Cybersecurity is Exhausting...
I feel like periodic exhaustion is normal in any profession, regardless of the color of the collar — but am I alone in saying that Cybersecurity is especially exhausting?
Let me explain
Cybersecurity is a profession of constant stress, anxiety and uncertainty. It’s the persistent twitch when your phone pops a notification. It’s the wince when you read about the latest breach to a software stack that you have deployed.
I do not mean to be a naysayer — I am a Cybersecurity Professional after all. I enjoy the work that I do. I look at it this way: The duties that I perform reduce the number of incidents, and therefore the impact on people. It is truly rewarding and meaningful work in my opinion. That does not mean that it is not absolutely exhausting. Besides that, I am a nerd at heart and always have been. I just happened to take an interest in Cybersecurity somewhere along the way.
So, why the exhaustion?
There are two sides to the story. On the one hand, technology has helped humanity advance beyond anything thought possible 50 years ago. On the other hand, as technology has exploded, so too have the opportunities for nefarious individuals to capitalize on its inherent weaknesses.
Cybersecurity Practitioners (defenders) have morals and ethics. Codes of Conduct that we must abide by to maintain our professional certifications and reputations; keep our jobs and be upstanding members of an orderly society. We generally love technology and the possibilities that it offers.
The Bad Actors (adversaries) do not have morals (not in the traditional sense). They do not have rules that they must abide by to keep a job or maintain an accreditation. The only rule that they have is “Don’t get caught”. They see technology as a means to an end; a tool to make easy money.
The kicker here is that there are far more adversaries than there are defenders and they have far more time on their hands.
For defenders, it is like having to swat wasps off of you 24-hours a day, 365-days a year — and it gets exhausting.
Asymmetry is real
The scales are always tipped in favor of the adversary. Organizations simply do not have the resources to staff their program with adequate tools and talent to defend against the swarm of adversaries prowling the perimeter around the clock.
Many organizations (certainly those selling security products) think that AI is the answer. I am here to tell you, it is not — at least not the complete answer. This is evidenced by the recent Hugging Face Breach.
Autonomous Adversaries: The attack was driven largely by autonomous malicious AI agents.
Guardrail Gap: Defenders using commercial models were constrained by built-in safety/ethics filters. Adversaries running open-weight models were not.
The Outcome: Fighting an unconstrained adversary with a restricted toolset accelerates practitioner burnout.
Defenders must be right 100% of the time; attackers only need to be right once.
Defining Boundaries; Finding Peace
This is a bit of a loaded statement - particularly given the topic of this article - but fear not, peace exists and it is within reach. The long and short of it is that there has to be a shift away from looking at this as a technical problem; it is not.
The solution is not buying more alert-generating security tools that boast being the industry leader in securing [insert thing here]. The solution is simplification. This is somewhat ironic given the pace at which technology evolves and gets more complex but that is where the “not a technical problem” comes in. You can’t patch your way out of burnout.
Simplification means adopting governance frameworks like NIST CSF 2.0 at the program level. Writing realistic, approachable, enforceable standards aligned with industry benchmarks like CIS. Aligning them with business goals and risk tolerances. Providing clear accompanying materials to innovators to help them understand and implement these standards.
Having effective governance that allows for security while not stifling innovation and progress. Adopting new technologies like AI responsibly.
Peace doesn’t mean zero risk; peace means controlled, measurable risk.
When security programs rely on human heroism and endless alert feeds to survive, burnout is guaranteed. To fix the exhaustion, leadership must stop treating security as a technical arms race and start treating it as an architectural boundary.
By aligning your strategy with simple, defensible frameworks like NIST CSF 2.0, you give your team permission to stop fighting every isolated fire.
Trust is subjective, risk is measurable, and risk acceptance comes with accountability.
When you build a program centered on accountability rather than perpetual panic, your business becomes resilient—and your security practitioners can finally breathe.


