Analysis
Named successor or empty chair: what 2026's CISO exits show
Nine of the fifteen CISO departures on the Wire this year came with a successor already named. The six that did not left seats open for weeks to months.
Most CISO exits in 2026 were not exits at all in the operational sense: the successor was named in the same announcement. Of the 15 departures recorded on the Wire this year, nine arrived with a named replacement the same day or week. The other six opened seats that stayed without a permanent holder for weeks, months, or, in two cases, still.
That split is the most useful thing the departure record says about how organizations manage the top security seat. A handover announced as one event is a plan. A departure announced alone is usually a vacancy.
Which exits came with a successor already named?
Nine of the fifteen:
- IIFL Finance: Sameer Gadve stepped down on January 22 and Kailash Gaonkar took the seat the next day.
- American Express: Fred Gibbins handed over to Gleb Reznik, who was already inside the company's technology risk function.
- State of New Hampshire: Ken Weeks to Pamela McLeod.
- Phillips 66: Michael Morgan to his deputy, Connie Devine.
- Trellix: Michael Green to David Soto.
- 360 ONE Asset Management: Somesh Patil to Alankrit Shrivastava.
- WaTech: Ralph Johnson to Gwen Gann.
- Aditya Birla Sun Life AMC: Basil Dange to Rishi Awasthi.
- NESO, Britain's energy system operator: Simon Lambe to Purvi Kay.
Three of the nine are Indian listed financial firms, where exchange disclosure rules put senior-management changes on the record to the day, and board approval of the successor usually lands in the same filing. Several others were internal promotions. In both cases the successor was lined up before the outgoing CISO's name reached the public.
How long did the other seats stay open?
The six departures announced without a successor:
| Organization | Departure on record | Permanent successor on record | Gap |
|---|---|---|---|
| Meta | June 2 | Assaf Keren, July 22 | 50 days |
| ANZ | April 23 | Sandro Bucchianeri, August 26 | 125 days |
| State of California | July 28 | Mike Marshall, week of August 24 | about four weeks |
| Commonwealth of Pennsylvania | week of February 2 | Andy Ritter, March | roughly a month |
| Department of the Air Force | week of March 9 | none; an acting CISO was named | open |
| National Australia Bank | August 26 | none yet | open |
ANZ's gap was filled by hiring NAB's security chief, which opened NAB's seat in turn. One unplanned vacancy became two.
Outside the departure list, the record holds one more example worth setting beside these. Nevada's new CISO, Bertrum Carroll, replaces a predecessor who retired in May 2025. That is about ten months between permanent holders, and a ransomware attack on state systems landed inside that window.
What should a board take from this?
Two things, both modest.
First, a named successor at the moment of announcement is the norm, not the exception. When a CISO departure is announced alone, that is a signal worth asking about: either the exit was not planned, or the organization had no bench.
Second, when there is no successor, the gap is measured in months, not weeks. Fifty days at Meta, a company with every recruiting advantage, is the short end of what this record shows. An acting CISO keeps the lights on, but the decisions a permanent holder would make wait.
What the record cannot tell us
The Wire records departures when they are publicly reported, and quiet exits often are not. A company that loses its CISO and says nothing does not appear in this count. The true share of unplanned vacancies is therefore likely higher than six in fifteen. And several dates above carry week or month precision, as the individual records note, so the gaps are approximate at the edges.
CISO Tribune Editorial
Editorial Desk
The CISO Tribune editorial desk reports on security leadership: who holds the role, who is leaving it, and what the moves mean. Every Wire entry is verified against its cited source before publication.
The Briefing
Every verified CISO move of the week, in your inbox Friday.
Every verified CISO move and one piece of analysis, weekly.
Unsubscribe any time. See the privacy policy.