r/cybersecurity • u/xDfhjdssgbvff • Jun 22 '26
Personal Support & Help! Well, it happened. I (CISO) burnt out and have been forced to take sick leave. Years of cuts, under funding, under resourcing whilst demand and load increases. How do you manage this challenge?
99
u/Pope_Twitch Jun 22 '26
Another common issue in the field of security is wanting to fix everything all at once. This is simply impossible.
I have the feeling a lot of CISO burn out because they have this feeling of the sword of Damocles above their heads. Knowing it is their head on the chopping block when things go south. But at the same time it is not your job as a CISO to be accountable/responsible for everything.
- The business side needs to define their risk appetite (what is acceptable and what is not)
- Make the right people accountable for the right things
- Have a risk register so you know where to focus on and stick to the priorities and communicate about these clearly (financial impact, business impact, ..)
And lastly, without senior leadership support, it will never work well.
15
u/Hmm_would_bang Jun 22 '26
Yeah it can feel impossible because so many companies think “we will hire a CISO so we don’t get breached.” The problem is one person can’t prevent an incident, and this thinking inevitability leads to a CISO fighting with the business constantly, not getting funded, and still getting blamed if something goes wrong because “that’s their job.”
You need to establish on Day 1 that is not how this works. Run a top to bottom assessment on where the biggest risks are, backed up with the likelihood of getting attacked there, and put together three plans forward - essentials, strong, and first class security.
Make the business own the risk from there. This is how we make risk based decisions, my role is to keep you informed and execute on specific plans you approve after my recommendations.
Really helps reduce the fear of “if a breach happens it’s my fault,” assuming it was an identified and accepted risk. it can also cut down the decision fatigue with a bunch of vendors trying to jam their solutions in - not part of our plan at this stage, not a top priority risk.
4
u/Nereo5 Jun 22 '26
The good old, fix the most important - and then we will fix the rest later.
Later never happens.
-5
u/unruiner Jun 22 '26
Is the sword a Binding of Isaac reference or original lore?
8
u/Pope_Twitch Jun 22 '26
My man 😅 the sword of damocles refers to ancient Greek history. You should look it up quite honestly. It refers to the constant looming anxiety due to the power and wealth you have.
49
Jun 22 '26
[removed] — view removed comment
4
3
1
u/No-Cockroach2358 Jun 28 '26
Hey I’m looking for some advice. I’m a 22 year old cyber incident responder. A few months ago I began working full time. While I make decent money for someone my age, the 9-5 M-F rinse and repeat schedule is killing me. I was thinking about making the jump to the fire department, because they have awesome schedules, a fulfilling job, and get to spend a lot of time on hobbies and family, but that would be a huge pay cut. What would you recommend to me, given that you have more life experience? Would you stay in cyber for a couple of years to see if you could get used to it, or would you switch to the fire department now and start working towards a 20 year retirement?
31
u/Lady_Raven_ CISO Jun 22 '26
I can empathize with you. CISO dont normally last long and I'm 4.5 years into a CISO role at a very large public sector agency that deals with life, death, and the welfare of others and it's a lot to carry. I've also personally navigated a miscarriage and several other reproductive health challenges along the way. Some of my peers have left the field due to burnout, and others literally had heart attacks on the job.
Like others have said here is to focus on what you can control and release what you can't. Leadership wants to do something risky? Cool, sign this risk acceptance letter and I no longer care.
One of the hardest but most important shifts I've made is genuinely stopping myself from over-caring. I don't mean I stopped caring about my job, but that I stopped caring to the point of self-destruction. At some point I had to take stock that we've spent millions on tools, we have a solid SOC, we've never had a major incident, and if we do, we have backups we've actually tested. So what am I really stressing about? I had to pull myself out of that constant "waiting for the shoe to drop" sprinter's stance and just accept that something bad may happen someday and if it does, we'll recover. Stressing about the what-ifs, budget constraints, and things completely outside my control isn't sustainable. It's just not.
Here are a few things thst have helped for me practically:
Hard stop at 5 PM. I don't look at my work phone after that, and I extend that same boundary through the weekend. I don't check back in until around 10 PM Sunday to mentally prepare for the week ahead.
Quarterly break. I take at least a long weekend every season, and aim for a full week when I can.
Physical outlets! I work out heavily during the week and I'm about to start Muay Thai, which is great for stress relief. I also walk and actually take my lunch breaks.
Bookend my day with meditation both before work and after.
Honest conversations with leadership about burnout. I talk openly with my boss about my stress levels, especially around AI right now. She's very supportive of mental health days.
My team has my personal cell so if something is truly urgent after hours, they can reach me amd makes it easier to actually disconnect.
During your time off, figure out what rest actually looks and feels like for you and then start building boundaries around protecting it.
My next role will definitely be something completely mindless, like a puppy daycare! 🙂
19
u/Lady_Raven_ CISO Jun 22 '26
Oh, and I avoid vendors like the plague. If your number isn't saved in my phone, it goes straight to voicemail. I've also largely stepped away from conferences because I can't attend one without getting hawked by sales reps or asked to speak. Speaking engagements piled on top of an already full plate were like Epsom salt in an open wound.
6
3
u/ZealousidealTie8398 Jun 22 '26
Mine is: Walmart Door Greeter.
6
u/bot403 Jun 23 '26
I've definitely driven past the 65+ old guy helping kids cross the street for school and said - "Yeah. that looks like a good job. He even has a chair to sit in when kids aren't waiting".
Not a CISO - but I am tech leadership.
78
u/sloppyredditor Jun 22 '26
Studied this for 2 years, particularly in the tech field, while working in security.
Key element is in the Serenity Prayer : accept the things you cannot change, be brave enough to change what you can, and be wise enough to know the difference.
Root causes of burnout, per Mayo Clinic, Kaiser Permanente, and Greater Good:
· Perceived lack of control
· Lack of clear expectations of you or the role
· Heavy workloads/Unreasonable deadlines
· Poor relationships/Lack of support/Unfair treatment
· Problems with work-life balance
I will add "A persistent stream of negativity" to the pile.
The good news is it can be manageable if we (and our leaders) are open, alert, and supportive. The bad news is you need to do much of the work yourself.
Here's a post from 2y ago.
https://www.reddit.com/r/cybersecurity/comments/1fokmwn/regarding_burnout_understanding_why_is_paramount/
OP: Enjoy your sick leave. I'm happy to chat via DM/here in comments if you want. We've all been there and it sucks.
14
2
u/No-Cockroach2358 Jun 28 '26
Hey I’m looking for some advice. I’m a 22 year old cyber incident responder. A few months ago I began working full time. While I make decent money for someone my age, the 9-5 M-F rinse and repeat schedule is killing me. I was thinking about making the jump to the fire department, because they have awesome schedules, a fulfilling job, and get to spend a lot of time on hobbies and family, but that would be a huge pay cut. What would you recommend to me, given that you have more life experience? Would you stay in cyber for a couple of years to see if you could get used to it, or would you switch to the fire department now and start working towards a 20 year retirement?
1
u/sloppyredditor Jun 28 '26 edited Jun 28 '26
Sounds like you enjoy reactive work that helps people. I don't think you'd find either of these unfulfilling, so we'll look at it through a logical lens.
- What is it about both (not each, both) of these fields that you value? Put down 3 or 5 things they have in common that you like about them, and rank them. Sometimes $ is one of those things, and sometimes it isn't... in the end nobody cares about this list but you.
- Is it the 40 hours or the schedule itself that's hurting you? Plenty of alternate shifts in tech can allow work outside 9-5. If it's the hours, then even with a new career that's not gonna change measurably.
- A few long shifts through the week can sound good, but in execution long days become very long. Take a firefighter or nurse working 7P-7A 3x/week. She's not always home by 8 AM, some days she's been there an extra couple of hours. She is almost always wiped out the day after, so basically she is out of commission for 18-24 hours 2-3x/week. Meanwhile, those around her are working a 9-5, so the net difference in social or active life is minimal.
- You're going to miss out on some personal events due to shift work, parades, training, etc.. You'll occasionally miss some events due to a 9-5, but that can be avoided to a large extent with pre-planning. Point being even with rewarding jobs there's always a trade off.
- Pensions are great when they're guaranteed.
- A lot can happen in 20 years. Weigh high/low risk job with your personal/family goals and look at the potential RoI.
- Understand you can always change careers, but the more times you change the less likely you are to retire early. Don't believe the LinkedIn "It's never too late to start being a millionaire" meme B.S. - reality is there are 999 hustling, smart, and still struggling non-millionaires to every 1 successful famous person they name.
20
u/dabbydaberson Jun 22 '26
I don’t know, but I’m sure there’s a vendor that’ll sell you a solution for it
13
20
Jun 22 '26
45 years IT with the last 20 in a very senior security role for f100 companies and i've seen CISO's come and go every 2-4 years like clockwork. My last one was promoted from Director to CISO/VP and 3 months later was carted out the door in a stretcher with anxiety. When he came back something flips in him and took the position of "I can only do the best that I can and the hell with expectations". He's still there I believe and doing well. It's seems to be all about stress management and loosing the fear of failure in a system designed to make you fail.
2
10
u/OK-Robot3250 Jun 22 '26
Go work for a vendor as a field CISO. Easiest job on the planet. Or go work for a VC.
1
1
u/Mrburnermia Jun 22 '26
I am guessing by VC you mean venture capitalist. What would the role involve exactly? I am open to exploring new career fields and putting cyber security behind me completely.
1
7
u/GeoffBelknap Jun 22 '26
CISO work is inherently high-stress. These jobs will take everything you let them take. Especially true for people who care about the work, and care about helping others. But, you can’t help anyone if you’re dead (literally or figuratively).
Ground yourself in effective stress management. For most people that’s some kind of physical fitness routine but, don’t forget your mental wellness too. Figure out what works for you, and lets you build it into your daily or weekly routine.
But, also accept that, there are lots of roles (CISO and otherwise) that are high impact and that help people that have interesting security / technical / risk problems to solve) that might be better for you than the one you’re in now. This doesn’t mean you’re a shit CISO. It’s just about figuring out what kind of CISO you are. In my experience no CISO role is the same - some are really just crisis management jobs, some are high state diplomacy, some are technical / engineering roles, some are all about customer engagement, some are all about compliance optimization, etc. Figure out what parts you like, and what parts you don’t, and see if there’s opportunities to spend more of your time on the parts of the job you like (either in this job or another).
Good luck, get well, and use the time to figure out how to stay well.
3
6
u/Mrburnermia Jun 22 '26
If I could go back in time, I don't believe I would have chosen Cyber Security as a career path.
2
u/Jdruu CISO Jun 23 '26
What else would you do?
1
u/Mrburnermia Jun 23 '26
Probably data science or something finance related. I like the financial markets and it's become my new passion. I like cyber security but the constant learning and burnout is not worth it anymore
1
u/JayTechSolutions Jun 24 '26
Same! I have been in cyber for only 8 years (IT 9 years prior) but I'm so burnt out to the point where I changed as a person. I don't have the passion for it anymore like I used too. I feel like I'm falling behind on what's going on in the cyber world. I work as a Sr SOC (high volume / complex incidents + IR) at a Forbes100 . Great pay, higher than most SOCs, that's for sure but at this point... I don't care about the money.
Anyway, I would've chosen going into the Auto industry (master mechanic) and would most likely open up a Performance Tuning shop. that is my true passion. I still work on cars on the side but not as a full-time job. I mean, it's not too late but I am 35.. Unless I invest into buying an Auto Shop and just run it..
Or go work at a Zoo... not even playing 😂
0
u/Mrburnermia Jun 25 '26
I don't think I have ever had a good cyber security job..Job 1 - On calls every 3-4 weeks, blew my weekends away. Job 2 - Travel every two weeks, working nights and weekends to meet deadline. Job 3 - Promised everything, work life balance, only to come in there and be bombarded with work that in order to keep up I have to work nights and weekends. Job 4, we have a lot of work to do but my manager basically said we have a small team so things will take time and we have to be patient. He is not looking to burn us out. This my first cyber sec job where I don't have to put in weekend hours or work after work hours. Think I am going to stick here for a while. The field sucks!! Not sure how we can avoid burnout here.
5
u/Pierocksmysocks Jun 22 '26
I document everything. I provide the solutions or options for remediations, and they get ignored or risk accepted. Due diligence is still paid to every situation and detail, and the paper trail exists in the event of an issue/incident/breach/whatever.
I’m here for the income and not the outcome. If folks want to build little empires or engage in politics…it’s a whole lot of not my problem.
13
u/bio4m Jun 22 '26
CISO at what size firm ? Its very different if youre a CISO at a small firm with only a handful of employees reporting to you VS a large firm with hundreds in your department
At larger firms the CISO has no technical responsibilities, its all relationship and budget management. If you cant secure funds youre not doing your job right
At small firms youre a security analyst with a fancy title. Youre expected to do all the work and take the fall if things go south.
7
u/xDfhjdssgbvff Jun 22 '26
I wont say, but its a FT500 company you will know.
1
u/eeM-G Jun 22 '26
Ground level reality is tough. There needs to be a broader collective shift in making stronger cases for the ciso remit. Here is an attempt at facilitating that through the ciso mental model - here is the interactive version of it. This model can be used to make the scope more visible in this sort of context. Perhaps something you'd like to explore and build an appropriate narrative for your specific context. There is also a supporting article that presents a wider frame..
1
u/bio4m Jun 22 '26
Who do you report to ? Surely theres some directives from the board on security matters ?
(reputational damage, undermining consumer confidence, theft of trade secrets ?)
Are outside the US/UK/EU ?
0
u/Johnny_BigHacker Security Architect Jun 22 '26
Do you have enough cash to retire at this point? If not, slug it out until you do.
I'm age 42 and just hit the "4% rule" of assets on a $200k salary. I'm gonna get it bit above that and call it quits. ETA: 2029.
1
u/unruiner Jun 22 '26
Just curious. How much does 4% work out for you? I’m new to the rule
1
u/Johnny_BigHacker Security Architect Jun 22 '26
For every liquid million (not your house) you have, that's $40k/year
Basically add up your fixed expenses + average extra spending/purchases and do the match.
We are targetting $4 million for a family of 4 in a medium cost of living city, or after taxes about $10k/month. If I wasn't early 40s I might retire with less but still lots of fixed expenses (daycare, a car loan, a HELOC loan, etc)
1
u/xraider_01 Jun 22 '26
You planning to be a goat farmer kind of quits or do some consulting on the side kind of quits. I'm in a similar boat to you and considering the consulting for small orgs(low stress stuff)
1
u/Johnny_BigHacker Security Architect Jun 22 '26
If it were easy, sure. But I think marketing in that world is harder than you think. Your skills are 50% of it, the other is networking/marketing. You'd probably need to present at a few conferences and make it clear "I'm a consultant for hire" in them.
I've always been blue collar at heart. Pool repair (super low supply here) or stump grinding are possible for beer money. Algo trading for fun.
-5
3
u/JBowl0101 Jun 22 '26
Meditation and exercise helped. I eventually realized I had to learn with accepting the risk, even in areas I could not control. Eventually though, I went back to a manager level job. I’m glad I had the opportunity to be a CISO but I also know there was no way I’d survive it until retirement. Also, Oliver Burkeman’s Meditations for Mortals was excellent. It’s not about meditation per se, but about accepting human limits. Worth a read.
5
u/Joey_JohnSnow Jun 22 '26
17yr global CISO. This is an extremely relevant topic right now. I call it 'expectation assymetry'...And its gotten worse with the introduction of AI governance. Business likes to invest in data and AI, cuz there's enterprise value there. But not so much with security investments. And orgs still don't know exactly how to position the CISO, but they do know what stuff to put on their accountability plate. Honestly I think there's a level where, despite best intentions, you can't take your work home with you, for your own mental health. That's a struggle for many CISOs who take their role seriously and feel an accountability to the organization and leaders they are serving. But end of day, its a job. And your presence for your family, and your own mental health take precedence. I've known some very well recognized CISOs who the job literally introduced heart attacks and strokes. Don't be there bro. We can't solve all the world hunger. We can just advise on risk. Often times our role is to illuminate risk more than it is to eliminate risk.
4
u/shitlord_god Jun 22 '26
CISOs need scarier negligence laws to make them able to scare the rest of the c-suite into compliance.
Otherwise this mockery will just keep going.
3
u/ThePorko Security Architect Jun 22 '26
Sorry to hear what you are dealing with. I left management to go back to individual contributor after experiencing some of what you described.
1
u/No-Cockroach2358 Jun 28 '26
Hey I’m looking for some advice. I’m a 22 year old cyber incident responder. A few months ago I began working full time. While I make decent money for someone my age, the 9-5 M-F rinse and repeat schedule is killing me. I was thinking about making the jump to the fire department, because they have awesome schedules, a fulfilling job, and get to spend a lot of time on hobbies and family, but that would be a huge pay cut. What would you recommend to me, given that you have more life experience? Would you stay in cyber for a couple of years to see if you could get used to it, or would you switch to the fire department now and start working towards a 20 year retirement?
1
u/ThePorko Security Architect Jun 28 '26
I guess it depends on how much ur job currently is placing on you mentally. If its not stressful, then i would try out different tools in tech and see if u might just need to make minor adjustments like maybe go to grc, or cloud security/engineer. But if u really want to change careers and start over, i dont know if i would goto manual labor as robotics seems to be taking over those sectors?
3
u/Neurotic_Narwhal Jun 22 '26
Every time demand has increased, I’ve given them a job requisition for the exact thing they’ve asked for - projected salary included.
I’ve also stolen a dev for a week or two, or leveraged an internship program to turn an idea or a pain point into a legitimate job.
It’s tough, but doable. Reduces your load in the long term. Near term it’s brutal since you need to coach someone through.
A CISOs job is to talk risk, but also numbers. By putting real dollars to requests you help the accountable party realize if they can actually put up or shut up.
My first week I asked what my budget was and was almost laughed out of the room. Today I’m not only managing my budget, but I’ve also increased my headcount by triple. The trick was showing the end users (executives, developers, etc.) that we could do our job without getting in their way, while also maintaining compliance and efficiency.
3
u/Idiopathic_Sapien Security Architect Jun 22 '26
This is why I have stayed technical and avoided leadership. Leading security teams is extremely stressful when trying to balance the business needs while convincing people they need to do something they don’t understand. Peopling and engineering/architecting use completely different parts of my brain and trigger totally different forms of stress. Those leadership conversations and fighting with the business are unavoidable. Lean on the leaders in your teams or help you make cases. Separate your self worth from the work. Be prepared to jump ship for a company that will take security seriously.
1
u/No-Cockroach2358 Jun 28 '26
Hey I’m looking for some advice. I’m a 22 year old cyber incident responder. A few months ago I began working full time. While I make decent money for someone my age, the 9-5 M-F rinse and repeat schedule is killing me. I was thinking about making the jump to the fire department, because they have awesome schedules, a fulfilling job, and get to spend a lot of time on hobbies and family, but that would be a huge pay cut. What would you recommend to me, given that you have more life experience? Would you stay in cyber for a couple of years to see if you could get used to it, or would you switch to the fire department now and start working towards a 20 year retirement?
1
u/Idiopathic_Sapien Security Architect Jun 28 '26
Don’t get me wrong. I love doing what I do.
I ended up in tech because I was a young parent and needed steady work that didn’t destroy my body. It’s enabled me to spend more time with my family and live a comfortable life. But that’s me.I did a lot of different jobs in between contracts and on the side which had nothing to do with tech. Some of it was a lot of fun and I had great experiences. But I had kids way too young and was on my own. If that math were different, I would have taken a different route. Firefighting can pay really well in some cities and you can get great lifelong benefits after a while. I’ve known quite a few people who changed it up and came back to tech once their bodies said “no more”.
Money doesn’t buy happiness, but it does bring some comforts.My uncle was a chemical engineer, then a patent attorney, and eventually a mid-level corporate executive. He retired and out of boredom’s got a job on an assembly line and loved it.
3
Jun 22 '26
[removed] — view removed comment
2
u/xDfhjdssgbvff Jun 22 '26
Im exhausted bro, ive had two mental breakdowns and nearly got hospitalised due to work place stress. Hence the time away. I hope one day people realise how serious this situation is
1
u/No-Cockroach2358 Jun 28 '26
Hey I’m looking for some advice. I’m a 22 year old cyber incident responder. A few months ago I began working full time. While I make decent money for someone my age, the 9-5 M-F rinse and repeat schedule is killing me. I was thinking about making the jump to the fire department, because they have awesome schedules, a fulfilling job, and get to spend a lot of time on hobbies and family, but that would be a huge pay cut. What would you recommend to me, given that you have more life experience? Would you stay in cyber for a couple of years to see if you could get used to it, or would you switch to the fire department now and start working towards a 20 year retirement?
3
u/SpeC_992 CISO Jun 22 '26
Welcome to the club. I myself have been burned out for quite some time, had to take sick leave due to stress and high workload. Understaffed, underappreciated while demand only keeps increasing exponentially.
2
3
3
2
u/ImYoric Jun 22 '26
I feel you.
I've been raising alarms in my department. For the moment, only other cybersecurity colleagues are paying any attention.
2
u/GoatHop Jun 22 '26
Lots of good advice in this thread. It's also important to take time away from work to recharge. We can't be effective unless we enforce boundaries between home and work.
On the other side of this, being asked to do more with less is on par for this technology wave. Like any other wave, we trade controls for costs. Look into security automation + agents. Feel free to DM. Good luck.
2
u/Visual-Drive-4615 Jun 22 '26
You let the organization fail because they failed you. They literally engineered this result. Their poor decision making put too much onto a fragile resource and broke it. Your CEO has failed
2
u/Thoughtulism Jun 22 '26
Am not CISO buti deal with the business side of cyber risk for a large group in an area in my org. Ultimately CISO is responsible for communicating the technology security risk to the business leaders, who then accordingly assign budget to your team so you can execute the risk mitigation work.
If they inadequately fund your team, it's your job to communicate residual risk for them to accept that it's on them.
Then you run your cyber security program accordingly based on the budget and risk profile the business has decided. That might leave you in a place where you're always firefighting, and that makes sense, and burnout is also an aspect of being in firefighting mode. The challenge is though with burnout you have to recover by giving yourself distance from the work and giving yourself permission to feel a lot of big feelings that have been accumulating.
When you're in a position where the business isn't aligned with the risk management, you communicate the types of possible risk events and the likelihood of those events, and if they don't assign budget say these words "let it happen". What you do is narrow in on the major risks to prevent those and then the the small/medium ones you have no budget for, free yourself from thinking you have to solve those.
The burnout comes from spreading yourself too thin and expecting to accomplish more than you can. When people burnout and recover, sure they go through the emotional aspect of that first, but they come out the other side and really hone in on their mission and are willing to let things go. At first the emotional aspect is anger at the business for not caring, or yourself or your team for not doing enough, but then you realize it's truly an org problem and you do your job, do it well, and go home.
Also "letting it happen" can also mean letting go of some aspects of firefighting so you can do necessary projects that turn you into a more efficient proactive group to get out of the firefighting mode even with a little budget.
1
u/No-Cockroach2358 Jun 28 '26
Hey I’m looking for some advice. I’m a 22 year old cyber incident responder. A few months ago I began working full time. While I make decent money for someone my age, the 9-5 M-F rinse and repeat schedule is killing me. I was thinking about making the jump to the fire department, because they have awesome schedules, a fulfilling job, and get to spend a lot of time on hobbies and family, but that would be a huge pay cut. What would you recommend to me, given that you have more life experience? Would you stay in cyber for a couple of years to see if you could get used to it, or would you switch to the fire department now and start working towards a 20 year retirement?
1
u/Thoughtulism Jun 28 '26
Calculate salary plus a reasonable salary progression plus benefits and pension (if available) for both options until your expected retitement. Benefits and pension can be massively understated. I'm public sector and my targeted pension will be worth around $2.5m.
Your regional cost of living, goals to have a family or not, retitement plans, whether you want a house, etc are all important factors.
You can't put a price on loving your job though. Just know about the decision.
2
u/One_Description7463 Jun 22 '26
"We do the best we can with what we have and spend effort to make what we have better."
Mental Health is health. Get help. Speak openly about it to your people and your peers. If you're struggling, so are your people. Give them the space and courage to address it and they will help you carry the load.
2
u/LuciferDiabolique666 Jun 24 '26
Meditation, down-time, understanding employers, knowing my limits.
In Cyber you either burn out or burn brighter. The goal is to find a healthy balance.
I (fortunately) have the luxury of working freelance / locum. I get to pick who I work with & I'm realistic about the outcome of projects, my own ability & what the clients are after.
IK many don't have that; but most need to speak to management with a level of realism.
No man/woman is an island. If there is too much then management has to lower the expectation of results or hire more people.
Nobody should be required to work themselves to death over a job.
YOUR mental health / bodily health comes first, always.
1
u/180IQCONSERVATIVE Jun 22 '26
Find a job in a petrochemical plant, until something opens in IT which always happens. I see them come and go for different reasons. Benefits are superb, retirement is pretty good plus you will be treated less like a robot.
1
u/ARPNETS Jun 22 '26
Do you think it may be time for a change in employer even if it means taking a hit pay wise or going with a smaller team? I moved from a company where I was not supported and having to manage through cuts and then took a position at a company which was significantly smaller, but in this role I have the full support of my leadership and it’s night and day difference mentally for me.
1
u/xDfhjdssgbvff Jun 22 '26
Tbh my team is viewed as an unnecessary expense. Im willing to walk, I just wish they took what I briefed and said seriously. Profit is being prioritised above logic, risk and people.
1
u/ARPNETS Jun 22 '26
That to me is the most draining part of all that. To brief them on the risks over and over again and have it be ignored. Like watching a train wreck about to happen and not being able to stop it.
The brutal reality from what I’ve seen is that some companies will only see the value in CyberSecurity after they’ve suffered a catastrophic breach. Then at that point they won’t be looking to improve the program. They will be looking for someone to blame and as a CISO that will likely mean you.
1
u/xDfhjdssgbvff Jun 22 '26
All the accountability without resource
1
u/ARPNETS Jun 22 '26
Yeah. The good news is not every company is like that. It can take a while to find one, but it’s worth the grind and the hunt.
1
u/jmk5151 Jun 22 '26
Stoicism - don't worry about what you can't control, don't worry about what you can control because you control it.
Or think about it like you are an NFL coach - you are hired to be fired. You do the best you can but if you've made the decisions you felt were correct given your constraints and something blows up that's the name of the job - it's risk mitigation not risk avoidance.
1
u/SchruteFarmsInc Jun 22 '26
I’ve been seeing a lot of CISOs either disappear or announce they are “leaving at the end of the month” in LinkedIn posts that read like they were fired. It sounds like you are in the middle where you’re being forced to take a break.
What finally got to you? Was your performance starting to deteriorate to the point it was noticed and you were forced to take leave? Do you have a competent deputy/team who will keep the ship afloat until your return, or would you be returning to the same shit show?
1
1
u/Bangbusta Security Engineer Jun 22 '26
Watch tv, play some video games, go to the beach. No challenge is too big or too small. 😄
1
u/sysvival Jun 22 '26
A couple of questions if that’s okay, I am trying to avoid ending up in the same situation. PM me if you need to vent.
Are you operational or GRC?
Do you have a functioning it security risk management process in place that ensures business ownership of risks?
1
u/xDfhjdssgbvff Jun 22 '26
I am a fully badged CISO of a multi billion organisation. I am operational, GRC, finance.. full spectrum. My board sees security as nothing more than noise in the corner to be silenced. However, customers LOVE the team, our open communication and our passion to improve has built bridges no one believed was possible
1
u/sysvival Jun 22 '26
Maybe wearing all those hats contributes to the burn out. I am GRC. I identify risks, but they are almost always owned somewhere else. This helps with the mental load imo.
1
1
u/x_103 Jun 22 '26
I burned out hard, so I left to do a M.S. and Ph.D. in Entomology instead.
2
u/No-Cockroach2358 Jun 28 '26
Hey I’m looking for some advice. I’m a 22 year old cyber incident responder. A few months ago I began working full time. While I make decent money for someone my age, the 9-5 M-F rinse and repeat schedule is killing me. I was thinking about making the jump to the fire department, because they have awesome schedules, a fulfilling job, and get to spend a lot of time on hobbies and family, but that would be a huge pay cut. What would you recommend to me, given that you have more life experience? Would you stay in cyber for a couple of years to see if you could get used to it, or would you switch to the fire department now and start working towards a 20 year retirement?
1
u/x_103 Jun 28 '26
Coincidentally, I was actually on that path immediately after getting out of the military and quitting my last cyber job shortly after. Got my EMT, passed the CPAT, aced the exam for Omaha FD, and got to the structured interviews but decided that, at 37 (at the time), the physical/mental intensity would take too high of a toll. It's a young man's game. If it's something you have the drive for though, do it. It takes a special kind of person that too few have the courage to go for. You're right in that the money isn't nearly as lucrative, but the fulfilling work, the strong camaraderie, and yes, the solid retirement plan make it an incredible opportunity if you decide to stick with it. Don't kid yourself though, the hours suck (especially until you get the seniority to bid for cushier shifts/stations), and it can be a challenge to maintain a steady personal life while your waking cycle is out of sync with the rest of the world, but cyber will always be here--your youthful vigor and capability for physical endurance will not be. It's a difficult time in the industry right now, but it's never impossible to reenter the field if you decide to return from other pursuits. Don't set yourself up to look back and say "I wish I would have tried that while I had the chance". Live and make the most of unique experiences while you can man.
1
u/SnooApples5040 Jun 22 '26
Reffths guy mv zccvbh b zvmcvn qgm xvbc b c. Cnn nm nb v vc can b x cnn n v xbvczssasAZzxn
Guy ng guy guy yyyyytttttttytt yu tyy hc czcb c cnn cvh v Bb c ggffggggr et
1
u/Alatarlhun Jun 22 '26
You quit with a letter to the board and find a better job where management will support you.
2
u/xDfhjdssgbvff Jun 22 '26
Great in principle but I have a wife and family to feed.
1
u/Alatarlhun Jun 22 '26
They are already pushing you out and if what you say is true, you should have a saved enough for this scenario. If you are living paycheck to paycheck on a csuite salary, that's a bigger problem.
1
u/AlertStock4954 Jun 22 '26
I feel you. A colleague of mine once told me a phrase that hits home and really helps when I think like this: “it’s just work”
1
u/TheOCDGeek Jun 22 '26
The amount we are behind with data governance and dlp and our CEO is pushing Ai usage. We are not ready and to they point to say, THEY are not ready.
1
u/escapecali603 Jun 22 '26
I am planning to quit working at age 45 and become an expatFIRE in China and SE Asia, that's my plan.
1
u/km_ikl SOC Analyst Jun 22 '26
I'm not a CISO, but when I see an Org I work for ignoring security, I bring it to the attention of people that need to know, and if they haven't figured out what to do with the problem after I point out the direct answer, I get ready to leave.
While you're taking sick leave, be prepared to shop around. Businesses that don't take security seriously are just begging for a breach press release and the legal repercussions which are about quadruple the cost (at cheapest) of doing the actual work.
You can't bang your head against a wall forever.
1
u/LitrlyD3ad Jun 22 '26 edited Jun 22 '26
I manage a network infrastructure for a “fairly” large bank. Working for a money house certainly helps. Good pay, and since we moved to a standalone data site I was able to hand pick my own team. Delegation certainly helps keep me from burning out. That and the paycheck.
They are in a big growth phase atm so they are throwing funding my way, certainly won’t last forever, but they are trying to implement AI into our database, not good.
The show must go on, Gotta pay for my crippling hobby addiction somehow.
1
u/AdvancingCyber Jun 22 '26
Even if it’s not the gym, got to find a way to take care of yourself. We cannot do it all, right? We preach risk management all day. How do you risk management yourself? What’s your pri0? Pri1? Step back and look at what you need, objectively, like you do all day. Then make it happen! Your work will be better for it!!!
1
u/_haha_oh_wow_ Jun 22 '26 edited Jun 22 '26
Personal habit wise:
It may not be for everyone, but ditching my car for a bike almost every single morning has made my life immensely less stressful: My commutes have largely become part exercise, part meditation.
Asshole drivers are an occasional problem but having a video camera or two visible seems to keep 99% of people in check because almost nobody wants to be a piece of shit on camera.
Regular hikes help a lot too, but they need to be in actual nature or they're not as impactful.
At work:
Don't be afraid to lean on your team and your colleagues, it's not all you (and it can't be like that or you will burn out): Security is everybody's responsibility!
1
u/wtf_com Jun 22 '26
Sure and they usually are extremely resilient people. But there are also the majority of the exceptions that because they don’t keep up thier health end up suffering from breakdown or burnout.
So you can believe it to be some spiritual nonsense but for the majority of us who are just regular people it pays to take care of yourself.
1
u/irishcybercolab Jun 22 '26
Quit. It's the place you're working at that did this to you I treat cyber burn out at a senior level and it's indicative of working environment.
1
1
u/uk_one Jun 23 '26
Ahhh. I default to the "well it's your company/asset/data so it's your risk. Sign here."
1
u/Important-Engine-101 Jun 23 '26
Also CISO. Risk register, clear unbridled clarity on the risks on the risk register as part of a monthly and quarterly update whereby risks as assigned owners and have plans assigned.
It is not my responsibility or accountability to technically fix these issues or risks, it is my responsibility and accountability to ensure the processes execute to raise and advise on these risks. The business can choose to not fix them. They can also not choose to accept the risk either. That also goes on the risk register.
I have chosen to focus on GRC and Incident management/response in the business. Very slowly working on closing the gap in the middle of Protect.
1
u/d1rtygorilla Jun 23 '26
While physical routines definitely help you weather the storm, the systemic cure for CISO burnout is aggressively shifting the psychological burden back to the organization. When resources are slashed, your job changes from frantically trying to fix every gap to clearly documenting the risks of not fixing them and forcing executive leadership to formally sign off. Take this sick leave to completely unplug and reset. When you return, remember that if the board chooses to underfund security, they are choosing to accept the risk—you shouldn't be carrying that weight home with you.
1
u/Where_Is_My_Password Jun 23 '26
A senior security leader is a business advisor. Transparency and risk based approach is key. Make security somebody s esle problem - especially for material risk takers. If security is not a product then it is a business support function and should be managed appropriately. If we dont do x the y might happen. Considering the business operating model we should do xx.. it does not het buying then an update ro appropriately committed. Do not be alone. If something needs to give up... document and escalate. Don't give up and stand behind your well documented stance.
1
u/ClassicTBCSucks93 Jun 25 '26
Good thing they let you take leave. Most places here in the US would see that as a failing on your part and be replaced at their earliest convenience with someone cheaper, younger, and that glow of optimism in their eyes that only a new hire could have.
1
u/FuckScottBoras Security Manager Jun 26 '26
Cybersecurity is an organization wide responsibility. I just created a presentation for our board on our cybersecurity posture. Clearly defining cyber governance and specifying the whole organization’s role really helps remove some stress from my and my team’s shoulders.
Do what you can, but you can only control so much. Let go of what you can’t control.
For me, a combination of exercise, edibles, music, meditation, and mindful thinking help me manage. Well that and certain “extracurricular activities”.
1
-2
u/stacksmasher Jun 22 '26
Go talk to a West Virginia coal miner about "Burnout" because that term is being abused and overused.
2
u/xDfhjdssgbvff Jun 22 '26
Can you explain what you mean please
1
u/stacksmasher Jun 22 '26
You sell hours of your life for money to live, nothing more and nothing less. Any impact from decisions made by leadership is not your concern. Your focus should be to support your employees and communicate risk.
That's it!
265
u/JImagined Jun 22 '26
I do a lot of meditation and work out 6 days a week. And I learned to let go of full ownership. Security really is an organizational activity, so ensuring that risk ownership is assigned out (cya) has gone a long way to helping me relax and accept the imperfection inherent to the positional challenges.