April 3, 2023 By Jennifer Gregory 4 min read

There is little debate that cybersecurity jobs are very stressful. In addition, few people will argue that an organization’s growth and revenue depend on its cybersecurity team. However, recent research has shown that the stressful nature of our industry may be setting up organizations for increased cybersecurity vulnerabilities.

A third of cybersecurity leaders are planning to quit

Research from BlackFog found that almost a third (32%) of CISOs or IT cybersecurity leaders in the U.K. and the U.S. are considering leaving their current organization. Among those with plans to leave, a third are hoping to quit within the next six months. Reasons for their dissatisfaction included a lack of work-life balance (30%) and too much time spent on firefighting rather than focusing on strategic issues (27%).

The survey also found that frustration stemmed from the skills shortage and the many changes in cybersecurity. Many of the leaders (52%) reported struggling with new frameworks and models, such as zero trust. One in five leaders also found the skill level of their team to be a serious challenge. Staying on top of the rapidly changing industry was also stressful, with 54% saying keeping up with the latest on solutions was hard and 43% reporting it was difficult to keep pace with the innovations.

Improving retention for cybersecurity leaders

When a CISO or IT cybersecurity manager leaves, organizations are often more vulnerable. Additionally, the time spent hiring and training new leaders takes away from protecting the organization. Other employees on the team often leave when a leader takes on a new job, further disrupting cybersecurity.

One of the roles of a cybersecurity leader is to reduce attrition on their team. However, many organizations fail to ensure that cybersecurity leaders are engaged and satisfied with their jobs. Organizational leaders must prioritize retention at all levels of their cybersecurity team.

Here are some ways to reduce stress and increase support for CISOs and security managers.

Support work/life balance

Because cybercriminals work 24/7, so must your security team. Unfortunately, that often means that cybersecurity leaders are constantly on call, which is unhealthy and leads to burnout. Additionally, your cybersecurity leaders set the example for work/life balance for their team. If they do not show good boundaries, their team will do the same. This creates a vicious cycle: teams burn out faster, employees quit and the cybersecurity manager’s stress level rises.

Provide training and support

Many leaders find it challenging to keep up with the ever-evolving nature of cybersecurity. To that end, organizations should ensure that their cybersecurity leaders have the training they need to stay up to date. By setting a budget for training, cybersecurity leaders can stay educated on both current threats and strategies to reduce risk.

When cybersecurity leaders feel confident in their knowledge and abilities, they often feel less stressed and burned out. Organizations should also consider how they can partner with cybersecurity experts, such as IBM X-Force, to get additional support and expertise when needed to further support their cybersecurity leader.

Establish backups for cybersecurity leaders

Leaders often feel like they are always on call because that’s the reality. Therefore, it’s important to work with cybersecurity leaders to train other managers or team members to rotate being on call with the leader. Yes, they must be contacted if a breach or attack occurs. But beyond those emergencies, organizations can build backups so leaders can count on times when they are not the first line of defense.

Make PTO mandatory

Consider requiring employees to use their PTO. At the same time, encourage them to fully disconnect by providing backup for their responsibilities while they are gone and not expecting them to check in or work remotely. According to SHRM, 78% of managers agree that vacation improves employees’ focus, and 81% say time off soothes burnout. But this only happens if employees actually take their vacation and don’t work remotely. Organizational leaders should also model this by taking their own PTO, which sets a good example.

Offer flexibility

Cybersecurity leaders will often work overtime, weekends and nights, even with the best plans in place. Organizations need cybersecurity professionals to be flexible when an emergency arises. By showing them the same courtesy, you can reduce their stress and improve productivity. Offering leaders (and employees) as much flexibility as possible on when and where they get their work done can help balance the inevitable inconveniences of cybersecurity.

In addition to the ability to work remotely, give leaders the flexibility to set their own hours. By providing this flexibility to both cybersecurity leaders and team members, you reduce the risk of burnout for everyone, which can significantly reduce your overall cybersecurity risk. When the cybersecurity team works overtime with emergencies, reward them with comp time or additional PTO to help offset the stress of the event.

Foster a “when not if” approach to breaches and attacks

Cybersecurity leaders are responsible for preventing attacks, and reducing the impact if an attack does occur. However, the increasing number and sophistication of attacks in recent years make the weight of this responsibility even more stressful. Organizational leaders should shift their thinking to assuming that an attack will occur and then give cybersecurity leaders the resources to minimize the disruptions. By reducing the responsibility for eliminating attacks from cybersecurity leaders and instead focusing on reducing the damage, cybersecurity leaders feel empowered instead of burdened.

Cybersecurity is always going to be a high-stress job. But when organizations provide cybersecurity leaders with the tools and support needed, they can reduce attrition in leadership roles. When cybersecurity leaders are engaged and satisfied, their team is likely to be more productive and happy as well, which reduces overall turnover. With a well-functioning cybersecurity team, your organization can proactively reduce risk and attacks.

More from News

Can memory-safe programming languages kill 70% of security bugs?

3 min read - The Office of the National Cyber Director (ONCD) recently released a new report, “Back to the Building Blocks: A Path Toward Secure and Measurable Software." The report is one of the first major announcements from new ONCD director Harry Coker and makes a strong case for adopting memory-safe programming languages. This new focus stems from the goal of rebalancing the responsibility of cybersecurity and realigning incentives in favor of long-term cybersecurity investments. Memory-safe programming languages were also included as a…

CISA hit by hackers, key systems taken offline

3 min read - The Cybersecurity and Infrastructure Security Agency (CISA) — responsible for cybersecurity and infrastructure protection across all levels of the United States government — has been hacked. “About a month ago, CISA identified activity indicating the exploitation of vulnerabilities in Ivanti products the agency uses,” a CISA spokesperson announced. In late February, CISA had already issued a warning that cyber threat actors are exploiting previously identified vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure gateways. Ivanti Connect Secure is a…

DOJ’s crackdown: A brief look at hacker group takedowns

3 min read - The Department of Justice (DOJ) is ramping up efforts focused on disrupting cyber criminal organizations operating within and outside of United States borders. The dismantling of Volt Typhoon, a prolific hacker collective, marked a turning point in the DOJ's offensive against cyber crime syndicates. The group was notorious for its brazen cryptocurrency scams and heists. Through coordinated global law enforcement efforts, individuals linked to the organization were apprehended, assets were frozen and critical infrastructure was seized. The success of the…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today