Burnout is becoming a significant problem in the cyber security sector, with an increasing number of cyber security professionals choosing to change careers. This is not a new problem, but one that has become more prevalent due to the growing number of cyber attacks.
Several factors are contributing to this, from the long hours and increased demands made of cyber security teams as they face ever-evolving threats from hacker groups, to the burden of responsibility when it comes to protecting sensitive data from numerous threat actors. There is also no effective downtime for cyber security professionals if they become hyper-focused on potential threats.
Bronwyn Boyle, executive vice-president of resilient communities at Cybermindz, says: “There’s no finish line. The best we can hope for, in terms of a positive result, is a no-score draw.”
Cyber burnout
Cyber security professionals are akin to first responders, as they aim to be the first on the scene when responding to an incident. However, unlike first responders, who are called out to specific incidents, cyber security professionals need to maintain awareness of new and emerging threats, and are always responding to varying degrees of cyber attacks. Hackers only need to be lucky once, but cyber defence teams need to be lucky every time.
“The best we can hope for is nothing happening,” says Boyle. “If you look at people who do other types of incident response, they resolve the incident and service is back up and running. We’re just trying to keep the bad stuff that’s outside of our control from manifesting.”
Cyber security professionals also take responsibility for ensuring that everything keeps working. With society becoming increasingly reliant on interconnected systems, cyber attacks have real-world impacts. State-sponsored hacking groups are now targeting national infrastructure, which is an attractive target because outages can undermine the population’s confidence in their government’s ability to protect them.
Such challenges have left many cyber security professionals unable to switch off at the end of the day. Even when security teams return home, their smartphones can mean they are still connected to work and expected to respond to calls and emails.
“There’s no finish line. The best we can hope for, in terms of a positive result, is a no-score draw”
Bronwyn Boyle, Cybermindz
A driver for this hyperconnectivity is that cyber security professionals need to respond quickly to an incident to mitigate damage. They cannot just wait until the morning of the next working day.
With all the focus on security resilience of networks and technologies, little is mentioned about the psychological resilience of the cyber security professionals protecting systems and data.
“We talk about people, process and technology, and we do all of these drills on resilience for our processes and our tech, but we don’t necessarily do the psychological resilience on our own mental health stock,” says Boyle.
The cost of burnout
Employers have a duty of care to ensure their employees are appropriately protected against physical and psychological harm.
The cost of burnout is far more than just losing a valued team member. Recruitment can be expensive, especially in a highly skilled profession such as cyber security, and interviewing prospective candidates ties up other members of security teams.
It costs one-and-a-half to two times someone’s salary in security to replace them. That is a big old jump. If you can keep that person happy, healthy and thriving, your company is not having that kind of delta and churn Bronwyn Boyle, Cybermindz
Knowledge loss when someone leaves must also be considered. Although various techniques exist for capturing knowledge, valuable expertise is inevitably lost. Training new candidates helps mitigate knowledge loss, but may not reach the level of expertise of departed staff.
“It costs one-and-a-half to two times someone’s salary in security to replace them. That is a big old jump,” says Boyle. “If you can keep that person happy, healthy and thriving, your company is not having that kind of delta and churn.”
The well-being of staff is both an ethical obligation and a practical consideration, so it is worth investing in retaining valuable institutional knowledge and skills.
“When we are stressed, our decision-making and executive function is not at its best,” says Boyle. “When cyber resilience practitioners are more stressed and don’t have a mechanism to reset, then it means that the defenders that you’re relying on in an incident are becoming part of a compounding issue.”
What can we do?
The mental health challenge facing the cyber security industry requires urgent action to enable cyber security infrastructure to be maintained.
Cyber attacks have now become so rampant and sophisticated that it is a case of when, rather than if, a network is breached. As such, the way an incident is framed needs to be recontextualised. There needs to be a move away from blaming the person who was tricked into allowing hackers to access a network.
Just as we identify targets of fraud as victims, so do we need to highlight that targets of hacking are victims. Targets of cyber attacks need to be encouraged to come forward and report any issues in a way that is free of blame. Organisations have a duty of care for protecting personal data by adequately investing in cyber security, including their defence teams.
“I’m a passionate advocate of not using the term ‘humans are the weakest link’, because I think, particularly now, any one of us could be engineered, and the idea of blame is so counterproductive,” says Boyle. “What you want is a trusted relationship, where people feel empowered to come and say something might have happened.”
I’m a passionate advocate of not using the term ‘humans are the weakest link’, because any one of us could be engineered, and the idea of blame is so counterproductive Bronwyn Boyle, Cybermindz
In 2017, the French government passed the El Khomri law to reform working conditions. Chapter II ‘Adapting the Labour Law to the Digital Age’ included the right to disconnect under Article 55, stating: “The procedures for the full exercise by the employee of their right to disconnect and the establishment by the company of mechanisms for regulating the use of digital tools, with a view to ensuring respect for rest periods and leave as well as personal and family life.”
It is possible that the El Khomri law will become an example and that other countries, especially within the European Union, may enact similar laws.
By legally giving employees the right to disconnect, they are able to relax and decompress without being concerned by potential incidents. This could help mitigate some of the drivers underpinning the rising cases of burnout in cyber security.
“I’ve been speaking to a few folks who were involved in high-profile breaches last year. Some of the really confronting findings were trying to recover service over a prolonged period of months when you’ve already got a huge whack of team in a trauma response or off sick because they’re struggling to cope,” says Boyle. “The idea is that you could spend a little bit of care and attention upstream – in the same ways we look at our process and tech resilience, we could do this for our psychology.”
A shift-based approach is one way to ensure that someone is always available to respond to cyber security incidents, while providing other members of the team with time off. Although incorporating on-call shifts will increase demands on resources, the costs will be far less than replacing staff suffering burnout.
There also needs to be a period of recovery after an incident. Time in lieu of overtime may help, as cyber security teams that have been involved in a major cyber security breach will need downtime after an incident to fully recover from the high-pressure situation. However, criminals could exploit this strategy, as simple attacks like a distributed denial of service (DDoS) could be used to wear cyber security teams down before the “real” attack occurs.
Increasing workloads mean greater need for support
The robust pattern recognition capabilities of artificial intelligence (AI) tools have the potential to significantly reduce the workload for cyber security professionals. However, there is also the potential for AI to compound the burnout problem.
Claude Mythos was able to autonomously discover vulnerabilities on major operating systems and produced usable strategies to exploit them within hours. Such discoveries would normally have taken researchers and penetration testers weeks. However, this also generated a high workload for cyber security teams who had to patch their systems, thereby adding to the existing stress and burnout.
Due to criminals not being bound by ethical constraints, hacker groups are already using weaponised AI tools to deploy attacks at an industrial scale. The AI-enabled proliferation of cyber attacks will naturally add to the burnout.
“If you can keep that person happy, healthy and thriving, and your company is not having that churn, you’re going to have a better bottom line,” says Boyle. “We need to have these factual conversations around risk management – our risk of attrition, burnout costs for sick pay, cost for sick leave … and that’s not even factoring in the human cost. Or we invest money in a cost avoidance strategy for the overall well-being of the company, because you’ve got engaged colleagues who are aligned on purpose and are working together as a cohesive team.”
Managed and extended detection and response (MDR and XDR) specialist Adlumin is attempting to help midmarket end-users lessen the impact of ransomware attacks by detecting…
nLighten has completed a £15m refurbishment of its Bristol datacentre, doubling its artificial intelligence (AI)-ready power capacity to 1.2MW to support regional enterprise workloads. The…
The Ministry of Justice (MoJ) has signed a Memorandum of Understanding (MoU) with OpenAI to provide civil servants with access to ChatGPT Enterprise. The MoU…
Fujitsu will pay bonuses to UK staff this year despite the ongoing controversy around its involvement in the Post Office scandal and its delayed contribution…
Across Europe, the Middle East and Africa (EMEA), organisations must up their game when it comes to addressing the human factors leading to data breaches…
The interim findings of the Competition and Markets Authority’s (CMA’s) investigation into Microsoft’s cloud software licensing strategy should be a significant cause for concern for…