BlogSecurity
August 31, 2026

Zombie work is biting CISOs

Written by
Lucia Giles
Sr. Content Marketing Manager
Reviewed by
No items found.

Accelerating security solutions for small businesses 

Tagore offers strategic services to small businesses. 

A partnership that can scale 

Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate.

Standing out from competitors

Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

There are tasks on your to-do list that just never die. It’s those things you maintain ownership of, but are waiting on other people to resolve. This is zombie work. 

We dug into data across 16,000 Vanta customers, observing how security tasks are distributed and what percentage actually get closed.

We found a zombie work outbreak among CISOs.

The work that never gets done

There’s a structural dynamic hiding inside how security work flows through organizations, and it hits certain personas harder than others. 

The first dedicated security hire at a scaling organization closes 96% of the tasks assigned to them in Vanta. At that stage, ownership is unambiguous, and blockers are rare. The work is high-volume, but it moves fast under a single owner.

But as organizations grow, there’s a notable contrast. When dedicated GRC practitioners and security leadership come on board, incomplete work increases tremendously. GRC personas carry a 44% incomplete task rate, while CISOs sit at 49%. 

Nearly half of everything on their plate remains unresolved. And a large number of tasks sit idly for months. For CISO’s, almost 1/3 of incomplete tasks show no activity for 60+ days. That number climbs to 70% for GRC personas. 

Why the work stalls

The work doesn’t stall because security professionals aren’t working. Larger organizations naturally have more work to be done, due to new compliance initiatives, international expansion, increased regulatory exposure, plus more systems and more vendors to contend with. CISOs and GRC professionals also deal with a backlog burden—often coming into the role inheriting a large backlog of work that previously had no owner. 

Cross-functional dependencies are another huge factor. A lot of the work at larger organizations can’t be resolved by a single individual in security. Instead, as organizations grow, security becomes a function that identifies problems for other people to solve. 

Unfinished tasks = expensive risks 

For GRC practitioners, 81% of unresolved work consists of remediating audit findings and compliance gaps. The most common unresolved tasks are things like CCTV installation and IDS/IPS implementation, or standing up organizational processes related to quarterly access reviews, like scheduling an event-driven access review after a new team member joins. These tasks often require collaboration with other departments like engineering, IT, operations, or subsets of security like a corporate/physical security team.

For CISOs, over 90% of their backlog is deprovisioning work like removing departed employees from Zoom, Google Workspace, or Gong. While CISOs wouldn’t normally be responsible for this work themselves, they remain the assigned owner while waiting on IT teams or application owners (who often aren’t in Vanta themselves) to execute the work. 

Notably, a lot of workflows around provisioning can be automated—like notifying a system administrator when access updates are needed—but manual execution is required for apps that don’t allow programmatic user access changes. That’s where the bottleneck with application owners comes in. 

All of this zombie work creates expensive risks. Almost 60% of a CISO’s deprovisioning tasks remain unresolved for 30+ days. Yet a former employee's Zoom or Google Workspace account sitting active for weeks is exactly the kind of oversight that surfaces in breach post-mortems, and the financial exposure is steep. The global average cost of a data breach is almost $5 million.

Unresolved compliance gaps that sit under a GRC practitioner's task list carry their own exposure: GDPR violations alone can reach €20 million and HIPAA penalties can hit over $2 million annually.

An antidote to the outbreak

Complexity and the rise of cross-functional security work aren't going away. The natural instinct is to try to implement better agentic workflows to design around it. But even that has limits when a manual execution step is required to complete a task. Automations and agentic workflows can flag the right person or track a task's status more efficiently, but can’t always (and shouldn’t always) click “remove” on a human’s behalf. 

Closing the gap takes a different kind of job versus a different type of tool. And success is dependent on your ability to foster cross-functional collaboration. 

A security team of one closes its own tickets. But a GRC professional or CISO running a mature program can’t. Individual effort has a ceiling when the work is distributed across multiple owners and departments. More often, the job is about trying to get someone who doesn’t report to you to finish something you can see, but can’t resolve. That takes a different kind of energy than most security careers train for.

Early on, at a smaller company, the job rewards technical depth: know the system, fix it. As organizations grow, it rewards relationship management instead. CISOs need to build a shared sense of security responsibility across their organizations so when they need another team to act, there’s no hesitation. Getting buy-in from other teams is core to the role, not a side project.

Encouraging greater collaboration can be done multiple ways. Embedding and investing in security champions across an organization positions security as everyone’s responsibility,  rewarding secure behaviors publicly encourages positive action, and maintaining an open feedback loop helps build processes that work for all involved. 

That shift in the role is hard, and it’s an under-documented contributor to the burnout crisis in security.

The backdrop of CISO burnout

Most burnout explanations focus on the external environment: escalating threats, stress of dealing with incidents, chronic underfunding, board pressure, and talent shortages. Add that to the fact that security leaders are “always on”—which is backed by our own data. Every persona in Vanta's platform, from the first dedicated security hire at a scaling startup to GRC practitioners to CISOs, shows meaningful weekend work activity. 

Zombie work—and what it represents about the shift in security responsibilities—is a missing variable in the conversation. The bigger the organization, the less power security leaders have to get the job done. One person becomes accountable for outcomes they can’t structurally control. 

And full accountability with only partial control is a recipe for burnout. 

Methodology: The anonymized data used in this analysis comes from Vanta's product usage telemetry and task management system across thousands of organizations from January through June 2026. Persona classification (CISO, GRC, Security Operations, Engineering, Founder) is derived from Vanta's user role taxonomy. Task analysis is scoped to organizations with at least one identified CISO user and limited to user-created tasks since January 2025, with completion status determined at the time of analysis. Incomplete rate represents tasks in an open or overdue state as a percentage of all tasks created by that persona. Session frequency, duration, and active days are reported at the user level and aggregated by persona using medians to reduce skew from outliers

Access Review Stage Content / Functionality
Across all stages
  • Easily create and save a new access review at a point in time
  • View detailed audit evidence of historical access reviews
Setup access review procedures
  • Define a global access review procedure that stakeholders can follow, ensuring consistency and mitigation of human error in reviews
  • Set your access review frequency (monthly, quarterly, etc.) and working period/deadlines
Consolidate account access data from systems
  • Integrate systems using dozens of pre-built integrations, or “connectors”. System account and HRIS data is pulled into Vanta.
  • Upcoming integrations include Zoom and Intercom (account access), and Personio (HRIS)
  • Upload access files from non-integrated systems
  • View and select systems in-scope for the review
Review, approve, and deny user access
  • Select the appropriate systems reviewer and due date
  • Get automatic notifications and reminders to systems reviewer of deadlines
  • Automatic flagging of “risky” employee accounts that have been terminated or switched departments
  • Intuitive interface to see all accounts with access, account accept/deny buttons, and notes section
  • Track progress of individual systems access reviews and see accounts that need to be removed or have access modified
  • Bulk sort, filter, and alter accounts based on account roles and employee title
Assign remediation tasks to system owners
  • Built-in remediation workflow for reviewers to request access changes and for admin to view and manage requests
  • Optional task tracker integration to create tickets for any access changes and provide visibility to the status of tickets and remediation
Verify changes to access
  • Focused view of accounts flagged for access changes for easy tracking and management
  • Automated evidence of remediation completion displayed for integrated systems
  • Manual evidence of remediation can be uploaded for non-integrated systems
Report and re-evaluate results
  • Auditor can log into Vanta to see history of all completed access reviews
  • Internals can see status of reviews in progress and also historical review detail
FEATURED VANTA RESOURCE

The ultimate guide to scaling your compliance program

Learn how to scale, manage, and optimize alongside your business goals.