TechForge

December 18, 2024

  • Cybersecurity professionals’ mental health affecting personal lives.
  • Responsibility for keeping the wheels on not appreciated.
  • Quantifying safety record as ‘nothing happened recently’ is inappropriate.

Research papers commissioned by companies with a vested commercial interest in the findings rarely present a balanced picture. Thus is the case of a survey results PDF [terrible stock-photography warning] published by Green Raven, a cybersecurity reseller and consultant, with survey statistics showing a feeling among cybersecurity professionals of despair, with negative thoughts and work-related stress carrying through into personnel’s home lives.

Although the survey commissioning company’s motives are in some part a tacit sales pitch, there are serious elements at play that deserve attention.

It may be true that a more strategic approach to cybersecurity would be beneficial (Green Raven offers consultative services on just such a thing) and that organisations’ investment in cybersecurity isn’t enough (Green Raven will be happy to oblige on that score). The presence of the dread acronym AI may be more contentious for some, although the paper devotes only page 10 to the subject, if readers of a cynical bent are pushed for time.

Most cybersecurity professionals’ mental health is affected by work. The chosen demographic to receive a questionnaire comprised cybersec management and team leaders; people who held responsible if the organisation’s data gets ransomed, exfiltrated or otherwise misappropriated.

That’s not to imply that the cybersecurity professional starting their career at the bottom of the career ladder feels none of the pressure. The survey’s findings say nearly 75% of team managers would take a serious incident as a personal failure, a figure that might be lower further down the food chain, but not so low, in all likelihood, even at career-starter level.

And the UK focus of the survey also has little relevance when considering the issues: The specifics of the UK cybersecurity ‘scene’ are pretty much applicable anywhere. The same applies to the size of the organisations quizzed – more than 1,000 employees – other than with regard to greater managerial responsibility for large teams and commensurate budgets.

Cybersecurity professionals’ mental health statistics

According to the research, 70% of respondents felt ‘negative emotions’ due to the increase in cyber losses seen in the wild. 59% feel a ‘sense of inevitability’ to their organisation’s cybersecurity failure, which is arguably a fairly healthy mindset to have in the sector.

Nearly 70% say they are under extreme pressure from senior management to demonstrate the need for their cybersecurity budget demands for the coming year. Over half don’t get the budget they feel they need, despite 90% of organisations seeing cybersecurity budget increases.

Fighting around at the boardroom table around budget allocation time is something that every department has to do, of course. But the dilemma for cybersecurity is exacerbated by the bundling of inevitability (“we will be hacked”) and budget requirements (“if we had more money, it may be less likely”). It’s the quantification of “less likely” that’s practically impossible.

So for the rest of the board, budgetary allocation for cybersecurity is judged on variables that are almost as random as the incidence of cyber attack: Does the board feel confident in the performance of the CISO? On what basis is that confidence formed? Are opinions swayed by personality clashes or attitudes to technology in general in different parts of the business? And lest we forget, lack of security incident does not necessarily prove cybersecurity effectiveness.

Responsibility

The fact that the stresses of a cybersecurity role are bleeding over into personal lives and negatively affecting mental health is unacceptable. The scale of responsibility (not the sense of responsibility) put on security staff is outrageous. To use a clumsy analogy, cybersecurity staff are like car mechanics – they try to make sure the machinery doesn’t present a danger to drivers and other road users. But there is at least a chance they’re not responsible if a driver crashes into a wall, and the cybersecurity leader is most definitely not to blame for others’ dangerous driving styles.

Sometimes, drivers need to retake their licence tests – usually after a catastrophic incident. But rarely do organisations pay more than lip service to staff cybersecurity training, and it’s not often that staff see more than a guide to ‘spotting a phishing email’ and the message ‘use unique passwords.’

It’s also a rare company that equips its staff properly to ensure their safety. To take a single example: It seems acceptable today that companies insist staff are always available to work on, or are contactable via, their personal smartphone. But suggesting every member of staff is given a locked-down company phone to securely access work resources is met with rolled eyes around the board room. ‘It will be unpopular with staff who will have to carry two phones,’ is a standard retort, as are the obvious objections on the basis of cost.

If companies are serious about cybersecurity, they need to commit proper resources. In many instances, that’s not necessarily a sum of currency given to a well-intentioned cybersecurity consultant. It means changing how people work with technology, every day. Giving new hires a company laptop and ensuring they have Outlook on their personal phone is the equivalent of letting them drive off in a car that could be just a mile or two from a broken axle on the motorway.

Author

  • Joe Green

    Joe Green is a writer based in Bristol, UK. He acquired his first Mac and dial-up modem in 1992 and has worked in the tech industry since 2000. He writes and podcasts, specialising in open-source, networking, cybersecurity, software development and online privacy.

    View all posts

About the Author

Joe Green

Joe Green is a writer based in Bristol, UK. He acquired his first Mac and dial-up modem in 1992 and has worked in the tech industry since 2000. He writes and podcasts, specialising in open-source, networking, cybersecurity, software development and online privacy.

Related

August 11, 2026

August 10, 2026

August 5, 2026

July 30, 2026

Join our Community

Subscribe now to get all our premium content and latest tech news delivered straight to your inbox

Popular

12345 view(s)
11326 view(s)
7643 view(s)
6152 view(s)

Subscribe

All our premium content and latest tech news delivered straight to your inbox

This field is for validation purposes and should be left unchanged.
Name(Required)