April 3, 2023 By Jennifer Gregory 4 min read

There is little debate that cybersecurity jobs are very stressful. In addition, few people will argue that an organization’s growth and revenue depend on its cybersecurity team. However, recent research has shown that the stressful nature of our industry may be setting up organizations for increased cybersecurity vulnerabilities.

A third of cybersecurity leaders are planning to quit

Research from BlackFog found that almost a third (32%) of CISOs or IT cybersecurity leaders in the U.K. and the U.S. are considering leaving their current organization. Among those with plans to leave, a third are hoping to quit within the next six months. Reasons for their dissatisfaction included a lack of work-life balance (30%) and too much time spent on firefighting rather than focusing on strategic issues (27%).

The survey also found that frustration stemmed from the skills shortage and the many changes in cybersecurity. Many of the leaders (52%) reported struggling with new frameworks and models, such as zero trust. One in five leaders also found the skill level of their team to be a serious challenge. Staying on top of the rapidly changing industry was also stressful, with 54% saying keeping up with the latest on solutions was hard and 43% reporting it was difficult to keep pace with the innovations.

Improving retention for cybersecurity leaders

When a CISO or IT cybersecurity manager leaves, organizations are often more vulnerable. Additionally, the time spent hiring and training new leaders takes away from protecting the organization. Other employees on the team often leave when a leader takes on a new job, further disrupting cybersecurity.

One of the roles of a cybersecurity leader is to reduce attrition on their team. However, many organizations fail to ensure that cybersecurity leaders are engaged and satisfied with their jobs. Organizational leaders must prioritize retention at all levels of their cybersecurity team.

Here are some ways to reduce stress and increase support for CISOs and security managers.

Support work/life balance

Because cybercriminals work 24/7, so must your security team. Unfortunately, that often means that cybersecurity leaders are constantly on call, which is unhealthy and leads to burnout. Additionally, your cybersecurity leaders set the example for work/life balance for their team. If they do not show good boundaries, their team will do the same. This creates a vicious cycle: teams burn out faster, employees quit and the cybersecurity manager’s stress level rises.

Provide training and support

Many leaders find it challenging to keep up with the ever-evolving nature of cybersecurity. To that end, organizations should ensure that their cybersecurity leaders have the training they need to stay up to date. By setting a budget for training, cybersecurity leaders can stay educated on both current threats and strategies to reduce risk.

When cybersecurity leaders feel confident in their knowledge and abilities, they often feel less stressed and burned out. Organizations should also consider how they can partner with cybersecurity experts, such as IBM X-Force, to get additional support and expertise when needed to further support their cybersecurity leader.

Establish backups for cybersecurity leaders

Leaders often feel like they are always on call because that’s the reality. Therefore, it’s important to work with cybersecurity leaders to train other managers or team members to rotate being on call with the leader. Yes, they must be contacted if a breach or attack occurs. But beyond those emergencies, organizations can build backups so leaders can count on times when they are not the first line of defense.

Make PTO mandatory

Consider requiring employees to use their PTO. At the same time, encourage them to fully disconnect by providing backup for their responsibilities while they are gone and not expecting them to check in or work remotely. According to SHRM, 78% of managers agree that vacation improves employees’ focus, and 81% say time off soothes burnout. But this only happens if employees actually take their vacation and don’t work remotely. Organizational leaders should also model this by taking their own PTO, which sets a good example.

Offer flexibility

Cybersecurity leaders will often work overtime, weekends and nights, even with the best plans in place. Organizations need cybersecurity professionals to be flexible when an emergency arises. By showing them the same courtesy, you can reduce their stress and improve productivity. Offering leaders (and employees) as much flexibility as possible on when and where they get their work done can help balance the inevitable inconveniences of cybersecurity.

In addition to the ability to work remotely, give leaders the flexibility to set their own hours. By providing this flexibility to both cybersecurity leaders and team members, you reduce the risk of burnout for everyone, which can significantly reduce your overall cybersecurity risk. When the cybersecurity team works overtime with emergencies, reward them with comp time or additional PTO to help offset the stress of the event.

Foster a “when not if” approach to breaches and attacks

Cybersecurity leaders are responsible for preventing attacks, and reducing the impact if an attack does occur. However, the increasing number and sophistication of attacks in recent years make the weight of this responsibility even more stressful. Organizational leaders should shift their thinking to assuming that an attack will occur and then give cybersecurity leaders the resources to minimize the disruptions. By reducing the responsibility for eliminating attacks from cybersecurity leaders and instead focusing on reducing the damage, cybersecurity leaders feel empowered instead of burdened.

Cybersecurity is always going to be a high-stress job. But when organizations provide cybersecurity leaders with the tools and support needed, they can reduce attrition in leadership roles. When cybersecurity leaders are engaged and satisfied, their team is likely to be more productive and happy as well, which reduces overall turnover. With a well-functioning cybersecurity team, your organization can proactively reduce risk and attacks.

More from News

ITG05 operations leverage Israel-Hamas conflict lures to deliver Headlace malware

12 min read - As of December 2023, IBM X-Force has uncovered multiple lure documents that predominately feature the ongoing Israel-Hamas war to facilitate the delivery of the ITG05 exclusive Headlace backdoor. The newly discovered campaign is directed against targets based in at least 13 nations worldwide and leverages authentic documents created by academic, finance and diplomatic centers. ITG05’s infrastructure ensures only targets from a single specific country can receive the malware, indicating the highly targeted nature of the campaign. X-Force tracks ITG05 as…

650,000 cyber jobs are now vacant: How to tackle the risk

4 min read - How far is the United States behind in filing cybersecurity jobs? As per Rep. Andrew Garbarino, R-N.Y., Chairman of the HHS Cybersecurity and Infrastructure Protection Subcommittee, overseas adversaries have a workforce advantage over FBI cyber personnel of 50 to one. His statements were made during a recent subcommittee hearing titled “Growing the National Cybersecurity Talent Pipeline.” Meanwhile, recent CyberSeek data shows over 650,000 cyber jobs to fill nationwide. Given the rising rate of cyberattacks, these numbers are truly alarming. How…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today