Sunday, December 22, 2024

HomeCyberSecurityAre cybersecurity professionals OK? | Cybersecurity Dive

Are cybersecurity professionals OK? | Cybersecurity Dive

Once the adrenaline wears off after a cyberattack, the feeling that can wash over cybersecurity professionals is best described by Jackson Browne’s 1977 hit “The Load Out.”

A 32-second long earnest piano ballad precedes a crooning Browne, who goes on to sing a tribute to his roadies and fans: “Now the seats are all empty/ Let the roadies take the stage/ Pack it up and tear it down.”

For Allan Liska, threat intelligence analyst at Recorded Future, it’s the perfect description for the aftermath of a security incident.

“Suddenly, the incident response teams are gone, the lawyers are gone, the insurance company’s gone, and now you have to put your network back together and rebuild security,” Liska said.

The highs and lows of incident response and recovery manifest a gloomy state of mind for many cybersecurity professionals. Finding an outlet, space and time to unwind is critical.

“You need to have that separation or this job will kill you, literally kill you,” Liska said.

To release tension and break away from the often chaotic work of cybersecurity, defenders have to get creative, and exhibit practice and intention. One of Liska’s outlets of choice — writing comic books — allows him to create characters that get to punish ransomware criminals.

Cybersecurity work is stressful and an extremely nerve-wracking way to make a living. Alerts flagging potentially malicious attacks are constant and they have to be taken seriously because every defender reluctantly knows attacks will happen, it’s just a matter of when.

On top of all of that, consider the insider’s perspective and insight they have into the personal threats criminals will make to extract a ransom payment from their victims. There is no honor among thieves.

Cybersecurity Dive spoke with more than a dozen security experts about the personal tolls of their job and simply asked: Are you OK? Some laughed nervously, others were momentarily taken aback by the question, and a few hinted at burnout, but the first response for each of them was, unequivocally, yes.

“My therapy session starts now,” quipped Stephanie Carruthers, chief people hacker and global head of cyber range at IBM Security X-Force.

Defenders who are doing well at work and in their personal lives have to recognize behaviors and circumstances that can throw them off course. Working all the time without breaks or meaningful distractions from the torrent of malicious activity is a surefire way to burn out, or at least undercut the ability to perform at a high level.


“You need to have that separation or this job will kill you, literally kill you.”

Allan Liska

Threat intelligence analyst at Recorded Future


“If it’s always on my mind, I’m never going to have that fresh thought,” said John Dwyer, director of security research at Binary Defense.

“As much of a science cybersecurity is, a lot of it is an art and usually your best ideas come to you whenever you’re thinking about different things,” Dwyer said. “Being the best that I can be means that I’ve got to take care of myself, too.”

Coping mechanisms

Damage control is a two-way street — on the job and away from work. Many people are attracted to cybersecurity because of its mission, yet the job can be stressful and all-encompassing.

Huntress CEO Kyle Hanslovan said he almost burned out seven years into running the company he co-founded in 2015. Early signs of fatigue, which threatened to hinder the type of difference Hanslovan hoped to make, motivated him to turn things around.

“I don’t know much in regards to psychology, but as somebody who regularly does personal therapy, it turns out for all of the negativity that you can focus on, there is just as much ample opportunity for that dopamine hit when you’re doing good,” Hanslovan said.


“I’d rather that I see the bad, such that my daughter doesn’t have to.”


“Look at me now,” he said during an interview in San Francisco’s Yerba Buena Gardens during the RSA Conference in May. “I’m not wearing a jacket, I’m wearing some Chuck Taylors, I’m out here having a good time and I’m going to hang at this trade show with my friends.”

Some people find meaning and the strength to absorb cyber-fueled tragedies in deeply personal ways.

 “I’d rather that I see the bad, such that my daughter doesn’t have to,” Amazon CISO CJ Moses said.

“It’s one of those, take the bad out of the world as much as you can for those that you care about the most,” Moses said.


Source link

Bookmark (0)
Please login to bookmark Close
RELATED ARTICLES
- Advertisment -spot_img

Most Popular

Sponsored Business

- Advertisment -spot_img