Burnout, Courage, and 'Good Enough': What One Top Security Chief Learned on the Way to the C-Suite

Ping Identity's CISO Russ Kirby on the mindset that carried him through a decade of high-pressure security roles, and what still keeps him up at night.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
A security leader's office at dusk, with desk covered in incident reports and a computer screen glowing with security dashboards, conveying the weight of respon
Share

Key points

  • Russ Kirby, Chief Information Security Officer (CISO, the executive responsible for a company's entire security program) at Ping Identity, shared career lessons in an interview published by SecurityWeek.
  • Kirby credits passion as the main defence against burnout in security leadership roles.
  • His path ran from Hewlett-Packard (HP) to the C-suite, shaped by 'good enough' thinking and a willingness to act before all the answers are in.
  • A CISO's personal legal exposure when things go wrong makes the role one of the most stressful in any industry.

Who is Russ Kirby, and why does his story matter?

Kirby is the CISO at Ping Identity, a company that makes software controlling who can log in to other companies' systems. His job, in plain terms, is to make sure criminals can't get in where they shouldn't.

That sounds straightforward. It isn't. A CISO sits at the intersection of technology, law and company finances, carrying personal legal exposure if something goes wrong. The role has one of the highest burnout rates in any profession.

Kirby's answer to that pressure isn't a wellness app. It's passion.

What does 'passion as antidote' actually mean?

Burnout, the chronic exhaustion that follows years of relentless high-stakes stress, is emptying security teams faster than companies can fill them. Kirby's argument, as reported by SecurityWeek, is that people who genuinely care about the mission carry a fuel source that pure professionalism can't supply.

That's not a soft claim. Our coverage on 3 August found that stress among security chiefs has become the norm, driven in part by a design flaw in how organisations treat the role itself.

Passion alone doesn't fix a broken organisation. Kirby is clear on that. Courage matters too, specifically the courage to make a call before the data is complete.

What is 'good enough' thinking?

'Good enough' sounds like cutting corners. Kirby means something different: recognising that waiting for a perfect solution often means no solution arrives before the attacker does.

Security decisions are made under time pressure with incomplete information. A CISO who freezes waiting for certainty hands the advantage to whoever is trying to break in. Acting on the best available picture, then adjusting, is a discipline, not a shortcut.

This mindset, Kirby says, is something he carried from his years at HP and refined across every role since.

What should ordinary people take from this?

Most readers will never sit in a CISO's chair. But they work somewhere that has one, or should. The security decisions that executive makes affect whether your employer's payroll system gets locked by ransomware (malicious software that encrypts files and demands payment to restore them), or whether your personal data stays private.

A burned-out, under-supported security team is a gap criminals will find. Organisations that treat security leadership as a cost centre, not a critical function, create that gap themselves. Kirby's story is a reminder that the humans carrying that weight need more than a title and a budget.

If you work somewhere with a security team, take their guidance seriously. Report suspicious emails. Follow the password rules. Those small actions reduce the burden on people carrying enormous weight on your behalf.

Common questions

What is a CISO and do smaller companies need one?

A CISO, or Chief Information Security Officer, is the executive who owns a company's plan for keeping its systems and data safe. Small businesses may not have a dedicated CISO, but every organisation that holds customer data needs someone filling that function.

Can security training actually reduce burnout for security teams?

Yes, indirectly. When staff across a company follow basic security habits, the volume of incidents the security team must respond to falls, which lowers pressure on those teams and gives them space to focus on harder problems.

© 2026 Threat Vectr