FinXTech Logo The Intersection of Financial Institutions and Technology Leaders

CISOs Face Increasing Levels of Stress

July 30, 2026

By Greg Neumann

Chief information security officers (CISOs) at banks and credit unions face a much more stressful landscape than ever before. The risk that human error could result in a data breach or ransomware attack remains as present as ever. But now they also face additional challenges posed by greater advances in artificial intelligence (AI) and the daunting possibility that a cyberattack could leave them personally liable. 

Cyber attacks in the United States have exploded in the past decade. The Federal Bureau of Investigation’s (FBI) Internet Crime Report 2025 shows losses reported to the Internet Crime Complaint Center increased from $1 billion in 2015 to nearly $21 billion in 2025. And in 2025 alone, the Cybersecurity and Infrastructure Security Agency (CISA) found the financial services industry trailed only the healthcare industry in the number of data breaches and ransomware attacks against its critical infrastructures.

Chad Knutson, CEO of the bank consulting firm SBS CyberSecurity, says CISOs have to keep up with a head spinning array of potential threats. “You can write ransomware with AI and make it new every time,” he says. “You merge that with the trend in technology adoption  — we adopt things fast now. I mean, bankers used to sit around and think about mobile deposit capture for years before they did something. Now, if you thought about AI for years, you’d be behind the curve. So just the rate of change is hard to keep up with.”

CISOs in all industries are feeling the pressure. An April 2026 survey of global cybersecurity professionals commissioned by the Information Systems Security Association International found that “nearly half of respondents have occasionally (30%) or regularly (17%) thought about leaving their jobs over the last 12-to-18 months, and among those thinking of leaving their jobs, more than half have occasionally (37%) or regularly (20%) considered leaving the cybersecurity profession altogether.” 

Marc Ashworth served as the CISO of $6.7 billion First Bank, based in Creve Coeur, Missouri, from 2017 to 2025. He says the toll of all that stress is very real. “When my position was eliminated back in November, I knew I was getting burned out,” he says. “The big thing is, it just never stops. It’s just constantly coming and you’re constantly worrying.’

A Constant Barrage of Threats
Patelco Credit Union, a $9.6 billion institution based in Dublin, California, suffered a 2024 ransomware attack that shut down its online banking platform for 17 days and allowed hackers to access the personally identifiable information (PII) of many of its roughly 500,000 members, according to California’s Department of Financial Protection and Innovation. Patelco CEO Erin Mendez told the San Francisco Business Times in June 2025 that the attack cost the credit union $85 million. Those losses came in the form of fraud, fines and a class-action legal settlement, but the credit union has since beefed up its defenses and remained financially strong after the attack, the Business Times said.

Ashworth says those are the types of attacks CISOs fear most. “There were many times when I was waking up in the middle of the night,” he says. “I was like, “OK, what about this? How about this? And you don’t sleep well.”

As FinXTech reported in May, rapidly-evolving frontier AI models are adding a new level of stress for CISOs, with new examples of the threats they pose popping up constantly. OpenAI on July 21 reported an “unprecedented cyber incident” in which one of its AI agents escaped a sandbox testing environment, accessed the internet and hacked into another company’s systems. 

But with all of the technology CISOs have to keep up with, human error is still a big reason cyberattacks are successful. TruStage Financial Group, which provides a variety of business solutions to credit unions and banks, reported that an employee likely inadvertently downloaded a malicious file that resulted in a July 11 cyberattack. The incident forced the company to take many of its institutional and individual customer-facing services offline. Trustage’s CEO says it has been working diligently to protect customers.

Ashworth, meanwhile, says he was lucky to never face such an incident, but has talked to many CISOs who have. “It’s an all hands-on [deck], however long it takes to get things going [event],” he says. “The potential for burnout is definitely really high after that.”

CISOs have always been at risk for losing their jobs after such cyberattacks, but now they have the added worry of being held personally liable for them. That concern has grown since the Securities and Exchange Commission (SEC) in 2023 held the CISO of a software company personally liable for fraud. Despite the SEC dismissing the case in 2025, Knutson says its chilling effect had already taken hold. “CISOs ask me — ‘should I get my own D&O (directors and officers) insurance coverage?’” he says. 

Research from Hitch Partners, an executive search firm for security information professionals, shows more than half of CISOs at private companies don’t have indemnification policies or coverage under directors and officers insurance policies. That coverage can offer protection from financial losses resulting from regulatory actions, but also from fees, judgments and settlements resulting from lawsuits. 

Helping Your CISO Survive the Stress
Not only are CISOs worried about cybersecurity, but so are other executives. Bank Director’s 2026 Risk Survey, sponsored by Baker Tilly, found 92% of bank CEOs, board members, chief risk officers and senior executives put cybersecurity at the very top of the five risk categories they are most concerned about this year. 

Knutson says a lot of bank CISOs tell him that adds to the pressure. They say, “‘I’m expected to make sure this place is secure, but I don’t have authority. I don’t control the budget. I don’t make the decisions on spend. So, while I’m responsible, I’m unable to address it,’” he says.

Giving CISOs more say in some of those decisions could help alleviate some of that pressure. Knutson also believes banks and credit unions with sufficient resources need to step up and hire more cybersecurity professionals or pay to improve their defense systems. “Spending is probably going up, but is it going up at a rate that keeps pace with the issue?” 

But Ashworth says even institutions with tight budgets can do things to reduce CISO stress. “I’ve always been big on cross-training because I’ve always had smaller teams, from two to 10 people,” he says. “If something happens at night, the person taking the call then has at least a basic foundation [of knowledge] and they don’t have to call one of the senior people every time until they really truly get stuck. Or if they go on vacation, you’re not bothering people on vacation.” 

Geoffrey Fehling, a partner at the law firm Hunton Andrews Kurth, says financial institutions should also be providing their CISOs with D&O insurance coverage. “They’re expected to prevent and explain and react to these cyber incidents,” he says. “If that is coupled with uncertainty about whether the company’s D&O insurer is going to step up and protect them from personal exposure when there’s a serious incident or cyber event, whether it’s litigation or regulatory scrutiny, that uncertainty is absolutely another pressure point and distraction that could lead to the rise in job pressure.”

Greg Neumann leads financial technology coverage for both Bank Director and FinXTech. Greg brings more than 30 years of combined experience in journalism and financial services to the role, previously working in television newsrooms across the country and leading communications for a financial industry trade association. He holds a bachelor of arts in mass communication from the University of Wisconsin-Milwaukee.