Stress and burnout is emerging as perhaps the biggest threat to corporate security. Long hours, alert overload, and a lack of visibility into their IT infrastructure have many security professionals reconsidering their chosen careers.
This is contributing to a massive cybersecurity skills shortage that is creating real security threats at companies across the globe. There are close to three million open and unfilled cyber vacancies around the world. Meanwhile, a majority of organizations cite a “problematic shortage” of cyber skills, and a new report from the Ponemon Institute has found that 65% of IT and security professionals are considering quitting due to burnout.
Reports like these should serve as bright red warning lights to everyone in a company, from Board members and CEOs down to Security Operations Center (SOC) managers. Everyone needs to take a strategic approach to addressing the problems emanating from the burnout brain drain. Without the right personnel, organizations can’t deploy the right resources, controls, and processes to prevent and mitigate attacks.
In short, they’ll be even more vulnerable than they are right now. That can’t happen. Organizations need to proactively tackle SOC stress. Here’s how.
Understand the causes
In an interview with Dark Reading, Julian Waits, general manager for security analytics firm Devo, which sponsored the Ponemon study, says the incomplete visibility into systems and threats is a major issue. Waits said that: "Going to work each day and knowing you've been compromised” can be enormously stressful for security professionals, but that “knowing” is compounded by the fact that most do not know how their organizations have been compromised.
Take the Neiman Marcus data breach during the busy 2014 holiday season, for example. The attack that compromised more than 1.1 million debit and credit cards set off about 60,000 alerts in the retailer’s SOC during the three-and-a-half month attack. This represented around 1% or less of the daily entries on protection logs. Unless the SOC knew what type of alert to look for, it would be a miracle for them to find it.
Know that money isn’t enough
In the face of growing threats, higher fines for breaches, and increased competition for cybersecurity talent, CEOs are throwing more and more money at relieving the knock-on effects of burnout in the SOC. And, in a red-hot job market, security pros can name their price. It’s not unusual for CISOs to command as much as $6.5 million in salary and profit sharing, with many jumping from job to job to attain that level of compensation.