A European board called us a few weeks ago about a CISO search. The remit ran to four pages. Somewhere in the middle, the same paragraph described the ideal hire as "a strategic business partner who will own the board and regulatory relationship" and "a hands-on technical leader who will rebuild the detection and response stack."
I have been hiring in cyber for more years than I care to share. Most of the CISOs and Cyber Directors I have met in the last 24 months are describing the same experience, and most of the briefs crossing my desk in that window have read like the one above. The brief describes two people with the hope that one candidate will show up. The odds are, they won't. And the reason why is the most important governance conversation European boards need to address, right now!
The regulation has made it personal (management liability)
Germany issued its first NIS2 penalty in February. A mid-sized cloud provider, €850,000, for inadequate risk management and incident response. France opened investigations into fourteen entities across healthcare and digital infrastructure in the same quarter. Ireland has not yet transposed the directive, the National Cyber Security Bill is still in the legislative queue and the European Commission has already issued a reasoned opinion, but when it commences, the NCSC estimates scope will jump from around 450 NIS1 operators to between 4,500 and 6,000 entities. The UK's Cyber Security and Resilience Bill cleared its second reading in January, with phased implementation starting mid-2026. Managed service providers, data centre operators, load controllers, all about to inherit obligations they have never carried before.
€850K
Germany's first NIS2 penalty — February 2026
~6,000
Entities in scope under Ireland's draft Bill (vs. 450 today)
4 hrs
DORA incident notification window — financial services
The detail that changes the leadership equation is personal management liability. Under NIS2, senior managers can be individually fined, temporarily banned from holding office, or held liable in their own right for governance failures. Germany's implementing statute has already activated that mechanism. Ireland's draft goes further, with specific enforcement hooks for CEOs and directors of essential entities. DORA carries equivalent exposure in financial services, with a four-hour incident notification window that in practice requires a pre-built decision protocol and a general counsel on speed dial.
Simply, no element of this explicitly existed in the role of CISO, five years ago.
The unicorn is dead. Everyone just hasn't said so.
For a decade, the pitch was that one executive could hold it all. Board reporting, regulatory strategy, architecture, engineering, vendor risk, incident response. The unicorn CISO was already a tough hire in 2022. Today, the job description is no longer internally coherent.
Look at what the role actually contains today. A European CISO in scope of NIS2 must personally register with the competent authority, certify the adequacy of risk measures, and maintain an audit trail that will hold up when an incident triggers supervisory attention. Splunk's 2026 CISO Report has 96% of CISOs carrying accountability for AI governance. The WEF's 2026 outlook has cyber-enabled fraud overtaking ransomware as the top CEO concern, driven largely by deepfake executive impersonation. Arup lost $25m to a deepfake CFO on a video call. Voice cloning now works from three seconds of audio.
Point at the one person who can stand in front of the Central Bank's operational resilience team, reconstruct an identity architecture mid-incident, negotiate a DORA notification with legal counsel, and explain model poisoning to a non-technical chair. There are perhaps sixty of them in Europe. And they move every five or so years.
96%
CISOs carrying AI governance accountability — Splunk 2026
$25M
Lost by Arup to a deepfake CFO on a single video call
85%
Orgs reporting at least one deepfake-related incident in 12 months
What forward thinking organisations are doing instead
The firms pulling ahead have started splitting the role, while safeguarding title and seniority:
Role One
STRATEGIC CISO
Owns the risk register, policy, regulators, board reporting, and the personal liability. Governance operator first, technologist second. Often a lawyer or former Big Four partner with cyber depth, or a seasoned CISO who has decided to stop running engineering.
Role Two
VP OF SECURITY ENGINEERING
Owns controls, detection, response, identity, and the AI governance technical stack. Hands-on technical leader, usually from a platform engineering or SRE lineage, judged on mean-time-to-remediate rather than boardroom poise.
One outcome plan, shared metrics, however the liability and the regulatory face of the firm sit with the Strategic CISO. The engineering leader is protected from board politics and free to build (and ethically hack / stress test the organisation's security posture for that matter).
Where this structure is not in place, one of two things happens. Either the sitting CISO is being paid on a 2022 salary while carrying 2026 liability, which is why so many experienced leaders are now moving to fractional and advisory roles and naming the accountability-authority gap explicitly when they do. Or the engineering build is being starved because the person nominally in charge is spending three days a week in board prep and regulator meetings. Both failure modes turn up in our search conversations every week.
The UK and Ireland picture is not symmetric
These two countries, while greatly dependent on one another for trade, are in totally different places on this timeline, and it matters for how boards should be hiring right now.
Ireland is twelve to eighteen months behind Germany on enforcement, and that gap is creating a dangerous complacency. The National Cyber Security Bill is expected to commence this year with a likely July readiness deadline for critical entity identification. Registration will trigger supervisory powers, audit rights, and sanction mechanisms that target the management body directly. Irish boards waiting for commencement before they restructure cyber leadership will be hiring into a market already picked over by better-prepared firms elsewhere.
The Irish candidate pool for the regulatory-facing version of the role is small. Fifteen to twenty people on the island who can credibly hold that seat in a large essential entity. Most are placed. The rest are being pursued by firms who read the Bill properly when it was first published.
There is also a structural point Irish boards underestimate. The draft Bill's enforcement mechanisms reach CEOs and directors of essential entities, not just the CISO. That makes cyber a board conversation, not an IT one. A board that delegates the topic to the CIO and an outsourced MSSP is quietly absorbing personal liability without the corresponding oversight. A Strategic CISO reporting to the CEO or directly to a Risk Committee is the only structure that survives a post-incident review.
The UK is ahead of Ireland but behind Germany. The Cyber Security and Resilience Bill will bring an additional 900 to 1,100 managed service providers into scope, with the ICO acting as regulator for that segment. UK-regulated financial services firms have been living under FCA and PRA expectations that effectively anticipated DORA, so the senior cyber leadership market in London and Edinburgh is more mature than Dublin's. Where the UK falls somewhat short is at the VP Engineering level, where candidates who combine deep controls engineering with the ability to leave an auditable evidence trail are genuinely difficult to appoint.
For boards in either market, the decisions made in the next six months will shape regulatory posture for the next three years. Getting this wrong is not a mid-career correction. It is an enforcement event, and it will be explained to shareholders.
The threat side is accelerating the same problem
If the regulatory picture were the only pressure, boards would have time to adjust. The threat side is simply not allowing for that time.
Mandiant's M-Trends 2026 puts mean time to exploit at minus seven days. In plain English, adversaries are now routinely exploiting vulnerabilities before a patch is released. An AI-assisted operator going after a mid-sized European firm can ingest corporate filings, LinkedIn transitions, regulatory notifications, and leaked credentials in minutes, and produce a prioritised attack plan rather than a generic reconnaissance dump. IBM's internal testing found that generative AI built a phishing campaign in five prompts and five minutes that performed as well as one that took human experts sixteen hours. Underground marketplaces sell deepfake services for €500 to €2,000 a silo. Industry data has 85% of organisations reporting at least one deepfake-related incident in the last twelve months.
-7 days
Mean time to exploit — Mandiant M-Trends 2026
5 mins
AI-built phishing campaign vs. 16 hrs for human experts — IBM
€500–2K
Cost to purchase deepfake services on underground marketplaces
The defensive consequence is that identity has replaced the network perimeter as the primary control plane, and AI governance is no longer adjacent to cyber. It is cyber. The VP Engineering of 2026 has to be fluent in prompt injection and identity forgery at machine speed. The Strategic CISO needs to be able to explain, in plain English to an audit committee, why a four-hour notification window exists and what the firm's exposure actually looks like when someone can deepfake the CFO on three seconds of audio. One person is simply not going to carry both conversations well for long.
What this changes in the hiring conversation
Back to the brief I opened with. When we got on the call, we spent the first thirty minutes speaking about everything except candidates. We talked about which of the two jobs the board was actually hiring for, what the reporting line would look like, whether the general counsel was in the incident chain, and whether the compensation package reflected the personal regulatory exposure the individual would be carrying.
I suspect that most of these calls will result in the coining of two to three roles. That is almost always the right answer in 2026, and it is the answer most boards arrive at once someone walks them through the liability question carefully.
If you are sitting on a senior cyber search right now and the remit still reads like the one I opened with, the shortlist is not the problem. The brief is. Fix that first and the rest may be a little more straightforward.
If you are navigating a CISO or VP Security Engineering search, or restructuring your cyber leadership model ahead of NIS2 commencement, I'd welcome a conversation. Sentiro Partners works with boards and executive teams across the UK, Ireland, and Europe on exactly these mandates.
SP
ABOUT SENTIRO PARTNERS
Leadership for the Augmentation Era™
Sentiro Partners is a global executive search firm specialising in frontier technology, AI, digital, product, and go-to-market leadership. Founded by Adrian Clarke, we scout the frontier to secure transformational leaders, experts, and mavericks who will define the future of the human & agentic workforce. Headquartered in Dublin, Ireland. Operating globally.