The board of a Fortune 1000 financial services company just fired the CISO and Deputy CISO because they did too good a job cataloging all of the risk in their infrastructure. Now that it's documented and defensibly quantified, the company is somewhat obliged to do something about it, and the board was not thrilled.
It can be a rough gig.