April 3, 2023 By Jennifer Gregory 4 min read

There is little debate that cybersecurity jobs are very stressful. In addition, few people will argue that an organization’s growth and revenue depend on its cybersecurity team. However, recent research has shown that the stressful nature of our industry may be setting up organizations for increased cybersecurity vulnerabilities.

A third of cybersecurity leaders are planning to quit

Research from BlackFog found that almost a third (32%) of CISOs or IT cybersecurity leaders in the U.K. and the U.S. are considering leaving their current organization. Among those with plans to leave, a third are hoping to quit within the next six months. Reasons for their dissatisfaction included a lack of work-life balance (30%) and too much time spent on firefighting rather than focusing on strategic issues (27%).

The survey also found that frustration stemmed from the skills shortage and the many changes in cybersecurity. Many of the leaders (52%) reported struggling with new frameworks and models, such as zero trust. One in five leaders also found the skill level of their team to be a serious challenge. Staying on top of the rapidly changing industry was also stressful, with 54% saying keeping up with the latest on solutions was hard and 43% reporting it was difficult to keep pace with the innovations.

Improving retention for cybersecurity leaders

When a CISO or IT cybersecurity manager leaves, organizations are often more vulnerable. Additionally, the time spent hiring and training new leaders takes away from protecting the organization. Other employees on the team often leave when a leader takes on a new job, further disrupting cybersecurity.

One of the roles of a cybersecurity leader is to reduce attrition on their team. However, many organizations fail to ensure that cybersecurity leaders are engaged and satisfied with their jobs. Organizational leaders must prioritize retention at all levels of their cybersecurity team.

Here are some ways to reduce stress and increase support for CISOs and security managers.

Support work/life balance

Because cybercriminals work 24/7, so must your security team. Unfortunately, that often means that cybersecurity leaders are constantly on call, which is unhealthy and leads to burnout. Additionally, your cybersecurity leaders set the example for work/life balance for their team. If they do not show good boundaries, their team will do the same. This creates a vicious cycle: teams burn out faster, employees quit and the cybersecurity manager’s stress level rises.

Provide training and support

Many leaders find it challenging to keep up with the ever-evolving nature of cybersecurity. To that end, organizations should ensure that their cybersecurity leaders have the training they need to stay up to date. By setting a budget for training, cybersecurity leaders can stay educated on both current threats and strategies to reduce risk.

When cybersecurity leaders feel confident in their knowledge and abilities, they often feel less stressed and burned out. Organizations should also consider how they can partner with cybersecurity experts, such as IBM X-Force, to get additional support and expertise when needed to further support their cybersecurity leader.

Establish backups for cybersecurity leaders

Leaders often feel like they are always on call because that’s the reality. Therefore, it’s important to work with cybersecurity leaders to train other managers or team members to rotate being on call with the leader. Yes, they must be contacted if a breach or attack occurs. But beyond those emergencies, organizations can build backups so leaders can count on times when they are not the first line of defense.

Make PTO mandatory

Consider requiring employees to use their PTO. At the same time, encourage them to fully disconnect by providing backup for their responsibilities while they are gone and not expecting them to check in or work remotely. According to SHRM, 78% of managers agree that vacation improves employees’ focus, and 81% say time off soothes burnout. But this only happens if employees actually take their vacation and don’t work remotely. Organizational leaders should also model this by taking their own PTO, which sets a good example.

Offer flexibility

Cybersecurity leaders will often work overtime, weekends and nights, even with the best plans in place. Organizations need cybersecurity professionals to be flexible when an emergency arises. By showing them the same courtesy, you can reduce their stress and improve productivity. Offering leaders (and employees) as much flexibility as possible on when and where they get their work done can help balance the inevitable inconveniences of cybersecurity.

In addition to the ability to work remotely, give leaders the flexibility to set their own hours. By providing this flexibility to both cybersecurity leaders and team members, you reduce the risk of burnout for everyone, which can significantly reduce your overall cybersecurity risk. When the cybersecurity team works overtime with emergencies, reward them with comp time or additional PTO to help offset the stress of the event.

Foster a “when not if” approach to breaches and attacks

Cybersecurity leaders are responsible for preventing attacks, and reducing the impact if an attack does occur. However, the increasing number and sophistication of attacks in recent years make the weight of this responsibility even more stressful. Organizational leaders should shift their thinking to assuming that an attack will occur and then give cybersecurity leaders the resources to minimize the disruptions. By reducing the responsibility for eliminating attacks from cybersecurity leaders and instead focusing on reducing the damage, cybersecurity leaders feel empowered instead of burdened.

Cybersecurity is always going to be a high-stress job. But when organizations provide cybersecurity leaders with the tools and support needed, they can reduce attrition in leadership roles. When cybersecurity leaders are engaged and satisfied, their team is likely to be more productive and happy as well, which reduces overall turnover. With a well-functioning cybersecurity team, your organization can proactively reduce risk and attacks.

More from News

Recent CrowdStrike outage: What you should know

3 min read - On Friday, July 19, 2024, nearly 8.5 million Microsoft devices were affected by a faulty system update, causing a major outage of businesses and services worldwide. This equates to nearly 1% of all Microsoft systems globally and has led to significant disruptions to airlines, police departments, banks, hospitals, emergency call centers and hundreds of thousands of other private and public businesses. What caused this outage in Microsoft systems? The global outage of specific Microsoft-enabled systems and servers was isolated to…

White House mandates stricter cybersecurity for R&D institutions

2 min read - Federal cyber regulation is edging further into research and development (R&D) and higher education. A recent memo from the Office of Science and Technology Policy (OSTP) states that certain covered institutions will be required to implement cybersecurity programs for R&D security. These mandates will also apply to institutions of higher education that support R&D. Beyond strengthening the overall U.S. security posture, this move is also in direct response to growing threats posed by the People's Republic of China (PRC), as…

New memo reveals Biden’s cybersecurity priorities through fiscal year 2026

2 min read - On July 10, 2024, the White House released a new memo regarding the Biden administration’s cybersecurity investment priorities, initially proposed in July 2022. This new memorandum now marks the third time the Office of the National Cyber Director (ONCD), headed by Harry Coker, has released updated priorities and outlined procedures regarding the five core pillars of the National Cybersecurity Strategy Implementation Plan (NCSIP), now relevant through fiscal year 2026. Key highlights from the FY26 memorandum In the latest annual version…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today