98% of Cybersecurity Leaders Report Job Stress. The Fix Isn't More Hiring.
A major industry survey finds that stress among security chiefs has become the norm, not the exception. The real problem, argues one senior researcher, is a design flaw in how organisations treat the role itself.

Key points
- Only 2% of cybersecurity professionals reported feeling no job-related stress, according to Omdia and ISSA's 2025 Life and Times of Cybersecurity Professionals study.
- 68% of respondents said their work has become measurably harder over the past two years.
- 47% considered leaving their job or the profession entirely in the past year.
- Full-time Chief Information Security Officer (CISO) appointments fell from 76% to 63% of organisations in a single year, while use of part-time, outsourced security chiefs roughly tripled.
- 72% of respondents said technology decisions are made without security teams being involved.
Two percent. That is the share of cybersecurity professionals who say their job causes them no stress at all, according to the eighth annual Life and Times of Cybersecurity Professionals report from research firms Omdia and ISSA. The other 98% feel the pressure. And 68% say the work has got noticeably harder over just the past two years.
Those numbers alone would suggest a workforce problem: not enough people, not enough pay. Dirk Schrader, a senior security researcher at software company Netwrix, writing in Dark Reading, argues that framing misses the point entirely. Eight years of the same survey producing the same results, he says, points to something structural.
Why are security leaders burning out?
The short answer: they carry the blame for decisions they never got to make. Some 72% of survey respondents said technology decisions happen without security's involvement, and 69% described security as something the rest of the business works around rather than builds alongside.
Put plainly, the person whose job it is to protect an organisation often finds out about risky choices after they have already been made. Chronic stress follows that arrangement reliably, regardless of salary.
Schrader uses a pointed comparison. Coal miners once carried canaries into underground tunnels because the birds would react to poisonous gases before any human felt ill. A CISO who burns out and leaves, he argues, is doing something similar: signalling that an organisation's underlying defences are weakening long before that shows up anywhere visible.
What does the data say about pay and technology fixes?
Compensation alone doesn't close the gap. A bigger salary raises expectations on both sides without changing the structural conditions that produced the stress. Organisations expect more; the security leader expects more say; neither reliably follows.
The technology picture is similarly tangled. Survey respondents named managing a sprawl of disconnected security tools as one of their biggest day-to-day stressors. Fragmented tools create blind spots, produce floods of alerts that require constant attention (sometimes called "alert noise"), and eat time that would be better spent on leadership work.
Schrader offers a concrete illustration: if a security chief spends ten weeks a year renegotiating contracts for a dozen separate software products, that is ten weeks not spent building the internal relationships the same survey identifies as the single strongest driver of job satisfaction.
The table below summarises the key survey findings
| Finding | Figure |
|---|---|
| Professionals reporting no job stress | 2% |
| Say work is measurably harder than two years ago | 68% |
| Considered leaving their job or profession in the past year | 47% |
| Technology decisions made without security involvement | 72% |
| Security described as something the business works around | 69% |
| Full-time CISO appointments (down from 76%) | 63% |
One trend in the data deserves particular attention. Full-time CISO appointments dropped from 76% to 63% of organisations in a single year. Over the same period, use of part-time or outsourced security chiefs, often called virtual CISOs, roughly tripled.
Part-time arrangements suit smaller companies and specific situations. But the survey found that leadership commitment to cybersecurity, the sense that senior management genuinely backs the security function, ranked as the strongest driver of professional satisfaction, ahead of pay. That kind of commitment, Schrader argues, is difficult to build from outside an organisation on a part-time basis. A virtual CISO focused mainly on policy documents and board presentations also risks making the role easier to automate away entirely.
Schrader's conclusion is straightforward: the fix requires giving security teams real authority that matches their real accountability, involving them in business decisions before those decisions create risk, and consolidating fragmented tool sets into platforms that provide genuine visibility. Those are design changes. No salary increase and no additional headcount substitutes for them.



