Chief information security officers, already fretting over hackers’ increasingly nefarious tactics and regulators penchant for holding individual executives liable for security lapses, have a new worry: that their C-suite colleagues will make them the scapegoat if something goes wrong.

That’s why cybersecurity experts have begun advising CISOs to build an intricate paper trail documenting their diligence, including security investments they recommended but were rejected as too costly.