, PR damage control, regardless of the executive's tenure or experience.

Although a fired CISO needs to lick their wounds, career recovery is possible. Former Uber CISO Joe Sullivan—blamed for paying hackers a ransom in the 2016 data breach—is now the CISO at Cloudflare.

If a CISO does their best to fulfill their duties without major missteps, yet a breach still occurs, the company must ask two questions, Mitchell said:

  • Would the business be in a better position if it paid the CISO to clean up the mess?
  • Or, should the company interview new CISOs, thereby diverting attention from recovery?

Several companies with public breaches, including Home Depot, retained their CISO or equivalent.

Home Depot adopted the CISO title when it hired Jamil Farschi, who was later hired by Equifax. But Daniel Grider, the IT VP responsible for security, remained in his role.

Other companies were less fortunate. Yahoo had three high-profile breaches between 2013 and 2016, later disclosing that the breaches affected 3 billion Yahoo accounts. During that period, especially in 2015, CISO turnover was frequent, although they left voluntarily.

Within six months in 2015, Yahoo saw three CISOs: Alex Stamos, Rames Martinez, and Bob Lord. Lord later left in 2018, and now Chris Nims, CISO of parent company Verizon Media, bears responsibility for Yahoo's troubled past.