CISO Tribune

Analysis

The CISO employment contract: what to negotiate before you sign

The contract terms security leaders should negotiate — indemnification, D&O coverage, severance, incident decision rights — and why the negotiation itself is a diagnostic.

By CISO Tribune Editorial · Published June 30, 2026 · 2 min read

TL;DR: The CISO seat carries personal legal exposure, incident-driven termination risk, and accountability that often exceeds authority. The contract is where those get priced. Negotiate five things — D&O coverage, indemnification, severance, decision rights, and structure in writing — and treat the company's reaction as the most honest preview of the job you'll get.

Why the contract matters more for CISOs than for peers

Three asymmetries. The role can end because of an incident nobody could have prevented — companies change security leaders after breaches as a signal, independent of fault. The role carries personal regulatory exposure — certifications with your name (NYDFS), disclosure processes you feed (SEC), and the post-Sullivan reality that how incidents are handled can become a personal legal matter. And the role's accountability routinely exceeds its authority — the contract is where you close that gap or at least document it.

What are the five asks?

1. D&O coverage, in writing. Confirmation that the CISO is covered as an officer under the directors-and-officers policy, with Side A protection (which pays individuals when the company can't or won't indemnify). Ask to see the policy; have your own counsel skim it.

2. Indemnification. A clause committing the company to advance and cover legal costs for acts within the scope of your duties, to the fullest extent the law allows. This is the company's own promise, sitting in front of the insurance.

3. Severance and equity treatment. Defined severance on termination without cause — and attention to what "cause" means; it should not be drafted so broadly that a breach on your watch automatically qualifies. Equity vesting treatment on termination matters as much as the cash.

4. Decision rights. Who determines disclosure? Can you take a revenue system offline in an active incident? Who owns the ransom question? These belong in the role charter referenced by the contract, not in hallway assurances.

5. Structure in writing. Reporting line, board cadence, budget authority. Verbal commitments about "direct access to the board" have a short half-life once the hiring urgency passes.

What does the negotiation itself tell you?

Everything. A company that says yes readily understands the modern role. A company that negotiates in good faith but pushes back on specifics is normal. A company that treats D&O and indemnification questions as impertinent, or refuses to put the reporting line in writing, is telling you precisely how the worst day will go — you will be alone in it. Candidates increasingly (and rightly) treat a refusal on all protection items as a decline signal, whatever the compensation.

What else deserves attention?

Three quieter clauses. Non-disparagement and cooperation terms — after an incident-driven exit, these shape what you can say and what help you owe. Clawback exposure — understand which policies apply to your compensation. The exit narrative — senior security roles are small-world; a pre-agreed reference posture in severance terms protects the next search. None of this is adversarial; it's two parties pricing a risky seat honestly. The companies worth working for respect the candidate who negotiates like they understand the job — because that is, itself, evidence they do.

Frequently asked questions

Should a CISO ask for D&O coverage?
Yes. Written confirmation that the CISO is covered as an officer under the company's directors-and-officers policy — ideally with the policy reviewed by the candidate's own counsel — has become a standard ask after the Uber and SolarWinds cases.
What is indemnification in a CISO contract?
A commitment that the company will cover legal costs and, where lawful, liabilities the CISO incurs for acts within the scope of the role. It complements D&O insurance: indemnification is the company's promise; D&O is the insurance behind it.
Is severance normal in CISO contracts?
Increasingly, yes — because the role carries structural termination risk after incidents regardless of fault. A defined severance and treatment of equity on termination without cause reflects the seat's real risk profile.

CISO Tribune Editorial

Editorial Desk

The CISO Tribune editorial desk reports on security leadership: who holds the role, who is leaving it, and what the moves mean. Every appointment entry is verified against a primary source before publication.