Burnout, Courage, and 'Good Enough': What One Top Security Chief Learned on the Way to the C-Suite

Ping Identity's CISO Russ Kirby opens up about the mindset that kept him going through a decade of high-pressure security roles, and what still worries him today.

ThreatVectr Newsdesk· 3 min read
A sleek, modern corporate security operations room photographed from a low angle looking toward a large curved desk with multiple dark monitors displaying abstr
Share

Key points

  • Russ Kirby, Chief Information Security Officer (CISO, the executive responsible for a company's entire security program) at Ping Identity, shared career lessons in an interview published by SecurityWeek.
  • Kirby credits passion as the main defence against burnout in security leadership roles.
  • His path ran from Hewlett-Packard (HP) to the C-suite, shaped by what he calls 'good enough' thinking and a willingness to act before all the answers are in.
  • Security chiefs across the industry increasingly cite burnout and chronic stress as a retention crisis.

Who is Russ Kirby, and why does his story matter?

Kirby is the CISO at Ping Identity, a company that makes software controlling who can log in to other companies' systems. His job, in plain terms, is to make sure criminals cannot get in where they should not.

That sounds straightforward. It is anything but. A CISO sits at the intersection of technology, law, finance, and company politics, carrying personal legal exposure if something goes wrong. The role has one of the highest burnout rates in any profession.

Kirby's answer to that pressure is not a wellness app. It is passion.

What does 'passion as antidote' actually mean?

Burnout, the state of chronic exhaustion that follows months or years of relentless high-stakes stress, is emptying security teams faster than companies can fill them. Kirby's argument, as reported by SecurityWeek, is that people who genuinely care about the mission, protecting real users from real harm, carry a fuel source that pure professionalism cannot supply.

That is not a soft claim. Research from the firm Heidrick and Struggles found in 2023 that roughly a quarter of CISOs planned to leave their roles within two years, citing stress and lack of support.

Passion alone does not fix a broken organisation. Kirby is clear on that. Courage matters too, specifically the courage to make a call before the data is complete.

What is 'good enough' thinking?

'Good enough' sounds like cutting corners. Kirby means something different: recognising that waiting for a perfect solution often means no solution arrives before the attacker does.

Security decisions are made under time pressure with incomplete information. A CISO who freezes waiting for certainty hands the advantage to whoever is trying to break in. Acting on the best available picture, then adjusting, is a discipline, not a shortcut.

This mindset, Kirby says, is something he carried from his years at HP and refined across every role since.

What should ordinary people take from this?

Most readers will never sit in a CISO's chair. But they work somewhere that has one, or should. The security decisions that executive makes affect whether your employer's payroll system gets locked by ransomware (malicious software that encrypts files and demands payment to restore them), or whether your personal data stays private.

A burned-out, under-supported security team is a gap criminals will find. Organisations that treat security leadership as a cost centre, not a critical function, create that gap themselves.

If you work somewhere with a security team, the simplest thing you can do is take their guidance seriously. Report suspicious emails. Follow the password rules. Those small actions reduce the burden on people carrying enormous weight on your behalf.

Common questions

What is a CISO and do smaller companies need one?

A CISO, or Chief Information Security Officer, is the executive who owns a company's plan for keeping its systems and data safe. Small businesses may not have a dedicated CISO, but every organisation that holds customer data needs someone filling that function.

Can security training actually reduce burnout for security teams?

Yes, indirectly. When staff across a company follow basic security habits, the volume of incidents the security team must respond to falls, which lowers pressure on those teams and gives them space to focus on harder problems.

© 2026 Threat Vectr