Menu

Call us on 03450 21 21 51

How to alleviate stress for CISOs
The SRM Blog

How to alleviate stress for CISOs

Julia Wailes-Fairbairn

Written by Julia Wailes-Fairbairn

27th May 2021

Share this article

stress for CISOs

High pressure environments are nothing new for C-suite executives. There are always decisions to be made, the stakes are always high, and the future aspirations of an organisation often rely on the effective steering of the corporate ship. However, the last 12 months have undoubtedly been stressful on another level.

In particular, the pressure under which Chief Information Security Officers – or CISOs – have been functioning is nothing short of stifling. It shouldn’t be surprising to hear then that many CISOs and senior IT professionals are beginning to feel things getting on top of them. With no relief over the last 12 months, a recent mental health survey suggests that a worrying 24% have now taken to self-medicating with alcohol, narcotics or prescription medication to ease the stress.

Often, mental health concerns are interpreted as an internal issue for individuals but, increasingly, we are realising as a society that the working environment is critical to wellbeing and businesses must do their part to ensure a culture of support and nurture.

A number of recent surveys of CISOs and IT professionals across the globe have provided useful insight into the factors which contribute to these elevated stress levels. Understanding the cause of stress for CISOs is important if we are to take steps to alleviate the pressure and ensure that CISOs have the resource and support to do their vital job effectively.

The IAMokay Mental Health Survey polled 250 tech professionals from around the world and found that 86% had experienced an increased workload as the result of the pandemic. What is concerning is that this new pressure is being added to an already difficult role. Back in February 2019, even before the pandemic hit, the Nominet study “Life Inside the Perimeter: understanding the modern CISO” reported that 91% of all respondents said they suffer from moderate or high stress with 17% using medication or alcohol to help cope.

What are the causes of all this stress for CISOs?

  1. The buck stops here

Being ultimately responsible for the security of an organisation is tough enough in today’s climate. Having the buck stop with you is surely pressure enough but the Nominet survey also found that 60% of respondents said they had found malware within their systems while admitting to having no idea how long it had been there. That is enough to give anyone a sleepless night or two, but 32% also said that they expected to lose their job or receive an official warning if a breach occurred.

  1. Threats

The 2021 Voice of the CISO Report examined responses from 1,400 CISOs in mid to large organisations around the world. It reported that 64% feel they are at risk of suffering a material cyber-attack in the next 12 months. Just over a third are concerned about Business Email Compromise attacks, 33% are concerned about Cloud Account Compromise and 27% about Ransomware attacks.

  1. The human factor

The stress of ultimate responsibility is exacerbated by the fact that CISOs do not operate in isolation. Although over half of respondents to the 2021 Voice of the CISO Report felt that co-workers understand what they need to do to protect their organisation from cyber threats, 58% of CISOs still feel that human error is the biggest cyber-vulnerability. What is more, 31% think that insider threats are a real problem with 58% of CISOs believing that human error is their single greatest vulnerability.

  1. Lack of board level support

The Nominet poll found that in 2019 48% felt that the security team was not valued and 65% considered that lack of board-level engagement was a major challenge. This is likely to have an impact on investment and, of significant concern is the fact that 57% in the IAMokay Mental Health Survey feel they had insufficient budget to deal with current threats.

  1. Lack of time & resource

The IAMokay Mental Health Survey 2021 also found that 54% of CISOs had been unable to take any time off over the last 6 months. In addition, the Nominet survey had found that 60% were unable to ever switch off from their jobs, despite already working a 40-hour week.

How can this stress be alleviated?

If things are left unchecked, it is likely that we will see a proportion of CISOs and IT professionals facing burnout over the next twelve months. Little can be done about the pandemic and its far-reaching impact but steps can be taken to address the other issues.

  1. Mental health support

Mental health support has been offered to 49% of IAMokay survey respondents. This must be welcomed but, without addressing the work load, cannot be the only provision to lift some of the burden facing by CISOs and their teams.

  1. Prioritising information security and allocating adequate resource

Data security is vital to the long-term future of any business or organisation. It is therefore not simply the responsibility of the CISO to make a case for making it a priority. It should be on every board agenda and regularly reviewed. Allocating an adequate budget is not a luxury; it is an essential investment in the future of any organisation.

  1. Providing practical expert support through a vCISO service

A stressed CISO will not perform to their best ability and providing expert support is probably the single most important factor for relieving the pressure cooker surrounding them. Just as specialist accountants support the finance team and expert lawyers support the legal team, the CISO can be supported and resourced by a managed virtual CISO service.

 

For organisations looking to add resource and expertise to their in-house information security and IT teams, our VirtualCISO service can be incredibly important. Having an information security specialist on hand as a flexible, versatile solution whenever required has proved itself to be an invaluable help to many of our existing clients.

To find out more about how our team can give your CISO or ISM the back-up you need, why not contact us today?