The Splunk 2026 CISO report makes public the challenges that CISOs face when trying to meet the rising demand to mask security incidents while also complying with tightening disclosure laws.
According to the report, which draws its conclusions from the responses of 650 CISOs, 20% of respondents had experienced pressure from their organization not to disclose a cybersecurity incident or breach, and 53% of those who were challenged had reported an incident or breach anyway.
It is stated that business and regulatory priorities conflict, putting CISOs in the middle of a regulatory dilemma.
In addition, there is a growing sense among CISOs that they could face disciplinary or legal repercussions if they fail to protect the company from cyber security threats. The percentage of CISOs concerned about being held accountable for a cyber incident increased from 56% in 2025 to 78% in 2026.
The report also shows that 79% of CISOs believe their jobs have become increasingly complex over the last year, with 43% reporting having taken on new roles and responsibilities outside their primary function, such as preventing fraud and financial crime.
Moreover, 96% of CISOs responded that they are now responsible for the governance and risk management of artificial intelligence. This is yet another factor contributing to the complexity of the CISO’s work, as they must ensure that companies adopt responsible AI practices.
The increasing difficulty of the CISO position is reflected in the fact that 26% of CISOs stated they have considered quitting their jobs due to the burdensome nature of the role.
It is therefore not surprising that the report’s findings coincide with new government regulations that further tighten cybersecurity disclosure laws. For example, according to the Cyber Security and Resilience (Network and Information Systems) Bill currently under consideration in the UK Parliament, organizations in the UK will be required to report on major cyber security incidents and strengthen board-level oversight of cybersecurity.
CISOs must therefore carefully weigh the risks and benefits of any response, as reporting an incident too soon could result in financial losses for the company, whereas reporting it later could incur severe regulatory penalties.
The report recommends that CISOs focus on building and maintaining strong governance by providing detailed information on how and by whom incidents were uncovered, as well as which steps had been taken to investigate and remediate the damage.
This will ensure that the CISO’s decisions regarding disclosure of an incident are based on verifiable facts and figures. By analyzing all relevant data across enterprise networks, cloud, endpoints, or servers, the security leader can build a comprehensive report outlining the exact course of action taken after the breach was discovered.
This will help to both satisfy regulatory authorities during an audit and assist in determining if and when a report needs to be filed.
The report therefore highlights the fact that the role of the CISO has changed dramatically and now entails a wide range of responsibilities, requiring them to make decisions that go beyond the realm of traditional cybersecurity.