A few months ago, I sat in on a debrief after a middle-of-the-night incident. The team had been up since 2 a.m. By 9, they were in a standup, talking through the postmortem like it was any other Tuesday. Nobody complained. Nobody asked for the morning off. That’s the moment that’s stayed with me, not the incident itself, but how normal it seemed to everyone in the room that this is just what the job costs.
Cybersecurity professionals carry a responsibility most people never see. They watch the threats moving quietly across networks. They respond at 2 a.m. because someone has to. The safety and continuity of entire organizations can depend on what they do in the next ten minutes. That work protects all of us. The industry hasn’talways matched that responsibility with the support it requires, and that gap is what I want to talk about as Cybersecurity Awareness Month begins.
The pressure behind the profession
Cybersecurity has always demanded vigilance. What’s changed is that the vigilance no longer has an off switch. Environments are more complex; threats move faster, and most teams are doing this short-staffed while being expected to answer at any hour.
The numbers back up what I hear anecdotally in conversations with our own teams and with peers across the industry. A Sapio Research survey of 300 U.S. cybersecurity and IT leaders found professionals are working an average of 10.8 hours beyond their contracted schedules each week, effectively a sixth working day. Nearly half work at least 11 additional hours a week, and one in five works more than 16.
Almost half say their jobs feel emotionally exhausting more often than rewarding, and many feel unable to take real time off because they know they’ll come back to a backlog waiting for them. About a third say they feel anxious about the week ahead before it’s even started. The 2025 ISC2 Cybersecurity Workforce Study tells a similar story: nearly half feel exhausted just trying to keep pace with emerging threats, and 47% often feel overwhelmed by workload.
Behind every one of those numbers is somebody skipping sleep, missing a kid’s game, pushing back a vacation for the third time, quietly wondering how much longer they can keep this pace up.
Resilience isn’t the same as an unlimited capacity to absorb stress
Cybersecurity people are, by nature, the ones who step forward when something breaks. I’ve never once seen this team hesitate when it mattered. But the industry has, I think, let “resilient” drift into meaning “can take anything,” and that’s a dangerous drift. Real resilience isn’t something a person has on their own; it’s something a workplace either makes possible or makes it harder.
That means looking honestly at whether workloads are realistic. It means staffing to the actual threat landscape. It means treating time off as something people can actually use without paying for it later in a backlog. And it means training managers to notice when someone’s “fine” doesn’t sound fine anymore.
Sometimes the most useful thing a leader can do is ask, and actually mean it: How are you, really? Not as a prompt for the expected answer, but with enough silence afterward that someone has room to tell you the truth.
What we’re doing this month
This Cybersecurity Awareness Month, Keyfactor is donating $5,000 to Cybermindz.org, a global nonprofit that works directly with cybersecurity professionals on burnout, stress, and trauma.
If our LinkedIn post on this reaches you and it resonates, we’d love for you to help it reach someone else who needs it. Someone in your network might be having the week I described above and might need to see that other people see it, too.
We’re in this together
There’s a statistic in the research that I keep coming back to despite everything above: 94% of professionals surveyed said they’d still choose a career in cybersecurity. That’s not a small thing. It tells me the purpose people find in this work is real, and so is the community around it.
To everyone doing this work behind the scenes: we see the cost, not just the contribution. You don’t have to carry it alone.
Learn more
Cybermindz.org is an international not-for-profit dedicated to strengthening the human side of cybersecurity.
Cyber professionals operate in one of the world’s most demanding environments, facing relentless threat activity, high-consequence decisions, disrupted sleep and increasing pressure from rapidly evolving AI-enabled attacks.
Cybermindz addresses the resulting risks to psychological health, cognitive performance and organisational resilience.
Our evidence-informed programs combine neuroscience, human performance, psychological safety and the iRest® protocol to help cyber teams manage acute stress, improve recovery and sustain clear decision-making under pressure.
Working with cybersecurity leaders, organisations, researchers and industry partners internationally, we are helping shift the conversation from burnout as an individual wellbeing issue to human resilience as an operational and organizational risk priority.
Through research, education, training and practical interventions, Cybermindz is building a future where the people protecting our digital world are themselves better protected, supported and equipped to thrive.
For more visit > cybermindz.org