Spoiler: Itâs a revolving door problem â and itâs costing both teams and companies the win.
The Cleveland Coach Carousel đ
Since the Browns returned to Cleveland in 1999, fans have endured what feels like a never-ending parade of head coaches.
In just over two decades, the Browns have cycled through 12 full-time head coaches â not including interim stand-ins. Thatâs an average tenure of roughly two years per coach.
The result?
A record of 142â283â1 â a .335 win percentage that tells a clear story: constant leadership turnover kills momentum.
Each new coach brings a new system, new staff, new philosophy. Players must relearn playbooks. Culture resets. And just when things start to click â a new face walks through the door with another âfive-year plan.â
Itâs not just instability â itâs instability institutionalized.
(And no, weâre not even going to talk about quarterbacks⌠we all know that list is longer than a CVS receipt.)
The CISO: The Head Coach of Your Cyber Defense
Now letâs switch from the 50-yard line to the boardroom.
The Chief Information Security Officer (CISO) is your organizationâs defensive coach â responsible for strategy, alignment, and execution across a complex playbook of risks.
But just like the Brownsâ sideline, CISO turnover is notoriously high.
The average CISO tenure is around 18 to 26 months, far shorter than other C-suite roles.
In comparison, CIOs average 4â5 years, and CEOs even longer.
Some Fortune 500 companies do better (around 4.5 years, according to Fortify Experts), but many mid-market firms churn CISOs faster than they can update their LinkedIn bios.
Why? Burnout, unclear authority, unrealistic expectations, and a disconnect between boards and technical teams. Sound familiar?
When Leadership Turns Over, So Does the Playbook
The parallels are almost painful:
| Theme | Cleveland Browns | Corporate Cybersecurity |
|---|---|---|
| Leadership Instability | 12 coaches in 25 years | CISO average tenure â 2 years |
| Constant Change | New systems, staff, and culture resets | New vendors, frameworks, and shifting priorities |
| Lack of Continuity | Players relearn every season | Teams reorg after every leadership change |
| Performance Impact | Losing seasons pile up | Security posture weakens, risk visibility fades |
| Root Cause | Ownership dysfunction, short-term thinking | Board misalignment, unclear expectations |
The Brownsâ record is on display for the world to see â the win/loss column doesnât lie.
But your companyâs cybersecurity record isnât nearly as visible. You donât get a Monday-morning box score for âattacks preventedâ or ârisks mitigated.â
Still, make no mistake: the higher the CISO turnover, the worse your overall security posture likely is.
The Takeaway for Boards đ§
If youâre sitting on a board, hereâs a question worth asking:
âHow many CISOs have we had in the past five years?â
If the answer makes you wince, thereâs a deeper problem â not just with the CISO, but with how the organization supports (or undermines) that role.
Strong defenses come from stability, trust, and long-term strategy, not quick fixes or new hires every two years.
So the next time youâre tempted to swap out your CISO hoping for a âfresh start,â remember:
You canât win championships by constantly changing coaches.
(And seriously â letâs not start counting quarterbacks, okay?)
âď¸ Possible Objections & Caveats
Not every turnover is bad â sometimes a change is needed due to mismatch, unethical behavior, or stalled performance.
Some organizations may require a âturnaround CISOâ, just as some franchises hire a firebrand coach to rebuild culture and discipline.
Fortune-level CISOs may enjoy longer tenure; averages often mask the variance between SMBs and enterprise-scale environments. (Source: Fortify Experts)
Winning in football is zero-sum and binary (win vs. lose); cyber defense is probabilistic â many interventions only show their value over time, not in a single âseason.â
Â

