Cybersecurity burnout is an operational threat: AI can help | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Cybersecurity has always been a high-pressure profession. Security teams are expected to monitor an organization’s digital environment continuously, respond when something goes wrong and stay ahead of attackers who need to be right only once. Now analysts are being asked to do it while navigating staffing constraints, budget pressure, rapidly changing technology and a threat landscape fueled by AI.

In the 2025 ISC2 Cybersecurity Workforce Study, 48% of cybersecurity professionals surveyed said they’re exhausted trying to keep up with the latest cybersecurity threats and emerging technologies. Forty-seven percent said they’re often overwhelmed by their workloads.

Cybersecurity burnout isn’t just a workforce or employee-wellness problem. When the people responsible for detecting, investigating and containing threats are overwhelmed and exhausted, those conditions degrade an organization’s security posture. Burnout can directly affect an organization’s ability to retain good people, track institutional knowledge, and identify and respond to threats.

With the industry’s workforce clearly under strain, a panel of cybersecurity experts dissected the problem during the “Burnout and Resilience in Cyber Operations” panel at the 17th annual Billington Cybersecurity Summit in Washington, D.C., this September.

“We believe that burnout isn’t simply a wellness issue,” said Debbie Sallis, panel moderator and executive director of The Cyber Guild Foundation. “Burnout is really about operational readiness and resilience, and therefore, it’s a mission-critical subject.”

A systemic issue

Many industries contending with employee burnout treat it as an individual problem that can be solved with better work-life balance or stress-management skills. Panelists were quick to point out that the cybersecurity field is different and, perhaps, unique.

David Grundy, public sector CTO at workflow automation platform, Tines, sees burnout as more systemic than a sheer volume problem. “We’re dealing with an issue of system design when it comes to cybersecurity with a compounding threat environment,” he said. “We’re dealing with tools that are being introduced on a rapid basis to our staff and our analysts, and a situation where our staff is drawn into researching false positive investigations, audit logging and reporting. That is not what I would call fulfilling work.”

Patrica Titus, field CISO at Abnormal AI, a cybersecurity software company, recalled efforts to train help desk staff to be security analysts. “What we’re finding is they don’t want to be ticket takers and today, that’s what’s happening.”

Panelists pointed out that security teams have become so encumbered that the work is leading to unmanageable stress levels. An SOC can have the right security products deployed and still lack the operational capacity to use them effectively. A SIEM or EDR generating alerts around the clock still requires human investigation. The effectiveness of an incident response plan depends on whether people have the capacity and experience to execute it.

A solvable problem

The discussion pivoted to a fundamental reimagining of how security operations function. Artificial intelligence was identified as a source of the strain but also as providing tools capable of addressing the root causes of analyst burnout while simultaneously strengthening organizational cyber resilience. AI can help with alert triage, investigation support, summarization and routine analysis, among other tasks.

“We have a growing threat landscape that AI is introducing and making worse,” Titus said. “And we need to find capabilities that are going to take away some of the low-risk, churn work that our employees are having to do, especially analysts. Some of this is around adopting technology that makes [analysts] more efficient and effective to be able to do the work that they really want to do.”

Grundy added that “the more mature organizations have now adopted AI to where they are expanding the roles of analysts with more of an end-to-end model where we can leverage AI to do the transactional, more rudimentary — what we might call — muck work.”

Grundy described a future using AI that would free analysts from repetitive tasks, spurring efficiency and creativity. “Now you’re designing new processes, new operations and new models for your security teams,” he said. “Now you’ve expanded the technical environment and the capacity of what your cybersecurity teams can do. Now they’re being creative. Now they’re designing new methods of support, and that’s really an exciting place to be, because now you’re forward-thinking, and now you’re getting in front of that threat landscape.”

Titus noted that AI is being used for negative ends, such as creating cyberweapons of mass destruction and attacking companies and water plants. “There’s so much stress around us,” she said. “We have to turn AI into the helpful companion in our operations centers.”

Richard Livingston is an editor for TechTarget Cybersecurity, covering news, trends and analysis. Livingston’s professional background includes editorial positions in the national defense industry covering the U.S. Army Medical Department, as well as offensive and defensive cyber strategy for military and government audiences.

——————————————————-


Click Here For The Original Source.