Cybercriminals secretly plan to run down entire security teams, here's what businesses can do

cybersecurity
(Image credit: Future)

After a year of high-profile cyberattacks, including ransomware campaigns on organizations such as JBS, Colonial Pipeline, Kaseya and more, the need for organizations to prioritize cybersecurity holds more weight than ever before. 

However, what often gets lost in conversations about the rise of sophisticated attacks is the human element and acknowledging the defenders who have been working tirelessly to protect organizations from these attacks.

About the author

Rick McElroy is the Principal Cybersecurity Strategist at VMware

Being a part of the security community for more than two decades, it’s clear that the pressure on cybersecurity professionals is increasing in parallel with the threats they’re defending against. 

This can and has led to burnout, especially as we continue to operate in remote and understaffed environments.

Defenders under stress

A recent report found that 51% of cybersecurity professionals are feeling symptoms of extreme stress or burnout, and of that group, 65% have considered leaving their jobs because of it.

In August, the Biden Administration also highlighted that there are 500,000 open cybersecurity roles across the country.

This talent gap is putting a strain on defenders and leaving most spread thin and their organizations vulnerable to destructive cyberattacks.

Opportunity in disguise

CISOs [Chief Information Security Officer] and business leaders have an opportunity to learn from these attacks and take advantage of this moment in time to educate employees and stakeholders about the importance of cybersecurity. 

But they should also leverage this opportunity to acknowledge the burnout facing security professionals and ensure these defenders are supported and empowered.

As part of my role, I have many conversations with CISOs and security leaders about the challenges they’re currently facing. 

Many are concerned about how best to build resilient security teams that can manage the high stress that a career in cybersecurity brings.

Tackling burnout

Here are four best practices for CISOs and security leaders working to break the burnout cycle:

1. Spot burnout from the start

It is important to spot the early signs of burnout. There are telltale warning signs like disengagement and cynicism that can happen before outright exhaustion sets in. 

Create an open environment where employees can feel comfortable expressing that they are experiencing the symptoms of burnout without it being seen as a fault or weakness.

2. Empower your team with the right tech

Encourage and train your teams to use efficient processes and technology. There is too much to do in a day to waste any time on inefficiencies. 

At the same time, a company can invest all the money in the world on automation technology and tools but without proper training, it can create unnecessary complexity and confusion. 

Arming teams with the proper tools and training will allow for them to effectively do their jobs, leading to a decrease in stress.

3. Encourage self-care

From my experience, cybersecurity professionals are extremely driven, tactical people. I find that often, they’re so engrossed in what their work needs from them that they forget what they need from themselves. 

As a leader, it’s important to urge your teams to take mental health days and PTO. Unplugging is crucial for people to reset and recharge, coming back feeling motivated and ready. 

Another idea would be to offer non-standard working hours based on the needs of your employees. Feeling respected and valued enough to create schedules that work for their lives leaves employees feeling in control and able to balance more.

4. Build anti-burnout activities into the day-to-day

Zoom fatigue and too much screen time can leave people feeling drained at the end of the day. 

Switch your team’s meetings to walking meetings, provide weekly mindfulness training, and encourage call-free Fridays. 

Remember as the leader, you should practice what you preach here and lead by example with these suggestions.

It’s time for security leaders to take a step back and not only examine their organization’s security posture but also take inventory of whether employees are feeling supported and empowered. 

The future of cybersecurity depends on it.

Rick McElroy
Principal Cybersecurity Strategist at VMware
Read more
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Don’t let holidays be your cybersecurity downfall
Abstract image of cyber security in action.
It’s time to catch up with cyber attackers
A digital representation of a lock
Exploits on the rise: How defenders can combat sophisticated threat actors
Hack The Box crisis simulation event
“Everyone will experience a hack” - how incident response can protect your organization
woman sit on couch near laptop take break reduce stress do yoga meditation exercise to calm down self control get rid of negative emotions, bad e-mail, difficult task, problems at work concept
IT industry workers hit badly by burnout, stress - but there's still potential for success
An abstract image of digital security.
Tackling the UK's cybersecurity skills shortage
Latest in Security
A TV remote pointing at YouTube logo
YouTube warns of phishing video using its CEO as bait
China
Microsoft says Chinese Silk Typhoon hackers are targeting cloud and IT apps to steal business data
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
BadBox malware hit after infecting over 500,000 Android devices
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
Latest in News
An Nvidia GeForce RTX 5080 resting on an RTX 5090 on a gray crafting mat.
Corsair tells us only one of its prebuilt PCs with an RTX 5000 GPU has suffered from chip-level fault, suggesting it’s as rare as Nvidia claimed
Fujfilm GFX 50R
First Fujifilm GFX100RF images leaked in build-up to expected reveal – here’s what they tell us about the unique premium compact camera
Samsung Galaxy Z Flip 6 in blue
The Samsung Galaxy Z Flip 7 could have a Motorola Razr-style full-sized cover screen – and I think it’s about time
Spotify logo on a mobile device
Had Spotify problems recently? It's clamped down on Premium APK 'modded' apps – here's what's happening
An AMD Radeon RX 9070 XT made by Sapphire on a table with its retail packaging
Last-minute AMD RX 9070 XT stock rumors are making me hopeful for a much better launch than Nvidia’s RTX 5000 GPUs – with just one snag
eSIM
Global eSIM shipment volume surpasses half a billion units as demand keeps on growing