
Anthony Young at Bridewell explains why burnout in cyber security teams is such a problem, and how organisations can combat it
When it comes to cyber maturity, having the right people is everything. Yet, according to recently commissioned research among cyber decision-makers in critical national infrastructure (CNI), 26% of organisations don’t have the skills they need to effectively and quickly respond to cyber threats.
A large part of this can be attributed to cyber burnout, with 4 in 10 cyber leaders in UK CNI saying stress and burnout could push them to leave their job in the next year. To ensure they have the right people to support their cyber security programmes, organisations must ensure cyber talent is rewarded, retained, and looked after.
Other factors contributing to cyber burnout include greater interconnectivity of systems, ever-more complex security compliance requirements, and the constant need to understand new technologies and drive digital transformation.
These pressures can create a vicious cycle: if cyber teams continue to be asked to do more with less people to support transformation, the risk of human error and data breaches could well rise, compounding the problem further.
However, there is hope on the horizon. Growing awareness of the issue of cyber burnout means that businesses can implement strategies today to alleviate the pressure on teams. To maintain a strengthened cyber security posture and a healthy workforce, systemic changes must be made – before the cyber burnout cycle is beyond repair.
Reducing the burnout threat among IT and security employees is a time-sensitive issue. Businesses need to move quickly and proactively in making sure their first line of cyber defence is fully staffed and equipped to manage evolving security risks. A key part of this is spotting the early warning signs of burnout.
These signs can include irritability and fatigue, a negative attitude to the role, disengagement, a lower quality of work, or higher absence rates. Staff with burnout may also start changing their usual working routines – possibly clocking in early, staying late, frequently emailing during out-of-office hours, or skipping lunch breaks.
In remote working environments, these early signs may not be as visible to managers, which is why businesses should build a culture where wellbeing is front of mind and professionals feel comfortable asking for support – no matter where they are working from.
Flexibility is a key factor in making cyber teams feel less exhausted, stressed, and overwhelmed. It can be incorporated into the working day in a number of realistic ways, such as by encouraging regular breaks or varying working hours. Scheduling regular one-on-one time with team members to check in on their workload and state of mind is also helpful. This allows managers to identify patterns in responses and devise a clear plan to tackle any impending burnout issues.
To effectively tackle any early warning signals, managers should ensure that volunteer mental health officers are on hand to provide an outlet where staff can air their concerns. Employee wellbeing should be available to everyone in the workplace, and can be promoted through wide-ranging initiatives such as flexible working arrangements, access to counselling through Employee Assistance Programmes (EAP), and team and activity days to ensure people have the opportunity to socialise both in and outside of work.
It is also essential to address burnout across all tiers of management. Middle managers, in particular, are becoming increasingly stressed and squeezed, with spiralling demand and gaps piling further pressure on the CISO. This means that those in middle and lower levels are being asked to do more with less and are often overlooked.
To reverse this trend, organisations must recognise the underlying issues. Constant firefighting, lack of resources, and a disconnect with senior management are commonly cited reasons for CISO burnout. This means that the C-suite has an important responsibility; establishing a culture that genuinely invests in cyber security and cyber talent.
By recognising these challenges and working with middle management and lower levels, these teams will feel supported from within.
To help close the cyber skills gap that is fuelling burnout, businesses should commit to upskilling their internal teams. After all, employees that feel on top of the tools and technologies essential to their jobs are considerably more likely to be engaged, productive, and in control.
Managers that pay attention to building up vital in-house skills stand to benefit in the long term, as they are less reliant on short-term ‘quick fixes’.
Education is key to managing evolving cyber threats, so staff at all levels should be fully informed and trained on a range of basic cyber hygiene practices, such as regular testing and patching of systems and segmentation of networks.
But there is another trick that many organisations are currently missing. Being prepared to take on and upskill other people from a more diverse talent pool can make all the difference in mitigating the effects of burnout. Instead of searching for someone who ticks every box, businesses should look out for the passionate and talented individuals in situ who can make their own valuable contributions.
Of course, not every business has the resources or expertise to provide this vital training in-house. Outsourcing is becoming an increasingly attractive option for many organisations looking to supplement depleted cyber teams. With their broad experience and sector-specific knowledge, external consultants can plug gaps quickly and efficiently, mitigating the additional risk to security from overstretched or overwhelmed staff.
Businesses that engage external expertise can also be supported in upskilling promising new starters as permanent team members, lightening the load on peers and encouraging career progression.
It is important for organisations to carefully consider which service provider to use when outsourcing cyber security. Some providers are reluctant to deliver any additional services outside the scope of the contract, which limits flexibility as cyber security challenges evolve over time. Other consultants look impressive from a cost perspective but do not guarantee outcomes, essentially rendering them ineffectual.
The best service providers will guarantee specific outcomes contractually, while offering organisations the flexibility needed to keep pace in a rapidly shifting cyber security landscape.
Ultimately, the decision lies with each individual business as to whether they should embrace external consultancy. But every business must now prioritise and address the growing issue of burnout facing cyber teams.
With the right strategies and approaches in their toolkit, managers can start to break the cycle and reverse this dangerous trend, helping IT and security teams reset in time for the challenging months and years ahead.
Anthony Young is Co-CEO at Bridewell
Main image courtesy of iStockPhoto.com
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543