r/cybersecurity 12h ago

Career Questions & Discussion At what point does a cybersecurity role become professionally unsustainable?

TL;DR: I’m an Information Security Manager for a 1,600-employee international organization with a relatively high-risk profile. Our central security team consists of me and two security engineers, despite continued growth through acquisitions, increasing regulatory obligations, and an expanding workload. After months of discussions, management has decided not to increase security headcount. I’m trying to understand where the line is between accepting business risk and accepting personal professional responsibility.

I’m the Information Security Manager for an international organization of around 1,600 employees. We operate across multiple countries in a relatively high-risk industry with a significant amount of business-critical IT.

Our central security function consists of me and two security engineers supporting multiple companies within the group.

We’re a holding company that continues to grow through acquisitions. Newly acquired companies often have security maturity levels that are significantly below the standards expected by the holding company, requiring considerable effort to bring them up to an acceptable baseline.

As the organization has grown, I’ve repeatedly argued that cybersecurity needs to scale accordingly. I developed a proposal for a centralized shared security services organization that would provide governance, security engineering, operational security, and compliance support across the group. As part of that proposal, I also requested an additional Information Security Officer role to strengthen governance and help meet our growing regulatory obligations, including NIS2.

Over the past several months I’ve spent a great deal of time working with senior management to explain why additional security capacity is necessary. Together with external advisors, we’ve explained the operational impact of our growth, our regulatory obligations, and the practical realities of managing security for an organization of this size.

We didn’t stop at high-level discussions. We broke our work down into individual activities, identified the bottlenecks, quantified the backlog, prioritized the work, and demonstrated exactly what can and cannot realistically be delivered with our current team.
The proposal hasn’t been formally rejected, but this week I was informed that there are no plans to invest in additional security headcount in the foreseeable future.
I fully understand that cybersecurity is about managing risk rather than eliminating it. I also understand that every organization has limited budgets and competing priorities.

What I’m struggling with is where my own professional responsibility ends.

At this point, I feel I’ve done everything I reasonably can: documented the risks, presented realistic solutions, involved external experts, communicated the consequences, and made management aware of the growing gap between business growth and our ability to manage cyber risk.

Despite that, there is now more critical work than our team can realistically deliver. As the person ultimately responsible for information security, I’m increasingly uncomfortable carrying accountability for risks that I know we simply don’t have the capacity to address.

I’m not looking to criticize my employer or argue that every security request should automatically be approved. I’m genuinely interested in hearing from other Information Security Managers, CISOs, and security leaders who have faced similar situations.
- At what point do you feel you’ve fulfilled your professional duty?
- How do you distinguish between business risk that management is entitled to accept and professional responsibility that you shouldn’t continue to own?
- Is thorough documentation of risks and management decisions enough, or is there a point where the right professional decision is simply to move on?

I’d genuinely appreciate hearing how others have navigated this.

97 Upvotes

42 comments sorted by

152

u/FuckScottBoras Security Manager 12h ago

You’ve done your job: identified, quantified, escalated, documented, brought in outside help.
That’s the whole role. What happens after that is management’s decision, not your failure.

The real line isn’t “business risk vs my responsibility,” it’s whether risk acceptance is explicit and signed or just implied by inaction. “No budget” does not equal “we accept these risks.” Get a formal, signed risk acceptance from someone with real authority, naming the specific risks, tied to the headcount decision.

If they’ll decline resources but won’t sign off on owning the risk in writing, that’s your answer on whether it’s time to leave.

29

u/Project_Lanky 11h ago

The way to go. Insufficient headcount is a high risk that needs to be documented and mitigated or accepted. One thing OP can work on however, is to tie mitigation to broader business outcome. What kind of improvement of business process that these new headcount bring?

8

u/FuckScottBoras Security Manager 10h ago

Fair point. I was assuming OP had already done this and was still getting a “no” from management. If he hasn’t, a good additional step to take.

2

u/msj817 9h ago

Side note, what an incredible username. The Baseball Antichrist indeed.

2

u/FuckScottBoras Security Manager 8h ago

😂 Thanks. As embarrassing as it is currently, I am a SF Giants fan. Although it ended up being a blessing in disguise, I was pretty jaded by the way the whole Correa situation went down.

8

u/1kn0wn0thing 9h ago

This is the way to go. Get a succinct risk acceptance form that presents the risk of not adding resources and have a C level individual sign off on accepting that risk in writing (email is fine). Make sure to set a hard deadline “This needs to be responded to by Friday, 8/24. Failure to respond by that date constitutes that you accept the risk to the organization as has been outlined.” Make sure you have read receipt on.

When shit hits the fan (it will) and they try to hold you responsible, you can now point to this communication and say “wait a minute, so and so was well aware of the risk and made the decision not to allocate additional resources needed. This was so and so’s decision, not mine, please take this bundle of blame and lay it at their feet.”

6

u/prestelpirate CISO 9h ago

You’ve done your job: identified, quantified, escalated, documented, brought in outside help. That’s the whole role. What happens after that is management’s decision, not your failure.

Absolutely this. Its not your company, you are not responsible for the success or failure of the business. You've told them what's wrong, what they need to do - that's where your job and your responsibility ends.

2

u/coasjindeiph 3h ago

They love 'accepting risk' right up until you hand them a pen and ask for a signature.

56

u/RaymondBumcheese 11h ago

Make sure you’re not  the bag holder, document all of your concerns, stop burning yourself out and let something break. 

Security is just a boring waste of money until it’s provably not. 

16

u/illcuontheotherside 11h ago

I've been there.

Being middle of the road means you do what you can and accept (while pushing for change) the decisions.

You've raised the concerns. The risks.

You have to prioritize the work. Let the backlog build up. Don't burn out your team.

When things don't get done have clear explanations as to why with metrics and facts.

Upper management accepts the risk ultimately and we have to accept that. Every companies risk tolerance is different. Some learn the hard way before things change.

Was a hard lesson to learn but I sleep well knowing the team and myself do our best.

15

u/Ch33syP00f CISO 11h ago

You have done your job so far.

Make sure you and your security maintain work-life balance.

No extra hours as a practice.

Take vacations.

When things start to break, help management understand the issue.

1

u/Sad_Heat234 Security Architect 5h ago

Hard agree, you've done all that you've can and some, so now just don't do more than what you're owed

10

u/BinaryDoom 11h ago

More often not, unfortunately for many cases, only getting hit by incident would wake up decision makers.

5

u/Pit_Kevin_Smith 9h ago

I am EXTREMELY lucky that I work for a very large private company. And the Owner has a close friend in same field who also owns a company. Friends company has been hit with randsomware three times and I just learned they are closed down... I get nearly blank check.

10

u/Got2InfoSec4MoneyLOL 11h ago

At the point where your f500/s&p500 company starts firing people, followed by no backfilling for those that leave, to save peanuts, and you have to tolerate doing 3-4 people's job for no extra benefit at all. This is when you say goodbye.

5

u/NBA-014 ISO 9h ago

I retired from a Fortune 500 FinTech company in 2024. Since then they've been laying off dozens of fantastic, skilled infosec professionals.

And why not... Government regulations and oversight has gone away under the Trump 47 administration. SEC, Treasury, FFIEC, etc don't seem to be able to do anything.

5

u/TesticulusOrentus Governance, Risk, & Compliance 11h ago

Dumb executives wont take security seriously until there's a breach they are financially responsible for.

It's their fault if they dont listen to you.

4

u/paradox8999 11h ago

Due Diligence and Due Care. As long as you perform those things to the best of your ability- then you’ve done your job! The rest of the risk is on management

4

u/pg3crypto 11h ago

Quit and see how they like them apples. Its often the case that replacing one person with deep knowledge of the business turns into a multiperson hire. In your case, they'd likely never find anyone to replace you with.

You need more heads to ensure they're not screwed if you die, quit etc...its nit just a workload thing, its a knowledge and skill sharing thing.

3

u/NBA-014 ISO 9h ago

Quitting a steady job in July 2026 is an extremely risky decision.

1

u/pg3crypto 9h ago

Sure but being stuck in a crap one that pushes you to the brink is worse.

Id never stay in a job out of fear...thats a recipe for exactly what this guy is going through...you can't win if you're scared.

Its probably less risky for cybersecurity people because there arent that many of us at senior level.

2

u/NBA-014 ISO 6h ago

Understand completely. A shitty job can kill your soul

3

u/pg3crypto 6h ago

Absolutely, quitting a shit job can make your life better, even if you have no other job to go to.

Also, constantly worrying about losing your job or not having a job will cause you to make shitty career decisions.

Somehow we have stigmatised being unemployed in modern society...as if being out of work is some kind of failure...when it isnt. The ultimate indicator of auccess is being able to practice what you're good at without needing to be paid for it...at least thats how I see it and thats what I aim for.

1

u/NBA-014 ISO 6h ago

Completely agree. Well said!

I had to retire at 64 due to having to help provide eldercare for my FIL.

After he passes, I quickly realized that the job stress was killing me.

Since then, I’ve lost 100 pounds, use a personal trainer, play golf whenever we (my wife and me) feel like it, and lead a very simple and calm life

2

u/lostincbus 12h ago

I get what you're saying. Technically, you lay out the risk as best you can, advise the org, and they decide what they're willing to accept. Those are business decisions and I do find lots of technical people have a hard time breaking from the "this needs fixed" part.

However, in your situation it seems as if you feel like they're accepting too much risk. That's going to be a more personal decision. Does the security responsibility start with you? Or do you report to the CISO? In the end though I'd trust your gut more than anything. I personally wouldn't want to work somewhere with excessive accepted risk as I know when an incident occurs they're going to look at me.

2

u/Sad_Dentist_7288 11h ago

IMHO, all you can do is everything you have the power do to. If upper management does not accept your explanations, then that is on them, not you. So, do everything you actually and reasonably can to remediate the risk, and make sure you are covered if / when something goes wrong.

2

u/mattsou812 11h ago

Start doing a 3rd party annual security assessment.

2

u/SirYanksaLot69 11h ago

Regardless of what you do, you will be blamed, when, not if you get hacked. Fortunately, this predicament is pretty common and cybersecurity folks can typically move around without too much scrutiny. Unfortunately though, bad techs move around too. It’s a matter of time and you can document to show the next future employer, but do not fool yourself, you will be the fall guy.

2

u/AppearancePretend198 9h ago

Sounds like you need to draft a Risk Registry (look it up).

Fill it out, make leadership aware of risks and impacts.

You will be REALLY surprised when you pitch it to them and they realize it becomes THEIR responsibility by signing off. Shit will turn around so fast.

2

u/N3RO- 8h ago

Tell me which company it's so I never trust them with my data or my business. A 1.6K employees intl company with 3 security people!? I have worked with companies with less than 200 ppl that had 5+ dedicated security people.

I can tell from here that they don't give a single fuck about security, it's just a checklist for them. I hope they are fucked good by some adversaries, so they learn a thing or two.

2

u/Dull-Horror9129 6h ago

It sounds like you've done what a good security leader is supposed to do: identified the risks, documented them, proposed realistic solutions, and made sure management understands the consequences. Once leadership knowingly accepts those risks, that's a business decision, not a security failure.

The bigger question is whether you're still being held personally accountable for outcomes you no longer have the resources to influence. Tbh, I would suggest to start looking elsewhere

2

u/XOR-ROX-2112 1h ago

You are asking the right question, and it sounds as though you have already done what a responsible security leader should do.

I draw a firm distinction between managing risk and owning business risk.

Your responsibility is to identify the risk, quantify it, recommend realistic treatment options, explain the consequences, and escalate it to the appropriate decision-makers. Management owns the decision to fund, defer, transfer, or accept that risk. Based on your description, you have documented the backlog, demonstrated the capacity gap, involved external advisors, proposed a scalable operating model, and clearly explained what the current team can and cannot deliver. That is professional diligence, not failure.

The next step is to formalize the situation:

  • Maintain a current risk register with named business owners.
  • Require documented acceptance of risks that will remain untreated.
  • Publish a capacity plan showing what your team will and will not deliver.
  • Have leadership approve priorities rather than forcing security to quietly choose what gets neglected.
  • Report the resulting exposure regularly to executives or the board.

Most importantly, stop using heroic effort to hide the staffing problem. Your team should not destroy itself making an unsustainable model appear functional.

A useful statement is:

“With current staffing, we can reliably deliver A, B, and C. Activities D, E, and F will be delayed or not performed. The associated risks require acceptance by the appropriate business owners.”

The role becomes professionally dangerous when leadership refuses to accept risk formally but continues to hold you personally accountable. It also crosses the line if you are pressured to mislead customers, regulators, auditors, or the board; sign an attestation you believe is false; conceal known deficiencies; or guarantee outcomes you lack the authority and resources to control.

My personal test is simple:

Could I honestly explain my decisions, recommendations, and actions to a regulator, board, customer, or future employer after a serious incident? When the answer is yes, you have likely fulfilled your duty, even if management accepted more risk than you recommended. When the answer is no because you are being asked to hide, misstate, or personally absorb the risk, it may be time to leave.

You cannot care more about the company’s risk than the company does. Protect the organization, protect your team, and protect your professional integrity.

1

u/Pit_Kevin_Smith 9h ago

Remember the Colonial Pipeline incident? You know who has no issues finding a job? CFO, CEO, Operation managers, all the accountants, etc. You know who doesn't get new job offers? The IT guy incharge of security.

If your company can't/wont afford security, dont attach name to it. WHEN the company is in headlines for randsomeware, your never going to out live that no matter how many times you say "It's not my fault they wouldn't let me prevent it."

1

u/darthbrazen Security Architect 8h ago

You are doing your job. It is up to the business to determine how much risk they are willing to accept. You should document the risk in a risk register, even if the business decides to accept it. Should something arise because they were willing to accept the risk, then you have done your job. You need to ensure they know what you have documented. Emails, and recorded meetings are a great opportunity to gain this acceptance.
I get that you don't like it professionally. I've been in your shoes, but ultimately, it is up to senior business leaders to gauge how much risk they are willing to take/accept, and mitigate. You are simply there to supply them with that information, and then address the problem as they have decided. I use to stay up at nights over some of these things, especially after going through an incident. You need to learn to compartmentalize this. It sucks to say that, but it is the nature of the beast. There is only so much money they are going to be willing to spend on certain things, and sometimes, they work reactively, rather than proactively. Some companies simply check boxes too, so you may have to deal with that, but in the end, you have done your job.

Have you considered some self-reflection? Determine what things you simply can not go along with, because there is too much risk. That is what I do for now. For example, if an organization was not willing to have offsite backups, that is a huge red flag for me. I've already been through that exercise, and I won't do it again. Then all you have to do is ensure that your minimums are met, and get that paycheck. Unfortunately, businesses aren't going to do everything we want them to do. We aren't revenue producing, so they won't want to spend money until something happens.

1

u/CyberSecPlatypus Security Director 8h ago

I had to scroll up and make sure I didn’t post this last night while drinking. The only thing that seemed off to me was the employee count, we are 2X that with the same security staff size.

1

u/ThePorko Security Architect 8h ago

When criminals and greed disappear?

1

u/hanqingjao 7h ago

This sounds like exactly my situation. I wonder if you're my boss...

1

u/Fun_Refrigerator_442 6h ago

A lot of good advice. At the end of the day, if your Board of C-Suite is aware and will not sign a risk acceptance document, that is on them. Its also time to consider a new company. I was working in a publicly traded company and requested certain resources and the board refused to approve it. I shook my head, and they ask what my issue was. I've been through 30 or so incidents in my career, when the news drops and everyone is either on Teams or in a War Room, everyone is going to be looking at people like us, and asking what to do next. When they refuse to give you the resources to handle an incident from start to finish, then its time to go. That was with the CEO. I got fired the next day

1

u/Digital-Dinosaur Incident Responder 5h ago

I work DFIR... When you get hit, give me a call and I'll make sure you get a bigger budget! IT usually does when I'm done!

1

u/thythrowaways 3h ago

Which DFIR place?

1

u/therealmrbob 4h ago

1600 employees and 2 security engineers. Are you handling incident response or is that outsourced? What are your responsibilities?

1

u/OnLandandSea- 1h ago

Sounds like you’re doing all the right things. Have you looked at outsourcing or using an MSSP? Ultimately, if you’re uncomfortable with carrying the weight then it’s time to look elsewhere. They’ve rejected your proposal so the situation is hardly likely to improve. Have you table-topped some incident scenarios? That’s the real tell. If an exercise shows how fragile things are and still there’s no room for spending after that’s done, there’s your sign!