OPINION
Only 2% of cybersecurity professionals report feeling no stress about their job, according to Omdia and ISSA’s eighth annual Life and Times of Cybersecurity Professionals study. In addition, 68% say the work has become measurably harder over the past two years. The difference between those two figures is screaming that stress in this profession has moved from an occupational hazard to the default condition, and that shift changes what conclusions security leaders should draw from the gap.
The common response to numbers like these is a workforce argument: too much pressure on too few people, addressed by hiring more of them or paying them more. Both responses are already underway across the industry, and neither has closed the gap. In fact, 47% of respondents say they have thought about leaving their current job or the profession entirely within the past year. Eight years of the same survey producing the same findings points to a design flaw in the cybersecurity profession itself, one that security leaders experience most directly because that is where an organization’s structural problems tend to surface first.
The CISO as an Early-Warning System
Viewed as a diagnostic signal rather than a personnel story, CISO fatigue looks different. Security leaders who burn out, and often leave, resemble the canary once carried into coal mines. Canaries, being far more sensitive to toxic gases like carbon monoxide and methane than humans, would show distress or die well before miners noticed anything wrong themselves. Likewise, CISOs with such a high and consistent level of stress serve as a signal of degraded organizational resilience, appearing well before that degradation shows up anywhere else. A CISO reading this might feel offended being compared to a canary in a mine, but the analogy is obvious. There is rarely a business existing today that does not depend on information and information technology to be available no matter what, so if the people responsible for its protection suffer, it is the early warning sign.
The research data names the specific mechanism behind that signal. Seventy-two percent of respondents say technology decisions are made without cybersecurity’s involvement; 69% describe security as something the business works around instead of building with. Together, those numbers describe a role carrying real accountability alongside very little real authority: Security leaders answer for outcomes decided upstream, by other people, without a seat at that table. Chronic stress follows from that arrangement on a predictable schedule, driven less by threat volume than by where security sits in the decision chain.
The Money and Metrics Trap
Compensation is the remedy organizations reach for first, and it can tighten the trap rather than loosen it. A larger salary raises expectations on both sides of the relationship: The organization expects more from a costlier hire, and the security leader expects more agency in return, even as the structural conditions that produced the stress remain unchanged. Performance metrics compound the effect. When success is measured by activity, audits closed, patches shipped, and alerts triaged, the incentive favors looking busy over being effective, and no bonus structure corrects an incentive built around the wrong outcome.
The technology stack produces a similar effect, and the mechanism runs deeper than day-to-day overhead. The survey respondents name sorting through a sprawl of disconnected tools among their most common stressors. A fragmented stack creates visibility gaps that force reactive firefighting, generates integration failures that surface as alert noise, and pulls attention toward vendor management at precisely the moment that time should go toward the leadership work the same survey identifies as most valuable in a CISO.
Suppose a security leader spends 10 weeks of a given year in renewal negotiations for a dozen point solutions that could function as one integrated platform. That is 10 weeks not spent building the executive relationships and cross-functional trust the ISSA data identifies as the top driver of job satisfaction, and, over time, of retention.
A Harder Question About Virtual CISOs
Full-time CISO appointments dropped from 76% of organizations to 63% in a single year, while use of virtual or fractional CISOs roughly tripled over the same period. The arrangement suits specific situations well: Smaller organizations, transition periods, and environments mature enough that strategic oversight, rather than day-to-day presence, is what the role actually calls for.
But the same study complicates the broader shift toward outsourcing the role. Leadership commitment to cybersecurity ranks as the strongest driver of professional satisfaction ISSA and Omdia measured, ahead of compensation, and that commitment has to be built from inside an organization rather than contracted in on a part-time basis.
Taken further, a harder question follows. A CISO role reduced to policy synthesis, compliance reporting, and board updates becomes increasingly automatable. A virtual engagement built around exactly those functions accelerates that narrowing rather than resisting it. Trust-building, internal politics, personal accountability, cultural leadership: None of those transfer well to a part-time, external relationship because each depends on someone occupying the seat full-time. Followed to its end, the virtual CISO trend risks dismantling the very role it is meant to preserve.
Three Kinds of Resilience, One Design Problem
Put back together, the problem implied by the research lies in the design of the cybersecurity management model used by many organizations. The fixes it calls for are the same three forms of resilience visible in the data.
Authority that matches accountability, the missing piece in the structural trap, is an element of personal resilience — having influence on a given situation. Security seated ahead of business decisions instead of reacting to them afterward, the fix to a role that answers for outcomes it never got to shape, is operational resilience. A stable, process-embedded technology foundation that delivers real visibility instead of more alert noise, the fix to the fragmented stack, is cyber resilience.
None of this is a matter of talent or more technology, though the field still needs more of both. It is a matter of design, and the CISO sits where that design failure concentrates most visibly. This is the condition the canary has been signaling all along, and the open question is how much longer organizations plan to let it sing.


