Our digital defense is crumbling: why our CISOs are burning out
Article content
When people outside our field think of cybersecurity, they mostly picture technology: firewalls, encryption, phishing emails and anonymous hackers battering digital walls. That picture is partly true, but it ignores one crucial factor: the human being. And this is not about the average employee who occasionally has to sit through mandatory e-learning, but about the professionals who stand on the front line every day: CISOs, security officers, SOC analysts, incident responders and ethical hackers.
Behind the scenes, a quiet crisis is playing out: prolonged stress, constant mental strain and rising burnout figures. The people who protect our most important data and systems are becoming exhausted at a rapid pace, and that is not a simple HR issue but a strategic risk for organizations and society alike. When these defenders are too tired to stay sharp, the chance of mistakes increases and our digital defense lines become thinner, directly.
This crisis is not a theoretical risk, it is something felt daily in teams and organizations. There is a lot of discussion about this on LinkedIn, and I regularly get asked whether things are really as bad as they seem, specifically for the CISO role. That is why I decided to dive into it and base this piece on (scientific) publications, articles and podcasts. Not a purely academic article then, but a CISO's perspective from almost 25 years of experience in cybersecurity, in which I have repeatedly observed this dynamic: in my own teams, with colleagues, and in the organizations I advise.
The five developments from recent research and from practice that I want to highlight here show how large the problem has become. Together they make clear how personal pressure, organizational friction and weak strategy are, step by step, undermining our digital resilience.
1. Cybersecurity professionals are under extreme pressure
The perception of cybersecurity as a regular office job is a dangerous misconception. While the work may not seem physically demanding, the psychological reality resembles a constant state of readiness in a digital conflict zone. The pressure is relentless, the threat omnipresent, and the stakes unimaginably high. Research strikingly compares the working environment of a cybersecurity expert to a "war situation".[1] Professionals operate under constant high tension, knowing that a single moment of inattention or a slow response can have major consequences for their organization. This constant pressure can lead to exhaustion.
I have unfortunately seen this happen multiple times in my own environment, and research shows this is the rule, not the exception. Studies show that burnout levels in our sector sometimes exceed those of frontline healthcare workers, such as emergency room doctors.[2] Emotional exhaustion in particular, a core component of burnout, is a common and draining aspect of the work. This emotional exhaustion is not only damaging for the individual, it also forms a direct threat because it reduces cognitive functions such as attention and decision-making, precisely the functions that are crucial for effective cyber resilience.
2. The biggest threat is not a hacker, but a burnt-out CISO
An organization's security is directly linked to the wellbeing of its leadership and management. A Chief Information Security Officer (CISO) who is mentally balancing on the edge is a strategic risk no company can afford. The ongoing stress and the heavy responsibility create an untenable situation, with potentially disastrous consequences for both the individual and the organization.
The professional toll of this crisis is visible in the alarming statistics associated with the CISO role:
- The average tenure of a CISO at a large enterprise is 18 to 26 months, compared with almost five years for the rest of the board. That points to a high level of turnover and instability for the organization.[9]
- As many as 90% of CISOs are willing to accept a pay cut in exchange for less stress. On average they would give up $9,642 (about €8,200) per year for it.[3]
- In the Netherlands, 56% of CISOs report experiencing or witnessing burnout in the past year, a clear rise from 43% the year before.[4]
These figures are compounded by a sense of role ambiguity and a lack of real authority, something that comes up regularly in CISO-only sessions. Many CISOs feel responsible without having the mandate to make fundamental changes. One CISO put this frustration into words: "You are excluded from the rest of the organization. Ambiguity in what is being asked of you and what is being provided. That's hard, the C is not real, you're not a chief."[5]
This deep frustration often originates in the dynamic between the security department (the CISO) and the boardroom, where this gap ultimately weakens the organization's defense further. As a CISO you feel the responsibility every day, but to actually act on it, you depend on leadership or the board. Plenty of CISOs, out of sheer frustration with this process, throw in the towel. The CISOs who keep fighting the fight, time and again, risk burning out.
3. The gap with leadership makes the defense more vulnerable
Effective cybersecurity is not an isolated IT function but a strategic pillar that must be anchored at the top of the organization. When the CISO and leadership or the board are not aligned, a dangerous vulnerability emerges. This mismatch weakens the organization and increases the pressure on teams. This is also backed up by worrying data:
- While 68% of board members primarily see cybersecurity as part of the IT budget, 60% simultaneously worry that threats are more advanced than their defenses.[6] This points to a discrepancy between the perception of the problem and the allocation of strategic resources.
- Alignment between the board and Dutch CISOs has dropped dramatically, from a peak of 80% in 2024 to just 59% in 2025.[4] Perhaps a warning sign of the widening gap between leadership and the CISO.
- As a direct result, 45% of Dutch CISOs feel they lack the resources to achieve their goals.[4]
This is gradually becoming a vicious circle: leadership sees security as a cost center, so resources stay limited. The CISO cannot adequately respond to growing threats, which leads to increased stress and a higher chance of a successful attack. This gap culminates in the most tangible risk: data loss, with 92% of CISOs who experienced data loss indicating that departing employees played a role, up from 73% a year earlier.[4] A direct consequence of a culture that burns out its most important defenders. This organizational friction, however, also has a deeply personal, emotional impact when an attack actually occurs, while leadership was aware of the risks and of the CISO's requests for more resources.
When an incident occurs under these circumstances, it is bitter that this CISO may have black-and-white proof that his or her requests for more resources were repeatedly denied, but what is that worth? Although it's a large field, it can sometimes feel like a small village where everyone knows which CISO was in charge at organization X when things went wrong. Not just a stain on the organization, but on the individual too, even if every process was followed to increase resilience.
4. A cyberattack leaves deep emotional scars
The aftermath of a serious cyber incident is often analyzed in technical terms: data loss, downtime, financial damage. What is regularly overlooked, though, is the deep psychological impact on the professionals who were in the middle of the crisis. Surviving an attack is a traumatic experience that can leave long-lasting emotional scars.
The emotional journey of a professional during an attack begins with "disbelief and despair", followed by a deeply personal feeling of "guilt and self-doubt".[1] Psychologically, though, it is notable that feelings of "purposefulness and self-efficacy" are also reported in the middle of this crisis. This is a classic stress response: the adrenaline and the focus on a concrete mission can temporarily mask the underlying psychological damage. While this is effective for incident response in the short term, it often accelerates emotional exhaustion in the long run.
When the adrenaline fades, the scars remain. The reported "increased cynicism" is more than a mood shift, it is a symptom of professional disillusionment.[1] This cynicism, combined with "fear of recurrence and thoughts of a career switch", can lead to burnout and loss of expertise. These human costs often remain invisible, and the solution does not call for more technology, but for a people-focused approach.
From experience, I recognize both the positive and negative sides of a crisis. An almost euphoric feeling during and after the incident, if it ended reasonably well, but afterward comes a process that is not just about the value of good preparation, teamwork and the professionalism of the security and IT teams, but also about how it got this far, whether it could have been prevented, and the personal question: "did I miss something or do something wrong?"
5. The solution is not more technology, but better leadership
In the race to stay ahead of cyber threats, the automatic reflex is often to invest in the latest technological solutions. While I believe technology is essential for strong digital resilience, it does not address the core of the burnout crisis. The most effective strategy to strengthen the resilience of security teams lies in human and organizational dynamics, with strong, supportive leadership at the center.
Research shows that certain leadership and organizational factors can significantly ease stress during a crisis:
- Good leadership and clear internal communication are crucial for maintaining situational awareness and focus, allowing teams to keep functioning effectively under pressure.[1]
- Leaders who act as "gatekeepers" for their incident response teams by shielding them from unnecessary questions from media or other departments significantly ease stress and allow the team to focus on the resolution.[1]
- A proactive leader who encourages open communication and psychological safety creates an environment where team members feel supported, which counteracts the risk of burnout.[7]
- Organizational interventions, such as providing social support and adjusting policy to manage workload, have proven significantly more effective than measures aimed solely at the individual, such as stress management training.[8]
Investing in leadership development and a supportive culture is not a "soft skill" or a luxury, it should be part of the security strategy. A team that is mentally healthy and resilient forms the strongest defense against any threat, and I can vouch for that.
Conclusion: it is time to defend our defenders
The paradox of modern cybersecurity: we desperately need human expertise to protect our digital world, yet we fail to protect the very professionals in question. We have built a system that systematically exhausts, isolates and burns them out. The quiet crisis of stress and burnout is no longer a side issue, it is a direct threat to our collective security.
Protecting our data and systems starts with protecting the people who guard our digital assets. Now that we see the human cost of our digital defense, the real question is not whether we can afford a data breach or theft, but whether we can afford to ignore the wellbeing of our defenders. This calls for an honest and open conversation. What steps is your organization taking to keep security professionals resilient?
Four steps a board can take this month
- Put threats and measures on the board agenda at least four times a year, as a standing item, not only when things go wrong.
- Document the mandate. Describe which decisions the CISO makes independently and which go to the board.
- Build the relationship before the crisis. Whoever still needs an introduction round during an incident is already too late. Whoever already knows each other has the right people at the table within an hour instead of after a day.
- Ask your CISO not only what is needed, but also what was dropped because it did not fit the budget or timeline. That second list is your real risk profile.
The Dutch Cyber Security Act (Cyberbeveiligingswet) is shifting the balance. Since 15 August 2026, the board itself must approve the duty-of-care measures, oversee their implementation, and have enough knowledge to assess risks and security measures. What that law further requires is explained in NIS2 explained. Want to discuss this further, with your board or with Jeroen personally? We help boards turn technical risk into decisions through Cyber Security Executive Services, and we support CISOs through security advisory and CISO-as-a-Service.
Sources
- Virtanen, T. (2024). Psychological Effects of Continuity Threatening Cyber Incidents. European Conference on Cyber Warfare and Security.
- Reeves, A., Pattinson, M., & Butavicius, M. (2023). Is Your CISO Burnt Out yet? Examining Demographic Differences in Workplace Burnout Amongst Cyber Security Professionals. Human Aspects of Information Security and Assurance.
- Leonhard, W. (2020). Security Now! Transcript of Episode #754. Gibson Research Corporation, referencing the Nominet study from 2019/2020.
- Proofpoint (2025). Voice of the CISO Report 2025.
- Piazza, A., Vasudevan, S., & Carr, M. (2022). Am I hired as a Firefighter? Exploring the role ambiguity and board's engagements on job stress and perceived organizational support of CISOs.
- Ernst & Young LLP (2025). 2025 EY Cybersecurity Study: Bridging the C-suite disconnect.
- ASIS International. Tackling Burnout in the High-Stakes World of Security.
- CDC. Module 8 Outline: Organizational approaches to reducing burnout risk.
- Cybersecurity Ventures & Sophos (2026). 2026 CISO Report.
About the author
Jeroen Schipper
Chief Security Advisor at DEFION. Advises boards and CISOs on cyber resilience, security strategy and the human side of digital defense, drawing on nearly 25 years of experience in the field.
This article originally appeared in shortened form on LinkedIn in December 2025.
Related services
Want to strengthen security leadership and board alignment?
DEFION helps boards and CISOs align responsibility and mandate before an incident exposes that gap the hard way.
Cyber Security Executive Services
Translate technical risk into board decisions and a clear mandate
CISO as a Service
Experienced security leadership without making the organization dependent on one person
NIS2 explained
What Europe's cybersecurity law concretely requires from board members
Security Advisory
Strategic advice on security governance and organizational design
®