This article is part of our Opinions section, where we invite industry professionals to share their views on the most pressing technology questions of our time.
The role of CISO has never been more demanding. As cyber threats grow in frequency and sophistication, security leaders find themselves leading the charge in an unrelenting battle for cyber resilience. They’re under pressure, not only to prevent attacks, but also to ensure their organisations can operate and grow securely and effectively.
Many face overwhelming workloads, budget constraints and, in some cases, insufficient board-level support. The expectation of higher-than average availability, coupled with mounting compliance requirements and financial pressures, has made CISO burnout an industry-wide problem, and one that could, in theory, exacerbate a companyโs security risks.
Burnout is a business risk
Splunkโs recent survey on stresses faced by UK CISOs reveals that stress and overwork are a significant concern. If burnout drives CISOs and their teams to exhaustion, businesses may be left vulnerable to attacks, regulatory failures and talent churn. Ultimately, this is not just a personal struggle for CISOs – it should be a business priority.
87% of UK CISOs report that their role has become more challenging over the past two years. With increasingly complex attack vectors, sophisticated phishing attacks, and the ever-present threats of ransomware or extortion, organisations are finding it harder to stay ahead. At the same time, CISOs need to navigate increasingly complex compliance requirements and the financial implications of breaches.
Unlike some other executive roles, where strategic oversight can be prioritised over day-to-day operations, CISOs are arguably expected to be more hands-on with the operational day-to-day, helping to manage and direct the response to crises while also planning long-term cybersecurity strategies and interfacing with the board.
Lack of support may be a factor in CISO stress
Despite these challenges, many CISOs feel under-supported. In Splunkโs 2025 CISO Report, more than half of CISOs globally reported that limited resources and budget constraints contribute directly to stress and overwork, and 64% link lack of financial support to a cyberattack.
The reality is that many executives do not yet fully understand the scale of modern cyber threats, yet they impose unrealistic expectations on security teams. Without sufficient funding, CISOs must attempt to do more with less, leaving gaps that attackers can exploit. It is no surprise to discover that 44% of CISOs are considering leaving their roles due to stress, while 23% are actively seeking out new job opportunities.
The strain is not limited to CISOs themselves as burnout is, perhaps unsurprisingly, also felt by wider security teams. Around 34% of UK CISOs report signs of burnout within their teams. This will often lead to declining morale, increased turnover, and weakened security postures. A security team that is constantly firefighting and working overtime to mitigate risks will eventually see diminished effectiveness.
With a well-documented talent shortage in the cybersecurity industry, organisations cannot afford to ignore these warning signs. If businesses fail to address the underlying pressures, they risk a revolving door of talent that compromises long-term resilience.
Some starting points in addressing CISO stress
The issue of CISO burnout is not an inevitability โ it is a problem that can be addressed with meaningful interventions. Cybersecurity is not just a technology issue but a leadership challenge requiring systemic change. Businesses need to educate boards and executive leadership on risks so that security leaders receive stronger institutional support.
CISOs and their teams, where possible, should not be expected to be on call 24/7, and structured downtime policies should be implemented to allow for rest and recovery. Responsibilities should be distributed more effectively across security teams to prevent burnout at every level.ย
Technology can also play a role in alleviating some of the pressures, but it is important to remember that it is not the only solution. By leveraging AI and automation, security teams can reduce alert fatigue, automate low-value security tasks, and focus on high-impact initiatives.
Cybersecurity is a field that demands constant vigilance, but organisations need to ensure that their leaders are not overwhelmed by routine tasks that could be streamlined with technology.ย
Additionally, implementing meaningful well-being programs can be of benefit in addressing any stresses that do arise. However, less than half of organisations surveyed provide or fund mental health and wellbeing services, even though structured well-being initiatives have been shown to improve resilience and retention.
Companies can establish peer support networks, coaching programs, and confidential mental health resources to support security teams. Investing in such programs is not just about employee welfare โ it is about ensuring the sustainability of an organisationโs cybersecurity strategy.
What needs to change?
While there is no single definitive solution to the issue of CISO stress, leaders should concentrate on a range of strategies. Otherwise, companies risk losing top security talent at a time when cyber threats are at an all-time high, and they may find themselves scrambling to fill critical security leadership roles amid an already competitive hiring landscape.
By prioritising the wellbeing of CISOs, businesses can not only prevent burnout but also strengthen their overall cybersecurity posture.
More stories on healthy workplaces