{"id":3714,"date":"2024-05-23T07:21:28","date_gmt":"2024-05-23T12:21:28","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-careers\/persistent-burnout-is-still-a-crisis-in-cybersecurity"},"modified":"2024-05-23T07:21:28","modified_gmt":"2024-05-23T12:21:28","slug":"persistent-burnout-is-still-a-crisis-in-cybersecurity","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/23\/persistent-burnout-is-still-a-crisis-in-cybersecurity\/","title":{"rendered":"Persistent Burnout Is Still a Crisis in Cybersecurity"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt1d2ae7d32d43a29e\/65e24973136b90040a17d761\/Meeting_Andriy_Popov_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/persistent-burnout-is-still-a-crisis-in-cybersecurity.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/persistent-burnout-is-still-a-crisis-in-cybersecurity.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Dr. Ryan Louie, a psychiatrist focused on the intersection of cybersecurity and mental health, recalls a valuable lesson from his medical student days that cybersecurity practitioners may find relevant: \u201cDuring one of my clinical clerkships at the hospital, our team&#8217;s attending physician on the first day of the rotation highlighted that &#8216;We are a team, and that everyone should feel free to say whenever they feel they have too much on their plate or if they need any help.&#8217; And that medical students and residents on the team should not worry about impacts to their evaluation. There was genuine psychological safety,\u201d he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But for many cybersecurity practitioners, their work is rife with the need for secrecy and discretion, making psychological safety difficult to attain. Expressing vulnerability and sharing feelings don&#8217;t happen often in this competitive environment. This lack of open communication, coupled with what often feels like never-ending crisis and work cycles, is leading to burnout at high levels in cybersecurity.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Conversations about burnout has been ongoing for nearly a decade, and the industry is getting better at recognizing the issue, but actual strategies for addressing \u2014 and preventing \u2014 burnout are still lacking.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Malcolm Harkins is no stranger to the demands of the high-stress field of cybersecurity. The chief security and trust officer at Hidden Layer (and the former chief security and privacy officer at Intel, among other past executive positions with security companies), he <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.gartner.com\/en\/webinar\/587297\/1315216\" rel=\"noopener\">speaks frequently about burnout<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, especially for chief information security officers (CISOs). A recent Gartner Peer Community survey found 62% of IT and security leaders have experienced burnout, and that many CISOs plan to leave their jobs or careers due to what Gartner called &#8220;unique stressors.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Burnout in cybersecurity, according to Harkins, is more than a personal issue \u2014 it&#8217;s a systemic problem that can undermine the very foundations of digital safety. He says the origins of cybersecurity burnout are deeply rooted in the relentless pace of demands, like those introduced by Patch Tuesday, where security teams scramble to fix software vulnerabilities within tight monthly deadlines.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;You&#8217;d have all these patch things \u2014 that was the workload that was driving, I think, a lot of the cycles of feeling burnt out,&#8221; Harkins says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While Patch Tuesday has been around for more than 20 years, the pressure to work late nights and weekends isn&#8217;t a historical footnote; it&#8217;s a present-day reality that continues to strain security professionals. And it is not hard to find survey after survey confirming that the consequences of never-ending work cycles are taking a toll. A<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/assets.sophos.com\/X24WTUEQ\/at\/wkk9cs4q3f7rg52hj33t\/sophos-future-of-cybersecurity-apj-wp.pdf\" rel=\"noopener\"> Sophos survey finds<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;85% of respondents from six Asia-Pacific countries say they are suffering from burnout, and 90% report increases in burnout in the past year.&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.mimecast.com\/blog\/helping-cybersecurity-teams-maintain-mental-health\/\" rel=\"noopener\">A survey from Mimecast<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> finds 56% of cybersecurity workers experience increased work stress every year, and 54% of respondents say that&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.mimecast.com\/blog\/ransomwares-relentless-rise-strains-security-teams\/\" rel=\"noopener\">ransomware threats<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;are having a negative impact on their mental health.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Harkins says this is due to two primary &#8220;battlefields&#8221; that cybersecurity professionals navigate: the external threats from hackers and cybercriminals, and the internal challenges posed by budgets, bureaucracies, and corporate behaviors. These factors combine to create a relentless grind that can wear down even the most resilient individuals.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"CISO: The Loneliest Executive\">CISO: The Loneliest Executive<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The isolation of running a security program is another factor in burnout specific to the cybersecurity industry. The core of the problem, Harkins argues, lies not only in the volume of work but also in the organizational and cultural structures of the companies within the cybersecurity industry. Top security executives, like the CISO, are not immune to these pressures and are, in fact, even more lonely than the team they manage.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Shamla Naidoo, head of cloud strategy and innovation at Netskope, also points to the loneliness of the CISO and others in charge of security, a feeling compounded by secrecy and confidentiality that often isolates CISOs from potential support systems.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">CISOs, she says, &#8220;are encouraged to operate under a cloud of secrecy and bound by confidentiality,&#8221; noting the expectation contradicts with societal norms that encourage open discussions about stress and mental health. And the expansion from traditional office and data center security to managing hybrid and remote workforces has significantly increased the complexity and stress of the cybersecurity role.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The job was hard back in 2013,&#8221; Naidoo says. &#8220;It\u2019s gotten harder since. The pressures are mounting from things like securing a remote workforce to securing a hybrid workforce, with constant change and heightened expectations.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Louie says his work leads him to conclude there is a pervasive need for a broader understanding and proactive measures in the industry.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The CISO role has added pressure, and it&#8217;s already built into the title: CISO has four letters in it, one extra letter compared to the three-letter roles such as CEO or CFO,&#8221; he says. &#8220;They are in charge of being the chief. They are in charge of information. They are in charge of security. And they are in charge of being an officer. These are all tremendous responsibilities that can each pull the CISO in a different direction, on top of an already very stressful environment.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The role\u2019s unique responsibilities contribute to higher levels of isolation and stress, and CISOs often lack a support system where they can discuss their challenges freely and safely. This leads to what Louie calls a &#8220;mental health attack surface,&#8221; warning that mental health vulnerabilities could potentially be exploited maliciously, much like cybersecurity vulnerabilities.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We have to view burnout and mental health not just about taking care of ourselves, but also think one step further and beyond: Could mental health be exploited by those with bad intentions?&nbsp;&#8221; Louie says.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Communication: The Antidote to Burnout\">Communication: The Antidote to Burnout<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Harkins says he regularly hears that security executives want to commiserate, but as the highest ranking member of their team, that can be difficult. Many feel lonely because, at the top, there is really nowhere else to go to ask for assistance.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">\u201cOther than to the board, there is really nowhere to go that\u2019s higher. But obviously CISOs use that board relationship in a different way,\u201d he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Harkins created a framework known as &#8220;I Believe, I Belong, I Matter,&#8221; based on life lessons that he hopes can help security professionals feel a sense of purpose, passion, and persistence to avoid burnout.&nbsp;He also thinks a shift is needed in how cybersecurity is approached, with a move toward understanding and addressing the material risks that companies face, rather than merely reacting to breaches as they occur, which only contributes to the never-ending cycle of work.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We need to get security to have design goals, not just metrics,&#8221; he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Netskope\u2019s Naidoo suggests community building, and encouraging CISOs to form support networks and small groups where they can share challenges and solutions without judgment, is a solid first step. Other suggestions include industry safe spaces for CISO discussion and cultural shifts that promote a culture of shared responsibility for security across all company levels, alleviating the isolation of the CISO and security team.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Culture is everything for a typical CISO portfolio to be successful,&#8221; she says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Referring back again to his medical training days, Louie says the model of open communication and psychological safety within his team led to effective collaboration and stress management. He thinks similar practices could be transformative in the cybersecurity field, particularly for those in high-stress positions like CISOs. Encouraging open dialogue about mental health within cybersecurity teams can foster a supportive environment that mitigates burnout and enhances overall team resilience.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Organizations are made up of people. And I believe that the stress, burnout, and mental health of an individual extends to the stress, burnout, and the mental health of an organization,&#8221; he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Louie envisions a shift in how CISO roles are perceived and integrated within businesses. He advocates for greater awareness of what CISOs do and for opportunities for them to learn about the functions of other departments, which can lead to more integrated and effective cybersecurity practices across all levels of an organization.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We should build a cybersecurity mindset into our daily practice,&#8221; he says, &#8220;and take charge of it within our domain and scope of practice.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-careers\/persistent-burnout-is-still-a-crisis-in-cybersecurity\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Dr. Ryan Louie, a psychiatrist focused on the intersection of<\/p>\n","protected":false},"author":12,"featured_media":3715,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3714","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/persistent-burnout-is-still-a-crisis-in-cybersecurity.jpg?fit=1800%2C1252&ssl=1",1800,1252,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/persistent-burnout-is-still-a-crisis-in-cybersecurity.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/persistent-burnout-is-still-a-crisis-in-cybersecurity.jpg?fit=300%2C209&ssl=1",300,209,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/persistent-burnout-is-still-a-crisis-in-cybersecurity.jpg?fit=640%2C445&ssl=1",640,445,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/persistent-burnout-is-still-a-crisis-in-cybersecurity.jpg?fit=640%2C445&ssl=1",640,445,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/persistent-burnout-is-still-a-crisis-in-cybersecurity.jpg?fit=1536%2C1068&ssl=1",1536,1068,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/persistent-burnout-is-still-a-crisis-in-cybersecurity.jpg?fit=1800%2C1252&ssl=1",1800,1252,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/persistent-burnout-is-still-a-crisis-in-cybersecurity.jpg?fit=1024%2C712&ssl=1",1024,712,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/persistent-burnout-is-still-a-crisis-in-cybersecurity.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/persistent-burnout-is-still-a-crisis-in-cybersecurity.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/persistent-burnout-is-still-a-crisis-in-cybersecurity.jpg?fit=1800%2C1252&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3714","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3714"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3714\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3715"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3714"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3714"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3714"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}