Security Employee Burnout: The Coverage Gap Hiding in Your Security Team
A few years back, Peter Coroneos, founder of the cyber mental health group CyberMindz, started making a claim that got a lot of attention: that cyber defenders operate at the edge of human endurance, under a 24/7 threat cycle he’s compared to high-intensity frontline roles, military contexts included. It was a good line. It got quoted at conferences, dropped into keynote decks, nodded along to in boardrooms. Then, in most organisations, it went exactly nowhere.
That’s the trouble with a frontline-stress metaphor. It’s vivid enough to make people feel something for thirty seconds, and vague enough that nobody has to act on it. You can’t put “operating at the edge of endurance” on a risk register. You can put a resignation rate on one.
The workload stopped being a feeling and became a number
This year, Seemplicity commissioned Sapio Research to survey 300 US cybersecurity leaders. The findings: nearly half are working 11 or more extra hours a week beyond their contracted schedule, one in five are past 16, and Seemplicity frames that as effectively adding a sixth working day. Seemplicity also reports an average of 10.8 extra hours a week across the group, and that 73% of leaders now rank AI oversight and governance as the defining capability of the future security professional, ahead of technical engineering. Whichever figure you lean on, the direction is the same: security leaders are absorbing an entirely new category of responsibility without anyone redesigning what their week actually looks like.
As Ravid Circus, Seemplicity’s Chief Product Officer, has argued: simply adding AI oversight on top of an unchanged team structure doesn’t ease the load, it accelerates burnout, because the org chart itself needs to be rebuilt around the new job, not just the old one with extra tasks bolted on.
That’s the real shift from three years ago. Burnout used to be a story about feelings. Now it’s a story about structure, and structure is something a CISO can actually redesign.
The same “edge of endurance” argument now comes with a control group
Here’s the part I find genuinely encouraging. CyberMindz didn’t stop at the metaphor. It kept running its iRest resilience training with cyber teams for the next few years and this year published results from 275 participants tracked between 2022 and 2026.
The numbers are the kind you can actually act on: emotional exhaustion down 19%, cynicism down 26%, professional efficacy up 10%. Attrition risk, the strongest predictor of someone quietly updating their CV, dropped from 27% of participants to 8%.
Coroneos made the point that matters most for how CISOs should be pitching this internally: framing burnout support as a wellness perk kills the funding, because wellness reads as discretionary. Framing it as a measurable driver of attrition and coverage gaps gets it into the same conversation as patch management and control gaps, which is where it actually belongs.
The lever that moves the needle isn’t a wellness stipend
If you’re looking for where to spend the budget, the workload numbers point somewhere specific. Bitsight’s 2025 State of Cyber Risk and Exposure report, drawn from more than 1,000 risk and security professionals, found burnout ran at 63% in organisations without solid asset discovery or continuous monitoring, and 44% in organisations that had it. That’s not a small gap, and it has nothing to do with meditation apps.
It tracks with what anyone who’s run a SOC already knows. Burnout thrives on uncertainty: not knowing what’s actually exposed, not knowing what to prioritise, firefighting the same ambiguous risk every quarter because nobody built the visibility to close it out permanently. Give a team clarity on what actually matters and the hours don’t necessarily drop, but the exhaustion does.
What this means for your risk register
Three things, none of which involve a poster in the break room.
- Put burnout indicators next to your other leading indicators. Overtime hours, unfilled reqs, time-to-fill on security roles: these predict coverage gaps the same way an unpatched CVE predicts an incident. Track them the same way.
- Fund visibility before you fund wellness. The data says uncertainty about risk exposure is a bigger burnout driver than raw workload. Fixing that is an architecture decision, and it’s one that pays off twice: fewer blind spots, fewer exhausted analysts guessing at what matters.
- Redesign the role before you redesign the perks. If you’ve added AI governance, threat-hunting, and board communication to a job description that hasn’t changed shape since 2019, you don’t have a resilience problem. You have a job design problem wearing a resilience costume.
The edge-of-endurance framing was never wrong. It just wasn’t actionable. What’s changed is that the same people who made that claim went and built the evidence behind it, and turned an evocative metaphor into a number a CISO can put in front of a board.
Treat burnout like the coverage gap it is, and it becomes something you can budget for. Leave it as a metaphor, and it stays something you apologise for after the resignation letter lands.

Responses