98% of Cybersecurity Leaders Report Job Stress. The Fix Isn't More Hiring.
A major industry survey finds that stress among security chiefs has become the norm, not the exception. The real problem, argues one senior researcher, is a design flaw in how organisations treat the role itself.

Key points - Only 2% of cybersecurity professionals reported feeling no job-related stress, according to Omdia and ISSA's 2025 Life and Times of Cybersecurity Professionals study. - 68% of respondents said their work has got measurably harder over the past two years. - 47% considered leaving their job or the profession entirely in the past year. - Full-time Chief Information Security Officer (CISO) appointments fell from 76% to 63% of organisations in a single year, while use of virtual or fractional security chiefs roughly tripled. - 69% of respondents described security as something the rest of the business works around rather than builds alongside.
Two percent. That is the share of cybersecurity professionals who say their job causes them no stress at all, per the eighth annual Life and Times of Cybersecurity Professionals report from research firms Omdia and ISSA. The other 98% feel the pressure. And 68% say the work has got noticeably harder over just the past two years.
Those numbers alone might suggest a workforce problem: not enough people, not enough pay. Dirk Schrader, Resident CISO (EMEA) and VP of Security Research at Netwrix, writing in Dark Reading, argues that framing misses the point entirely. A profession that produces the same survey results across eight consecutive years, he says, has a structural problem, not a staffing one.
Why are security leaders burning out?
They carry the blame for decisions they never got to make. The person whose job it is to protect an organisation routinely finds out about risky choices after they've already been made. Chronic stress follows that arrangement regardless of salary.
Schrader uses a pointed comparison. Coal miners once carried canaries into underground tunnels because the birds would react to poisonous gases before any human felt ill. A CISO who burns out and leaves, he argues, is doing something similar: signalling that an organisation's underlying defences are weakening well before that shows up anywhere visible.
We've been tracking how this pressure manifests differently across the profession. Our 20 July story "A Quarter of Security Chiefs Thought About Quitting Last Year. AI is Why." found Splunk survey data pointing to AI risk and personal legal exposure as compounding factors alongside the structural ones Schrader identifies here.
What does the data say about pay and technology fixes?
Compensation alone doesn't close the gap. A bigger salary raises expectations on both sides without changing the conditions that produced the stress. Organisations expect more; the security leader expects more say. Neither reliably follows.
The technology picture is similarly tangled. Respondents named managing a sprawl of disconnected security tools as one of their biggest day-to-day stressors. Fragmented tools create blind spots, produce floods of alerts requiring constant attention (sometimes called "alert noise"), and consume time that should go toward leadership work.
Schrader offers a concrete illustration: a security chief who spends ten weeks a year renegotiating contracts for a dozen separate software products is spending ten weeks away from the executive relationships the same survey identifies as the single strongest driver of job satisfaction.
The table below summarises the key survey findings
| Finding | Figure |
|---|---|
| Professionals reporting no job stress | 2% |
| Say work is measurably harder than two years ago | 68% |
| Considered leaving their job or profession in the past year | 47% |
| Security described as something the business works around | 69% |
| Full-time CISO appointments (down from 76%) | 63% |
One trend in the data deserves particular attention. Full-time CISO appointments dropped from 76% to 63% of organisations in a single year. Over that period, virtual or fractional security chiefs roughly tripled in use.
Part-time arrangements suit smaller companies and specific situations. But the survey found that leadership commitment to cybersecurity ranked as the strongest driver of professional satisfaction, ahead of pay. That kind of commitment is difficult to build from outside an organisation on a part-time basis. A virtual CISO whose work narrows to policy documents and board presentations also risks making the role easier to automate away entirely.
Schrader's conclusion is direct: the fix requires giving security teams real authority that matches their real accountability, involving them in business decisions before those decisions create risk, and consolidating fragmented tool sets into platforms that deliver genuine visibility. Those are design changes. No salary increase substitutes for them.
The canary has been signalling for eight years. Whether organisations choose to listen is the only question left.



