$626 million: The true cost of cybersecurity burnout | Issue #6

$626 million: The true cost of cybersecurity burnout | Issue #6

Welcome to issue #6 of the ThreatReady newsletter!

ThreatReady is your source of actionable truth based on the latest industry news. It offers a people-centric perspective that connects deeply with the challenges and triumphs of leading security teams and strategy.

If the cybersecurity landscape were a chessboard, the ThreatReady newsletter would be your strategic guide to staying three moves ahead of bad actors.

Building a firewall against cybersecurity burnout

Cyber threats don’t sleep. 

There’s a constant stream of new tactics, techniques, and procedures (TTPs) and Advanced Persistent Threats (APTs) for cybersecurity professionals to be aware of and defend against.

Our latest research report: Building a firewall against cybersecurity burnout , reveals the root cause of mental health struggles in cyber teams and provides strategies to combat the burnout pandemic. 

Here’s a snapshot of key findings: 

  • On average, medium to large enterprises are losing over £130 million annually in the UK and over $626 million in the US due to lost productivity coming from stress, fatigue, or burnout.
  • 90% of CISOs are concerned about stress, fatigue, or burnout affecting their team’s well-being.
  • 74% of business leaders report staff taking time off due to stress, fatigue, or burnout.

By arming yourself with our unique research, you’ll be prepared to not only tackle burnout, but proactively look after your team, boosting your security posture in the long-term, and improving retention.

Read our report: Building a firewall against cybersecurity burnout


Are you compliant with NIST CSF 2.0?

The NIST CSF is a cybersecurity standard that many companies adopt to drive their security strategy. 

After a decade, it’s been updated to the NIST CSF 2.0. 

To remain compliant, companies must adapt to these changes, building their team’s capabilities in alignment with the new standards. 

New guidelines have been reshuffled and sub-requirements put in place:

Addressing emerging threats with NIST

The NIST CSF 2.0 has a keen focus on specific threats, such as AI, supply chain attacks, and data privacy risks.

💡 HTB Academy’s SOC Analyst job role path, alongside blue team labs provides training on the key skills needed to perform incident detection and digital forensics. This includes both new and existing requirements in the NIST CSF’s Respond (RS) function.

See how HTB content helps align your team with NIST CSF 2.0.


60% of security pros fear AI will be used for sophisticated attacks

But we can use the technology to bolster our defenses against these AI-assisted attacks. 

“AI is now more accessible to a much broader audience, like entry-level security analysts.

We’re already seeing teams use the tech to automate repetitive aspects of triage, documentation, and incident report writing with custom tools.”

Sabastian Hague, Head of Defensive Content at Hack The Box.

Want more cybersecurity trend insights that aren’t from some generic listicle with little context? 

At Hack The Box, we’ve gathered unique statistics from our own original research, to give you a glimpse into strategies to improve your cybersecurity, alongside emerging trends and threats. 

Our pick of the top three insights:

  1. 60% of security pros fear AI will be used for sophisticated attacks.
  2. 68% say learning is better at beating burnout than boosting salary.
  3. 3 in 10 security pros want a blue team role (before going “red”).

Read our top 18 cybersecurity statistics.


Win of the month (let’s celebrate fellow security leaders) 👏

Husam Shbib , Information Security Consultant, TrustLink: Recently launched a comprehensive website dedicated to guiding aspiring security professionals into the field of memory forensics , providing valuable resources and support to foster their growth and success.


👉 Share your win with the community

Your expertise and insights are invaluable. And we’re eager to share them with our vast audience of over 2.6 million members.

We’d be honored to feature your top "win" of the month related to your team, department, or security program in the next edition of ThreatReady.

A “win” could be:

  • Achieving compliance or industry standards.
  • Successfully onboarding new team members.
  • Celebrating your team’s performance.

The top wins will be shared in the next month’s edition of ThreatReady (and if it’s really good, may get some additional love on social media). Want to share your win?

Drop a comment below telling us what it is👇


Terrance P.

Cybersecurity Consultant @ Richey May GRC | SOC | Pentesting

4mo

I Agree that AI will lead to the development of new security vulnerabilities. 😶

Like
Reply
Lars Bo Frydenskov

Cybersecurity Consultant | OSEP | CRTO

4mo

European Union Agency for Cybersecurity (ENISA) highlights skill shortage as a threat and it will persist to be a threat in 2030. I think it is important for companies and organizations to invest in the mental health of their security staff. Skilled securtiy professionals change positions and sometimes even field, due to burnout, fatigue and stress. Happy to finally get some numbers on the rising problem.

Elvis F. Aboagye

Championing Secure, Sustainable, & Supportive Tech | Integrating Privacy, Cybersecurity & Mental Wellness

4mo

Great read in the latest ThreatReady newsletter from Hack The Box. The $626 million annual loss in the US due to burnout is a real eye-opener. NIST CSF 2.0 updates are spot on too. Kudos to HTB for keeping us ahead of the game.

Husam Shbib

Digital Forensics Consultant | Combating Cybercrime with Digital Forensics and Securing Businesses with Ethical Hacking | Pentester | Forensicator | VAPT | DFIR | CTF Player | Sherlock Holmes by Day - Lupin by Night

4mo

That's awesome!! We won!! Thanks for considering Memory Forensic as the Win of the month <3

Nicolas LEFEVRE

Founder at Cardyio | Quantum Business Insider | Lead Auditor ISO 27001 | Zero Trust & AI Advisor | Mindfulness & Stress Management Advocate | Fortune 500 | “NSA-Level” Security (EAL7+) | Teacher

4mo

AI is going to be use for blue team 💙 too

To view or add a comment, sign in

More articles by Hack The Box

Insights from the community

Others also viewed

Explore topics