As we reach the end of Cyber Security Awareness Month, I want to take a different approach than may be expected. Rather than raise awareness of the latest threats, security controls, or compliance frameworks, I'd like to shine a light on something equally critical but far less often discussed: the mental health of those defending our digital infrastructure.
This year alone, the UK has seen significant cyber incidents affecting major retailers including JLR, Co-op, M&S, and Harrods. What strikes me about the coverage of these incidents is a subtle but important shift. Historically, press coverage might have been quick to suggest that organisations had done something wrong. Today, there's increasing recognition that these organisations are actually victims of crime, with coverage focusing on the disruption caused to customers and operations.
There's a perspective, however, that rarely makes the headlines: those at the coalface, fighting to put things right. The security professionals who spend working life in a state of high alert, wondering where the next attack might come from. The analysts who receive the 3am phone call. The CISOs bearing the weight of protecting their organisation's crown jewels.
The data tells a troubling story
The statistics are stark. According to research published by ISACA in October 2024, 73% of European IT professionals report experiencing work-related stress or burnout. The causes are varied: 61% cite heavy workloads, 44% point to tight deadlines, and 43% highlight lack of resources. Nearly half (47%) found that difficult or unsupportive management were impacting workplace wellbeing.
The situation is particularly acute in cybersecurity roles. The CIISec State of the Profession 2020/21 report found that over half (51%) of cybersecurity professionals have experienced significant mental health impacts as a result of work-related stress. More recent data from ISSA-ESG research shows that 55% of cybersecurity professionals experience work-related stress frequently, and 28% of CISOs are considering resigning due to burnout.
The people behind the statistics
While the statistics tell a troubling story, personal accounts published recently shed light on the reality. In a recent BBC article, Tony's experience illustrates how burnout develops gradually in cybersecurity roles. Working in security awareness at a major UK ecommerce company, he found himself progressively unable to sleep or face going into the office. The passion that many bring to cybersecurity work — the sense of protecting something important — can itself become part of the problem when it drives professionals beyond sustainable limits.
His account of responding to the 2017 WannaCry ransomware attack is telling. Despite his organisation not being directly affected, the security team spent the entire weekend proactively removing every device from the network. This kind of preventative response, while potentially saving the organisation from compromise, came at a personal cost. Tony's experience wasn't dissimilar to my own; I was acting as the Head of Security for a financial company when WannaCry hit. I remember coming out of a professional exam to a barrage of missed phone calls from senior leadership; trying to rapidly assess whether we were affected, what we should do, and ultimately having to give the executive committee hourly updates on patch deployment and other mitigations. Despite being assured that this was a way of sharing the load, and the reason for this was that 'this is too big of a risk for you to manage on your own', it didn't feel that way at the time. Similar patterns are now repeating across organisations responding to recent attacks against UK retailers.
My experience of WannaCry, however, pales in significance to Tim Brown's experience of being the CISO at SolarWinds during a significant cyber-attack that was attributed to Russia. In an article for the Guardian, he discusses how he lost 25 pounds in 20 days and suffered a heart attack due to accumulated stress.
Why is cybersecurity so stressful?
Several factors contribute to the mental health challenges in cybersecurity:
Constant pressure and high stakes. Cybersecurity professionals are tasked with protecting sensitive data and critical infrastructure. As the World Health Organization defines it, burnout is an "occupational phenomenon" resulting from chronic workplace stress that has not been successfully managed. In cybersecurity, the stakes are always high, and the consequences of failure can be severe.
Alert fatigue. The repetitive nature of reviewing and assessing security alerts can lead to mental exhaustion, reducing decision-making effectiveness. This is particularly acute for younger professionals in frontline roles and security operations centres.
Fear of failure. Mistakes in cybersecurity can have severe consequences, increasing anxiety and self-doubt among professionals. There's often a "blame culture" where successes are "low visibility", leaving professionals carrying what industry experts describe as "a low level of dread".
Rapidly evolving threats. The need to stay ahead of new attack vectors demands continuous learning, adding to cognitive overload. Hackers backed by nation states are accounting for more attacks, whether to carry out espionage, steal IP, or cause disruption. As the BBC reports, "threat actors don't adhere to office hours" — and neither, increasingly, do security professionals.
The organisational challenge. While organisations often look to security professionals to address security challenges, the key to meaningful improvement frequently lies elsewhere in the organisation. Sustainable security requires support from leadership, investment in adequate resources, realistic expectations from the business, and a culture where security is everyone's responsibility. When security carries the weight of organisational security alone, it creates an unsustainable burden that contributes directly to burnout.
The need for cybersecurity-specific support
Reading about Tony and Tim openly discussing their experiences is, for me, a sign that the tide is turning and the mental health challenges in the cyber security profession are becoming better understood, but challenges remain.
Traditional Employee Assistance Programmes (EAPs) have proven insufficient for addressing the mental health crisis in cybersecurity. The October 2024 study "Even if you build it, they may not come" found that even when comprehensive mental health resources are provided, uptake remains problematically low. Generic wellness initiatives that place the onus on individuals to "fix" themselves miss the mark when system-level issues like chronic understaffing and unrealistic expectations are the root cause.
More encouragingly, in May 2025, the Chartered Institute of Information Security (CIISec) partnered with PTSD Resolution to provide trauma therapy and mental health support specifically designed for cybersecurity professionals. The programme includes trauma awareness training and access to confidential therapy through a network of 200 accredited therapists. As Colonel Tony Gauvain (Retired), Chairman of PTSD Resolution, observes:
"Executive burnout and the trauma experienced in high-pressure cybersecurity roles share many similarities with the military trauma we regularly treat. Both involve high-stakes decision-making, constant vigilance, and potential for moral injury when security breaches occur despite best efforts."
What can we do about it?
While I'm far from a mental health expert, it strikes me that there are things that can and should be done both at a leadership and managerial level and as individuals. Here are a few things that I think can make a real difference.
For your team
Normalise the conversation. Create a culture where checking in on team mates is normal and expected. Create safe spaces for team members to discuss mental health challenges without fear of stigma or career impact. There's no shame in being exhausted after you've been up all night investigating a high priority alert; or after your kid has kept you awake for that matter.
Build in recovery time. After major incidents or high-pressure periods, explicitly schedule recovery time. Don't immediately move to the next crisis. The research shows that "change fatigue" is real and can lead to overwhelming feelings of stress and burnout.
Champion work-life boundaries and challenge unrealistic expectations. Model healthy behaviour yourself. If you're sending emails at 2am, you're implicitly setting expectations for your team. Encourage people to genuinely disconnect outside of on-call periods. Sometimes the best thing you can do for your team's mental health is to push back on unrealistic demands from the business.
Make personal connections, especially with remote teams. If your team is remote or geographically dispersed, make extra effort to check in. Buy that stressed analyst a coffee. Listen to their concerns genuinely. Ask yourself: is there something in your roadmap that could improve their day-to-day experience? Look for warning signs of impending burnout (changing sleep and eating habits, becoming more withdrawn, or generally not seeming themselves).
Think outside the security operations box. Look at your security alerts critically. What are they telling you beyond just technical issues? Can you improve security culture or strengthen defensive controls to reduce the operational burden on your team? Prevention is better than cure — and it's better for wellbeing too.
Adopt an engineering mindset. There's plenty of marketing material about how agentic AI and automation are essential to keep up with threats. But can they also help deal with monotony and reduce workloads? When adopted successfully, automation isn't just about threat detection — it's about giving your people back time to focus on work that's meaningful and engaging rather than repetitive toil.
For you
Recognise the signs early. Don't wait until you're in crisis. If you're consistently struggling to sleep, feeling cynical about work, or finding it hard to disconnect, these are warning signs worth taking seriously.
It's not all on you. The individual responsibility narrative around resilience and self-care can be harmful. Yes, practice self-care where you can, but also recognise when systemic issues are the problem. You don't need to "fix" yourself when the working conditions are the issue.
Build your support network. Connect with other security professionals who understand the unique pressures of the role. Professional communities and peer support can be invaluable.
Take advantage of the CIISec/PTSD Resolution partnership. If you're a CIISec member, you now have access to specialised trauma therapy and mental health support designed specifically for cybersecurity professionals. The programme includes trauma awareness training and access to confidential therapy through a network of 200 accredited therapists. This isn't generic corporate wellness — it's targeted support that understands the unique stressors of our profession. More information is available from CIISec.
Use available support. Beyond the CIISec programme, if your organisation offers mental health support, use it. Therapy isn't a sign of weakness — it's a practical tool for maintaining your wellbeing in a high-pressure profession.
Consider your sustainability. Ask yourself honestly: is this role sustainable for me long-term? What would need to change to make it sustainable?
Sometimes the healthiest decision is to recognise when a role or organisation isn't right for you.
