Cybersecurity by its very nature is a high-stakes job, a constant, ever-accelerating battle against the “bad guys.”
And while it may be perceived from the outside as a sort of “Dr. Strangelove” environment — intense, fiery sessions in tactical rooms going over battle scenarios — in reality, many cybersecurity professionals describe their roles with stark adjectives.
Tedious, repetitive, mindless, monotonous, overwhelming, inundating — even demoralizing.
[ Related: The great CISO resignation: Why security leaders are quitting in drovesCybersecurity professionals at all levels are dealing with record levels of stress and burnout, and experts say the industry is in a full-blown mental health crisis.
“These protectors of society are in such a state of fragility,” said Peter Coroneos, founder of Cybermindz, a nonprofit dedicated to improving cybersecurity professionals’ mental health and well-being.
Speaking at a roundtable with security leaders from Devo Technology and AT&T at this year’s Black Hat, Coroneos emphasized: “We’re deeply concerned about the impact not only on a human personal level, but obviously on a societal level. Something needs to be done.”
Alert fatigue, intense pressureResearch by the SANS Institute found that 55% of SOC analysts have contemplated leaving their positions due to the immense pressure of their work.
Notably, alert fatigue is a serious issue: According to Orca Security, 59% of SOC teams receive more than 500 alerts a day, and more than half of security teams spend upwards of 20% of their time deciding which alerts should be dealt with first. And the majority agree that alert fatigue has contributed to turnover, caused internal friction and resulted in critical alerts being missed on a daily and weekly basis.
“There’s a repetitive nature of doing the same tasks, there's always new stuff coming in,” said Chaz Lever, senior director of security research at Devo. “It’s really tough to do that same thing over and over again. It contributes to this kind of ‘I can't do this thing anymore’ feeling.”
Added to that is the “intense pressure to get it right,” said Joshua Copeland, security director of cyber at AT&T.
Because, he pointed out, it’s not just getting one task right — there are second and third order impacts. If you miss one alert and it leads to an incident, now you’ve impacted hundreds, thousands, maybe 10s of thousands of people.
Dealing with that pressure while also facing an onslaught of alerts “creates a kind of a mental conflict that just drains you horribly,” said Copeland.
Why CISOs are fleeing firstThat stress goes all the way up the chain: BlackFog found that close to one-third (32%) of CISOs and cybersecurity leaders in the U.S. and UK were considering quitting, citing a lack of work-life balance and too much time spent “firefighting” rather than strategizing, among other factors.
Coroneos pointed out that, “generally we’re losing the CISOs first.”
When a security team is “decapitated” due to a resignation or firing, enterprises are left scrambling to find a replacement, and “that just starts to build this downward spiral of increasing pressure on teams,” he said.
He lamented that often at the board level there is “no comprehension” that this is even an issue, “nor is there necessarily concern.”
In cases where there is awareness and action, it’s often “very superficial,” he said. Mental health intervention is often a one-and-done ‘let’s have a mental health day, see you next year,’ and programs are often not customized, sustainable or measurable.
The disconnect between neuroscience and threat detectionSo, what is a potential long-term solution?
Coroneos pointed to the study of neuroscience. Through evolution, the brain became optimized for threat detection — but just the physical kind. Brains are “low optimized for virtual threats, and certainly not optimized for a 24/7 attack cycle.”
When looked at in macro evolutionary terms, burnout is “a very predictable outcome of putting your brain putting neural infrastructures into an environment that it was never devised for.”
This leads to issues with hyper-vigilance, because “the way the brain responds to a constant attack cycle, is it thinks everything is a danger,” he said.
Many CISOs and SOC analysts tell him they have trouble sleeping because they go home and “there's all this stuff spinning in their subconscious.”
“They'll wake up in the middle of the night: ‘Did I remember to patch that system or alert the enforcer?’”
Many also report workplace uncertainty; increased workload and pressure to succeed; challenges in managing and balancing personal and work responsibilities; increased irritability, emotional sensitivity and anxiety; and weight gain and physical health issues.
Cybermindz meditative protocolCybermindz addresses the disconnect between neurology and the threat environment through the iRest protocol, a contemporary, 10-step meditative practice adapted from ancient teachings by Richard Miller.
The evidence-based practice is endorsed by the U.S. Military and involves short sessions (10 to 20 minutes) that can be done anywhere and at any time. The protocol’s 10 steps include: connect to your heartfelt desire; set an intention; find your inner resource; feel your body; become aware of your breath; welcome your emotions; witness your thoughts; experience joy; find lasting peace; and reflect on your practice.
The intent is to teach people to come out of their ‘fight or flight’ mode, build resilience and self-monitoring capabilities and address “unprocessed, emotional drivers” that get triggered in a cybersecurity incident, Coroneos explained.
You have to be able to “get to the stuff that's beneath the surface that you're carrying in your subconscious,” he said.
Participants in a recent eight-week pilot program reported feeling more rational, calm, confident, balanced, perceptive to stress and aware of their thoughts and emotions. Many also saw improvements in their sleep, mood, concentration, creativity and productivity and felt they were better equipped to handle stressful situations and workload fluctuations and understand personal triggers. Developing coping mechanisms and self-improvement initiatives were other key takeaways.
Cybermindz was founded in Australia a year ago, entered the U.S. in April and plans to continue to further its global reach. Devo has pledged financial support for the nonprofit — an undisclosed lump sum, as well as $10 for every visitor at its booth at Black Hat.
iRest is a practice and it does take time to learn and master, Coroneos acknowledged. But he underscored the fact that, “we're in a neurological state of warfare. Quick fixes are not going to cut it.”
Incorporating AI and getting back to humanityLever urged cybersecurity professionals to remember they got into the field for a reason — “there’s something here that you love.”
Make time for passion projects and be willing to take hits as a team and learn from them, he advised. Moving forward, AI can automate monotonous tasks and help junior analysts level up their skills (by watching how a model came to a certain conclusion, for instance).
AI can also take out a lot of the monotony, Copeland said, thus allowing analysts to pivot to more strategic tasks (and in near-real time).
He described one of his early “ah-ha!” moments in this area: He incorporated threat logic based on readily-available foreign intelligence into his company’s system and “literally the next day” they had a breach. Because he had built in that threat logic, he was able to detect the issue in real time and prevent it from escalating.
“I did something that benefitted,” he said. “I'm just closing out false positives for eight hours a day. That creates job satisfaction. Leveraging AI to take care of those false positives equals more opportunities for wins.”
He also advised SOC leaders to engage, connect with and pay attention to their team. He, for instance, holds one-on-one sessions to talk to team members about their goals, responsibilities, frustrations and other factors.
This helps to not only build a relationship, but allows him to watch for burnout red flags, at which point he can intervene and move them to another area or task, “backfill them and shuffle the deck that way.”
“Ultimately, you get to put the people back into cybersecurity,” said Copeland.
Comments