CISO Tribune

Analysis

Named successor or empty chair: what 2026's CISO exits show

Nine of the fifteen CISO departures on the Wire this year came with a successor already named. The six that did not left seats open for weeks to months.

By CISO Tribune Editorial · Published September 25, 2026 · 3 min read

Most CISO exits in 2026 were not exits at all in the operational sense: the successor was named in the same announcement. Of the 15 departures recorded on the Wire this year, nine arrived with a named replacement the same day or week. The other six opened seats that stayed without a permanent holder for weeks, months, or, in two cases, still.

That split is the most useful thing the departure record says about how organizations manage the top security seat. A handover announced as one event is a plan. A departure announced alone is usually a vacancy.

Which exits came with a successor already named?

Nine of the fifteen:

Three of the nine are Indian listed financial firms, where exchange disclosure rules put senior-management changes on the record to the day, and board approval of the successor usually lands in the same filing. Several others were internal promotions. In both cases the successor was lined up before the outgoing CISO's name reached the public.

How long did the other seats stay open?

The six departures announced without a successor:

OrganizationDeparture on recordPermanent successor on recordGap
MetaJune 2Assaf Keren, July 2250 days
ANZApril 23Sandro Bucchianeri, August 26125 days
State of CaliforniaJuly 28Mike Marshall, week of August 24about four weeks
Commonwealth of Pennsylvaniaweek of February 2Andy Ritter, Marchroughly a month
Department of the Air Forceweek of March 9none; an acting CISO was namedopen
National Australia BankAugust 26none yetopen

ANZ's gap was filled by hiring NAB's security chief, which opened NAB's seat in turn. One unplanned vacancy became two.

Outside the departure list, the record holds one more example worth setting beside these. Nevada's new CISO, Bertrum Carroll, replaces a predecessor who retired in May 2025. That is about ten months between permanent holders, and a ransomware attack on state systems landed inside that window.

What should a board take from this?

Two things, both modest.

First, a named successor at the moment of announcement is the norm, not the exception. When a CISO departure is announced alone, that is a signal worth asking about: either the exit was not planned, or the organization had no bench.

Second, when there is no successor, the gap is measured in months, not weeks. Fifty days at Meta, a company with every recruiting advantage, is the short end of what this record shows. An acting CISO keeps the lights on, but the decisions a permanent holder would make wait.

What the record cannot tell us

The Wire records departures when they are publicly reported, and quiet exits often are not. A company that loses its CISO and says nothing does not appear in this count. The true share of unplanned vacancies is therefore likely higher than six in fifteen. And several dates above carry week or month precision, as the individual records note, so the gaps are approximate at the edges.

CISO Tribune Editorial

Editorial Desk

The CISO Tribune editorial desk reports on security leadership: who holds the role, who is leaving it, and what the moves mean. Every Wire entry is verified against its cited source before publication.

The Briefing

Every verified CISO move of the week, in your inbox Friday.

Every verified CISO move and one piece of analysis, weekly.

Unsubscribe any time. See the privacy policy.